VDAI (Lithuania) - 3R-252

From GDPRhub
VDAI - 3R-252
[[File:|center|250px]]
Authority: VDAI (Lithuania)
Jurisdiction: Lithuania
Relevant Law: Article 5(1)(a) GDPR
Article 5(1)(e) GDPR
Article 5(1)(f) GDPR
Article 6(1) GDPR
Article 9(1) GDPR
Type: Investigation
Outcome: Violation Found
Started: 24.04.2025
Decided: 13.02.2026
Published:
Fine: 6,000 EUR
Parties: VšĮ Biržų ligoninė
National Case Number/Name: 3R-252
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Lithuanian
Original Source: VDAI (in LT)
Initial Contributor: ap

The DPA fined a hospital €6,000 for unlawfully installing video surveillance cameras in operating rooms and staff workplaces without a valid legal basis, and for storing the data for excessively long periods.

English Summary

Facts

In April 2025, the DPA carried out an ex-officio investigation regarding the video surveillance activities of a hospital (the controller). In its investigations, the DPA found that the controller had placed video surveillance cameras in several areas, including outdoor areas, entrances, common areas and operating rooms. All indoor cameras recorded both video and audio, and the controller placed signs informing data subjects of the surveillance activities.

The controller argued that its surveillance activities were lawful under legitimate interest (Article 6(1)(f) GDPR).

Holding

The DPA first found a violation of Articles 5(1)(a) and 6(1) GDPR, as the hospital did not have a valid legal basis for the video surveillance activities. The DPA noted that the controller had only relied on legitimate interests to process the data. The DPA therefore assessed whether the cumulative requirements under Article 6(1)(f) GDPR were met; whether the controller has a legitimate interest, whether the processing is necessary for the purpose, and whether data subjects’ rights and freedoms override the controller’s legitimate interests.

The DPA acknowledged that the controller’s aims of ensuring a safe environment for patients in general and ensuring efficiency in the operating rooms were legitimate aims. In addition, the surveillance activities were necessary to ensure a safe environment, and the data subjects’ rights and freedoms did not override the controller’s legitimate interest. This, however, was not the case for all the cameras; the DPA made a distinction between the surveillance of outdoors or common areas (such as corridors), and operating rooms or staff areas. According to the DPA, the surveillance of operating and staff rooms did not meet the requirements of necessity or overriding interests. For example, the controller could efficiently organise its operating rooms with less restrictive means, and it had not provided evidence that video surveillance was the only necessary means to ensure that operating rooms were organised smoothly. The DPA also considered the reasonable expectations of privacy of data subjects in operating and staff rooms, concluding that the use of video surveillance violated data subjects’ rights. The DPA reached the same conclusions for the use of audio recordings, stating that they were not necessary for the controller’s purposes and violated data subjects’ rights. Finally, the DPA stated that the controller processed sensitive data through its video and audio surveillance in operating rooms, which is prohibited under Article 9(1) GDPR.

The DPA also found a violation of Article 5(1)(e) GDPR, as the hospital had not complied with the principle of storage limitation. The DPA found that the controller did not have clear storage limitation periods, and stored the data for excessively long periods of time.

Finally, the DPA found a violation of Article 5(1)(f) GDPR, as the hospital had not complied with the principle of security of processing. In its investigations, the DPA found that employees did not have full knowledge of who had access to the video and audio recordings, and were also unable to provide all the information the DPA requested. With this, the DPA concluded that the controller did not have appropriate security measures in place, particularly for sensitive data.

The DPA fined the controller €6,000. The DPA took into account the high number of data subjects affected, the sensitive nature of health data and the fact that the controller recorded areas where the expectation of privacy is high (such as operating rooms).

Comment

The DPA outlined the violations and initiated proceedings for an administrative fine in a previous decision, and later imposed a fine in this decision. You can read the DPA’s previous decision here, and the press release here.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.

Extract of an electronic document
STATE DATA PROTECTION INSPECTORATE
DECISION
February 13, 2026 No. 3R-252 (2.13-1.E)
Vilnius
The State Data Protection Inspectorate (hereinafter referred to as the Inspectorate) examined the case in written procedure regarding the imposition of an administrative fine on the Public Institution Biržai Hospital (hereinafter referred to as the Hospital,
the Inspected Person), legal entity code 190570182.
1. Circumstances for initiating the inspection of the Inspectorate
On 2025-04-24, the Inspectorate received a notification (Inspection
Reg. No. 1R-2619 (2.13 Mr)) from UAB „Šiaurės rytai“ (hereinafter referred to as the Notifier) regarding video surveillance carried out on the premises of the Hospital (including operating rooms).
By order No. 1T-44 (1.12 E) of the Director of the Inspection of 2025-05-05, it was decided to initiate an inspection on its own initiative regarding a possible violation of the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR), in relation to the Hospital. 2. Inspection carried out In accordance with the order No. 2R-2246 (2.14.E) of the Director of the Inspection of 2025-05-21, an on-site inspection was carried out on 22 May 2025, i.e. The compliance of the video surveillance and audio recording carried out on the territory and premises of the Hospital (at the address Vilniaus
g. 115, Biržai) with the requirements established in legal acts was checked.
During the inspection of the Hospital carried out on 2025-05-22, the following actions were taken in order to document the actual circumstances:
1) the observation fields of the Hospital's video surveillance cameras were checked and photographed;
2) the information boards located on the territory and premises of the Hospital, informing about the video surveillance and audio recording being carried out, were checked and photographed;
3) the actual storage duration of the video recordings recorded by the video surveillance cameras was checked;
4) an assessment of the sound recording and the change of the video camera observation field was carried out;
5) access to the video and audio recordings recorded by the video surveillance cameras was checked.
During the inspection, the Hospital's Personal Data Protection Officer (hereinafter referred to as the DPO) explained that 26 video surveillance cameras are operating in the Hospital's territory and premises and submitted Appendix 1 to the Hospital's Rules for the Use of Video Surveillance Cameras and Video Data Processing, approved by order of 25 March 2025 - "List of video surveillance equipment for the territory and premises of the institution, establishing the terms for storing video data" (hereinafter referred to as the List). When asked what the GDPR provides for the legality of personal data processing based on which video surveillance and audio recording are carried out in the Hospital, the Hospital's DPO indicated that the Hospital has carried out a data protection impact assessment (hereinafter referred to as the PDIA) and submitted the PDIA report of the Public Institution Biržai Hospital on 3 February 2025. The DPO of the Hospital explained that data subjects are informed about the video surveillance and audio recording by means of information boards, in addition to the fact that files with the necessary documents have been prepared (both for Hospital visitors and employees); data subjects can access files for Hospital visitors on the premises of the Hospital (at the posts and in the reception area), and the latter are familiarized with documents for employees by signing. After the on-site inspection, the Inspected Person submitted additional explanations on 2025-06-17 (Inspection reg. No. 1R-3973 (2.13 Mr)). That is, it indicated that it provides the Inspection with the following relevant documents: 1) The rules for processing personal data of the Public Institution Biržai Hospital with annexes approved by the order of the Hospital Director of 2024-06-18 No. PVK-30; 2) The description of the procedure for the implementation of the rights of data subjects when processing personal data in the Public Institution Biržai Hospital, approved by the order No. PVK-31 of the Hospital Director of 2024-06-18;
3) The description of the procedure for the implementation of the rights of data subjects when processing personal data in the information systems of the Public Institution Biržai Hospital, approved by the order No. PVK-32 of the Hospital Director of 2024-06-18;
4) The document “Information for patients about personal data processed in the Public Institution Biržai Hospital” approved by the order No. PVK-42 of the Hospital Director of 2024-06-18;
5) Information notice on the processing of personal data for patients;
6) The test of the balance of legitimate interests regarding video surveillance carried out in the Hospital together with audio recording of 2025-02-03;
7) 2025-03-27 Order of the Hospital Director Regarding the Provision of Access to Video Data No.
PVK-11;
8) 2025-03-27 Commitment of the Hospital’s Authorized Employees to Maintain Data Confidentiality;
9) Privacy Policy approved by the Hospital Director’s Order No. PVK-35 of 2024-06-18;
10) Rules for the Use of Video Surveillance Cameras and Video Data Processing of the Public Institution Biržai Hospital, approved by the Hospital Director’s Order No. PVK-7 of 2025-03-25;
11) Description of the Procedure for the Processing of Video and Audio Surveillance and Recording in the Provision of Personal Health Care Services and Video and Audio Recording Data of the Public Institution Biržai Hospital, approved by the Hospital Director’s Order No. PVK-8 of 2025-03-25.
It also indicated that during the inspection it was noticed that the video data was stored for longer than the established time limits, therefore, by order of the Hospital Director, a commission was formed for the manual destruction of video data. It explained that the data stored for too long was destroyed, and also indicated that it ensured that the video data would be stored in the device only for the established time limit.
The Hospital submitted the Hospital Director's order No. PVK-34 of 2025-05-23 "On the Formation of a Data Destruction Commission".
After the inspection, the Information Technology Department of the Inspectorate prepared Inspection Report No. 4R-672 (2.14.E) "Ensuring the Requirements for Video Surveillance of the Public Institution Biržai Hospital" on 2025-12-19 (hereinafter referred to as the Inspection Report).
The inspection report assessed: 1) The surveillance fields of the Hospital's video surveillance cameras; 2) the possibility of changing the field monitored by video surveillance cameras; 3) Information boards located on the territory and premises of the Hospital; 4) actual duration of storage of video and audio recordings recorded by video surveillance cameras; 5) assessed the possibility of access to video and audio recordings recorded by video surveillance cameras and video surveillance programs.
The inspection report made the following conclusions:
First, during the inspection, it was determined that 26 video surveillance cameras are operating on the territory and premises of the Hospital, the actual arrangement of which corresponds to the List submitted to the Hospital Inspectorate:
1) 8 video surveillance cameras operate in the outdoor area, which monitor the entrances to the Hospital premises, parking lots, electrical panel and solar power plant, and waste collection site;
2) 1 video surveillance camera operates in a common room, which monitors the main entrance of the Hospital and the lobby near the stairs;
3) 4 video surveillance cameras operate in the Admission and Emergency Department, which monitor: (1) the entrance to the department, (2) the patient waiting room, (3) the 3rd patient admission and examination room of the Admission and Emergency Department (the field of view of this video surveillance camera has been adjusted - the patient examination area is covered by a filter), (4) the outpatient operating room (hereinafter referred to as the Outpatient Operating Room) (the entrance door and the part of the room near the door, the video camera's field of view covers a small part of the patient examination area);
4) 1 video surveillance camera operates in the Supportive Treatment and Nursing Department, which monitors the main entrance and part of the corridor of this department;
5) 2 video surveillance cameras operate in the 1st Internal Medicine Department, which monitor the entrance to this department, the corridor and the emergency exit;
6) 2 video surveillance cameras operate in the II Department of Internal Medicine, which monitor the entrance to this department, the lobby, the corridor and the emergency exit;
7) 2 video surveillance cameras operate in the Department of Surgery and Orthopedics Traumatology, which monitor the entrance to this department, the lobby, the corridor and the emergency exit;
8) 1 video surveillance camera operates in the consultation polyclinic, which monitors the entrance to this department and the corridor;
9) 1 video surveillance camera operates in the Geriatric Day Hospital, which monitors the reception and the corridor;
10) 3 video surveillance cameras operate in the operating rooms, i.e. one video surveillance camera operates in the surgical operating room, the purulent operating room and the traumatology operating room (hereinafter referred to as the Operating Rooms). After checking the field of view of the video camera in the surgical operating room,
it was determined that the camera captures the image along the wall, i.e. a small part of the room near the wall, into which the work table and the employees located next to it enter; the operating table and/or the patient who was undergoing an operation at the time of the inspection did not enter the camera's field of observation. The video surveillance camera in the purulent operating room captures the wall, the space between the wall and the operating table, and the edge of the operating table also enters the field of observation of the video surveillance camera. The video surveillance camera in the trauma operating room captures the wall, the space between the wall and the operating table; the operating table does not enter the field of observation of the video camera. 11) 1 video surveillance camera operates in the basement, which monitors the basement corridor. Secondly, it was established that the fields of observation of all video surveillance cameras can be changed only physically. Thirdly, it was established that all video surveillance cameras installed in the Hospital premises perform audio recording. Audio recording is not performed by cameras installed outside. Fourth, it was concluded that data subjects are informed by information signs before entering the areas where video and audio recording is carried out.
Fifth, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the video recordings made are stored in two different video recording devices. The oldest video recordings saved in the first video recording device were dated 2025-05-03 (i.e. 20 calendar days old), and the oldest video recordings saved in the second video recording device were dated 2025-02-27 (i.e. almost 3 months old).
Sixth, the video recordings recorded in the video recording devices are viewed only after entering a special room locked with a key, which can only be accessed by one authorized person. The computer workstation
and the video recording device program are protected by passwords, therefore the physical security measures applied are sufficient and ensure the physical security of the stored video recordings. It has also been established that
remote access is not possible for monitoring video recordings captured by cameras (except for Operational video cameras) (including connecting to the computer workstation, video recording device program or video surveillance cameras located in the room).
1 The model of the video surveillance cameras in the field is "Hikvision DS-2CD2232-I5. The cameras of this model do not have an audio recording function. 4 Seventh, it was established that the image monitored by the video surveillance cameras in the Hospital's Operating Rooms is broadcast live on a computer in the Hospital's Operating Rooms reception area. Persons can enter the Operating Rooms reception area only with a pass card. The computer workstation of the Hospital's Operating Rooms reception area employee is password protected, and the employee's account in the video surveillance program (through which the image and audio from the Operating Rooms are broadcast) is also password protected, therefore the applied physical security measures are sufficient and ensure the physical security of the video broadcast. The inspection report stated that during the inspection at the site, the Hospital representatives could not indicate who has privileged access rights to the program, nor could they answer whether there is a video recording device for the cameras in the Operating Rooms. (and if so, in which location), therefore, the Inspectorate employees were not given the opportunity to determine which persons have access to the program (i.e. live broadcast video), and it was also not possible to determine whether video recordings are being made in the Operational Units during video surveillance. For this reason, after the on-site inspection, the Inspected Person was additionally contacted with instruction No. 2R-3401 (2.14 E) to provide additional information. The Inspected Person submitted a response to the Inspection's instruction on 07-08-2025 (Inspection reg. No. 1R-5255 (2.14 K)), but no evidence was provided to the Inspection together with it that would allow determining who has actual access to the program and determining whether video recordings are actually being made or not. For these reasons, the Inspectorate employees were not given the opportunity to determine who has actual access to the program (i.e. live broadcast video and audio) and whether The video surveillance is not recorded in the operational areas.
3. Applicable legal regulation
The European Data Protection Board (hereinafter referred to as the EDPB) in its Guidelines No. 3/2019 of 29 January 2020 on the processing of personal data using video devices (hereinafter referred to as the Guidelines on video surveillance)
notes in the preamble that the intensive use of video devices has an impact on citizens' behaviour.
These technologies can in fact limit the ability to move around anonymously and use services, as well as generally limit the ability to remain undetected. The Guidelines on video surveillance also note that surveillance by video cameras is not necessary in itself in cases where there are other means to achieve the main purpose. Otherwise, dangerous changes in cultural norms may occur, leading to the rejection of privacy being accepted as a common starting point.
The European Data Protection Board has indicated in its Guidelines on video surveillance that the specific purpose of the data processing must be clearly stated before the data is used (GDPR Article 5(1)(b). Video surveillance can be used for various purposes, for example, to help ensure the protection of property and other assets, life and physical integrity of persons, to gather evidence for civil claims, etc. These surveillance purposes should be specified in written documents (Article 5(2) GDPR), and the specific purposes related to each video surveillance camera used should be specified. The guidelines on video surveillance emphasize that video surveillance has a significant impact on data protection, therefore video surveillance is not necessary in itself in cases where other means are available to achieve the main purpose. It should be noted that the GDPR does not establish separate provisions exclusively for the legal regulation of video surveillance and/or audio recording, therefore the video surveillance and/or audio recording carried out must comply with the general provisions of the GDPR and the Law on the Legal Protection of Personal Data of the Republic of Lithuania (hereinafter referred to as the “PLPPL”). A person Data processing is considered lawful when it complies with the provisions of the GDPR and the GDPR. Paragraph 39 of the GDPR preamble states that any processing of personal data should be lawful and fair. First of all, the processing of personal data must also be based on at least one of the conditions for lawful personal data processing provided for in Articles 6 and/or 9 of the GDPR (depending on the categories of personal data being processed). That is, in cases where special categories of data are also processed (e.g. health data relevant in the context of this inspection2), such processing of personal data must be based on Article 9(2) of the GDPR. Otherwise, the health data of the individual (patient) cannot be processed. Consequently, the processing of health data must comply not only with at least one of the conditions for lawful personal data processing provided for in Article 6(1) of the GDPR, but also with at least one of the prohibitions on the processing of health data provided for in Article 9(2) of the GDPR.
Secondly, personal data must be processed in accordance with the principles set out in Article 5(1)(a) to (f) of the GDPR. In other words, personal data must be processed in accordance with the principles of lawfulness, fairness and transparency, the principle of purpose limitation, the principle of data minimisation, the principle of accuracy, the principle of storage limitation and the principles of integrity and confidentiality. Compliance with the principles set out in Article 5(1)(a) to (f) of the GDPR imposes certain obligations on the data controller.
For example, the application of the principle of transparency set out in Article 5(1)(a) of the GDPR requires that data subjects should be clear about the purpose for which their personal data are being processed, how the personal data relating to them are being processed and what personal data processing operations (collection, use, transfer, etc.) are being carried out on them3. Thus, the principle of transparency requires that data subjects be provided with information about their personal data data
processing. It should be noted that Article 13(1) and (2) of the GDPR establish what information must
be provided when personal data are collected from a data subject. Article 12(1) of the GDPR establishes that the data controller shall take appropriate measures to provide the data subject with all the information referred to in Article 13 of the GDPR in a concise, transparent, intelligible and easily accessible
form, in clear and plain language. The information shall usually be provided in writing or by other means, including, where appropriate, in electronic form. Thus, the data controller (in this case – the Hospital) performing video surveillance and/or audio recording must provide the following information to individuals (before entering the premises or area where the video surveillance and/or audio recording is being performed): 1) the fact that the video surveillance and/or audio recording is being performed; 2) the name and contact details of the data controller; 3) the purpose(s) of the personal data processing; 4) a reference to the source of the information, where more detailed information on the video surveillance being carried out (i.e. the information referred to in Article 13(1) and (2) of the GDPR, the procedure for exercising the rights of data subjects set out in Articles 15 to 22 and 34 of the GDPR, etc.), for example a link to a website, a contact telephone number, etc. The principle of storage limitation enshrined in Article 5(1)(e) of the GDPR provides that personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Recital 39 of the GDPR establishes the obligation to ensure that the storage period of personal data is kept to a minimum. The European Data Protection Board draws attention to the fact in its Guidelines on video surveillance that “[t]he longer the storage period is set (in particular when it exceeds 72 hours), the more arguments need to be provided relating to the legitimacy of the purpose and the necessity of the storage. If the data Where the controller uses video surveillance not only to monitor its premises but also intends to store the data, it must ensure that the storage of the data is actually necessary to achieve the purpose”4. This means that the controller must carefully
2 Article 4(15) of the GDPR states that health data means personal data relating to the physical or mental health of a natural person, including data relating to the provision of healthcare services, which reveal information about the state of health of that person.
3 Point 60 of the GDPR states that, in accordance with the principles of fair and transparent processing, the data subject shall be informed of the processing operation and its purposes.
4 The Guidelines provide an example: the owner of a small shop usually notices any vandalism on the same day.
Therefore, a normal retention period of 24 hours is sufficient. However, weekends when the shop is closed or several public holidays may be grounds for setting a longer retention period.
6
assess what period of retention of video recordings would be adequate and proportionate in his/her specific case.
When choosing to retain video recordings, it is necessary to both choose a specific period and be able to justify such
chosen period.
The principle of integrity and confidentiality enshrined in Article 5(1)(f) of the GDPR means
that personal data must be processed in such a way that appropriate technical or
organisational measures ensure the appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. The implementation of this principle is related to Article 32 of the GDPR, according to which
the procedures must provide for how video and audio recordings made will be protected against accidental or unlawful destruction, alteration, disclosure and any other unlawful
processing. The Inspectorate notes that, pursuant to Article 32(4) of the GDPR, the procedures must describe measures to ensure that any natural person under the control of the data controller who has access to the video and/or audio recordings does not become familiar with them. In addition, the procedures must specify the computer and software used to process the video and/or audio recordings, and, among other things, must specify how appropriate physical and logical access control to the video surveillance cameras and/or audio recording devices is ensured, e.g. locked premises, password storage, access by authorised persons, etc.
The Inspectorate also notes that Article 35(1) of the GDPR provides that where the type of data processing, in particular when new technologies are used, and taking into account the nature, scope, context and purposes of the data processing, is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall, before processing the data, carry out an assessment of the impact of the envisaged data processing operations on the protection of personal data. It is noteworthy that point 6.2 of the list of data processing operations subject to the requirement to carry out a data protection impact assessment5 states that a DPIA must be carried out in cases where personal data are processed in healthcare, social care, prison institutions and other institutions where services are provided to vulnerable persons. Point 10 of the aforementioned list also provides that a DPIA must be carried out in the event that the personal data of employees are processed for the purposes of "monitoring or control: processing of personal video and/or audio data at the workplace and/or on the premises or territories of the data controller where its employees work; processing of personal data relating to the monitoring of employees' communication, behaviour, location or movement". Thus, the data controller, before starting to carry out video surveillance and/or audio recording in a healthcare facility and thus process the data of visitors and employees of the Hospital (vulnerable persons), must first carry out a DPIA. It should be noted that Article 5(2) of the GDPR provides that the data controller (in this case, the Hospital) is responsible for ensuring compliance with the GDPR and must be able to demonstrate compliance (accountability principle). 4. Inspection conclusions6: 4.1. Regarding the lawfulness of the video surveillance
As mentioned above, the processing of personal data must first be based on at least one of the conditions for the lawful processing of personal data provided for in Articles 6 and/or 9 of the GDPR (depending on the category of personal data being processed).
In the case under consideration, the Inspected Person has submitted to the Inspectorate the PDAV report of 2025-02-03 and the Balance of Interests test of 2025-02-03.
5 approved by the Director of the State Data Protection Inspectorate of 14 March 2019 by Order No. 1T-35(1.12.E).
6 According to the report No. 4R-672 (2.14.E) of the Information Technology Division of the Inspectorate of 2025-12-19 “On ensuring the requirements for video surveillance of the Public Institution Biržai Hospital”.
7
The PDAV report states that the purpose of video surveillance and audio recording carried out in the Hospital's outdoor area and premises (except for the Operating Rooms) is the safety of Hospital visitors, employees and property, i.e. the aim is to ensure the safety of employees and Hospital visitors/patients, and to implement the prevention of physical and psychological violence. It is also stated that when conducting video surveillance, the Inspected Person has the opportunity to assess visitors entering the premises (whether they are not intoxicated, do not behave aggressively, do not bring in unauthorized items or do not take certain items away (in the event of theft), etc.), and also has the opportunity to identify patients leaving the Hospital premises without warning (thus ensuring the safety of patients).
The PDAV report also establishes that three cameras are used for monitoring the Operating Rooms, i.e. three separate cameras monitor three Operating Rooms – the surgical operating room, the purulent operating room and the trauma operating room. It is stated that the purpose of video surveillance in the operating rooms is the smooth organization of the work of the Operating Room. Having assessed the objectives of video surveillance specified by the Hospital – the safety of persons and property and the smooth organization of work, it is concluded that the aim of protecting persons and property is to be considered a legitimate interest, therefore it is concluded that the Hospital carries out video surveillance on the basis of Article 6(1)(f) of the GDPR. It should be noted that the Hospital did not rely on any other conditions of lawfulness provided for in Article 6(1)(f) of the GDPR and/or the exceptions provided for in Article 9(2)(f) of the GDPR. According to Article 6(1)(f) of the GDPR, personal data may be lawfully processed when it is necessary to do so for the legitimate interests of the data controller or a third party, except in cases where such interests or fundamental rights and freedoms of the data subject which require the protection of personal data prevail over them, in particular where the data subject is a child. The Court of Justice of the European Union, interpreting Article 6(1)(f) of the GDPR, has established that the application of this provision provides for three cumulative conditions for the lawfulness of the processing of personal data: 1) the processing of personal data is necessary for the purposes of the legitimate interests pursued by the controller or a third party; 2) the processing of personal data is necessary for the purposes of the legitimate interests pursued; 3) the interests or freedoms and fundamental rights of the person whose data must be protected must not be overridden (judgment of 04 July 2023 in Meta platforms and others in case C-252/21; judgment of 17 June 2021 in Mircom International Content Management & Consulting (M.I.C.M.) Limited v. Telenet BVBA in case C-597/19). The requirement for the application of cumulative conditions means that if at least one of the cumulative conditions for the lawfulness of the processing of personal data is not established, the processing of personal data would be unlawful (decision of the Supreme Administrative Court of Lithuania of 29 November 2023 in administrative case No. eA-831-525/2023). Thus, in order to determine whether the video surveillance carried out by the Hospital is lawful, basing such processing of personal data on Article 6(1)(f) of the GDPR, it is necessary to assess all three aforementioned cumulative conditions. 4.1.1. Regarding the condition related to the pursuit of a legitimate interest (first condition), the Article 29 Data Protection Working Party, established on the basis of Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, in its Opinion No. 2014-04-09 06/2014 “On the concept of legitimate interests of the controller pursuant to Article 7 of Directive 95/46/EC” (hereinafter referred to as the Opinion on legitimate interests)
clarifies that an interest is the general need of the controller to process the data or the benefits of the processing for the controller or the potential benefits for society. In accordance with the EDPB Guidelines on video surveillance, the legitimate interests of the controller or a third party may be of a legal, economic or intangible nature. It is noted that a legitimate interest must be real and relevant (i.e. it cannot be a fictitious or hypothetical interest). In accordance with the Opinion on legitimate interests, an interest can be considered legitimate if the controller can pursue it without infringing
8 data protection and other legal acts. In other words, a legitimate interest must be acceptable under the law.
In the case under consideration, the Inspected Person indicated that video surveillance is carried out in the Hospital premises (except for the Operating Rooms) in the interest of ensuring the safety of persons and property, and video surveillance in the Hospital's Operating Rooms is carried out in order to ensure smooth work organization and more efficient provision of services. It is agreed that both the aim of ensuring a safe and appropriate environment for the Hospital's visitors/patients and employees and the aim of properly and efficiently organizing work in the Operating Rooms are realistic and legitimate. Taking this into account, it is agreed that the Hospital, when carrying out video surveillance, pursues a legitimate interest, therefore the video surveillance carried out meets the first condition necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR. 4.1.2. Regarding the condition relating to the necessity of processing personal data (second condition)
According to recital 39 of the GDPR, personal data should only be processed if the purpose of the processing of personal data cannot reasonably be achieved by other means.
The Opinion on legitimate interests states that “[i]n applying this balancing test, it is important to first consider, on the one hand, the nature and origin of the legitimate interests and whether the processing is necessary for the pursuit of those interests”. Thus, if the controller decides that the processing of personal data is necessary for the pursuit of the relevant legitimate purpose, he should also ensure that the purpose of the processing is achieved by applying the least intrusive measures for the privacy of data subjects.
It should be noted that the Hospital submitted a Balance of Interest Test to the Inspectorate on 2025-02-03, which indicated that the Hospital determined that such processing of personal data (video surveillance) is the only way to achieve the objectives pursued. It was noted that the processing of personal data (video surveillance) will achieve the goal of ensuring the safety of visitors and employees of the Hospital, the security of property, and public order. It is stated that it is not possible to effectively achieve the set goal in any other way. It was noted that no other alternatives for achieving the set goals were considered. The Inspectorate, having assessed the assessment submitted by the Inspected Person, concludes that in order to ensure the safety of persons and property (public order) in the territory and premises of the Hospital (except for the Operating Rooms), video surveillance is one of the necessary measures, therefore the video surveillance carried out in these premises complies with the second condition, the necessary processing of personal data based on Article 6, Paragraph 1, Point f of the GDPR. According to the explanations provided by the Inspected Person, video surveillance in the Hospital's Operating Rooms is carried out in order to ensure the smooth organization of the work of the Operating Room and more efficient provision of services. During the on-site inspection, the Hospital representatives explained that the employee working in the Operating Room reception, by observing the image broadcast directly from the Operating Rooms, can more quickly determine when the operation is being completed/finished and can more quickly organize the management of the Operating Rooms, the preparation of the next patient for the operation, etc. It should be noted that the presented Balance of Interest test does not assess whether video surveillance in the Hospital's Operating Rooms is the only and most effective way to achieve the aforementioned objective. During the inspection, the Inspected Person did not provide the Inspectorate with any explanations as to why work in the Operating Rooms cannot be properly organised not by means of video surveillance, but by applying other measures that are less restrictive of the privacy of data subjects (patients) (e.g. by notifying the responsible employee about the end of the operation by telephone or in other ways). Taking into account the above, it is concluded that the Inspected Person has not proven that in order to ensure the smooth organisation of work in the Operating Rooms, video surveillance is the only and necessary means to achieve this objective. Thus, video surveillance in the Hospital's Operating Rooms does not meet the second condition necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR.
9
4.1.3. Concerning the condition of primacy of conflicting rights and interests (third condition)
According to the Guidelines on video surveillance, in cases where video surveillance is necessary to protect the legitimate interests of the data controller (i.e. when the first two cumulative conditions are met), the video surveillance system may be put into operation only if there are no overriding interests or fundamental rights and freedoms of the data subject that override the legitimate interests of the data controller or a third party. The data controller must assess: 1) the extent to which the surveillance affects the interests, fundamental rights and freedoms of individuals and 2) whether the rights of the data subject are infringed or adversely affect them.
In other words, it is necessary to balance the legitimate interests of the data controller or a third party with the legitimate interests of the data subjects.
According to the Guidelines on Video Surveillance, it is necessary to take into account the reasonable expectations of the data subject at the time when his or her personal data are processed. The Guidelines on Video Surveillance state that in the context of video surveillance, the decisive criterion should be whether an objective third party could reasonably expect and conclude that he or she will be monitored in the specific situation. For example, an employee usually does not expect to be monitored by his or her employer at the workplace. Furthermore, one cannot expect to be monitored <...> in examination and treatment rooms. Data subjects can reasonably expect that there will be no surveillance by video cameras in such places. Data subjects can also expect that they will not be monitored in places that are publicly accessible, in particular where those places are commonly used for treatment, rehabilitation and leisure activities. In this case, the interests or rights and freedoms of the data subject will often override the legitimate interests of the data controller. In the Balance of Interests test submitted to the Inspectorate on 2025-02-03, the Inspectorate has indicated only that data subjects are informed about the processing of personal data, and video data is accessible only to a very limited number of persons. In the Balance of Interests test, the Inspectorate has indicated that video data is processed only for the purpose of ensuring the security of persons and property, and that monitoring data subjects in service premises to ensure the protection of persons and property is common practice. It is also indicated that the video surveillance carried out has only a positive impact on data subjects, since using video data, conflict situations are resolved, violations (e.g. theft) are identified, the safety of Hospital employees and visitors is ensured, and physical and psychological violence is prevented. It is also stated that the video surveillance carried out does not have any negative impact on data subjects, since the video data is not provided to anyone, there is no constant review of the recordings, the video recordings are stored only to the extent necessary to achieve the objectives, and no video recordings are made at all in the Hospital Operating Rooms. It is noted that a negative impact on data subjects could arise only in the event of a personal data breach. It should be noted that the EDPB Guidelines No. 1/2024 of 8 October 2024 on the processing of personal data based on Article 6(1)(f) of the GDPR (hereinafter referred to as the Guidelines on Legitimate Interest) state that the data controller must assess its legitimate interests and the legitimate interests of data subjects and third parties. This balancing test must be carried out in each case where the processing of personal data is based on Article 6(1)(f) of the GDPR, and must be carried out before the processing of personal data begins. This means that it is necessary to balance the conflicting interests of the data controller and the data subjects. In accordance with the Guidelines on legitimate interest, the balancing of interests test must address: 1) the interests, fundamental rights and freedoms of the data subjects; 2) the impact of the data processing on the data subjects, including the nature of the personal data processed, the context of the processing and any other consequences of the processing; 3) the reasonable expectations of the data subjects; 4) a final assessment of the balance of the conflicting rights and interests, including an assessment of the possibility of taking other measures that are less restrictive of the privacy of individuals. Having assessed the Balancing of Interest Test carried out by the Subject, it can be seen that it does not actually address how data subjects could react to the processing of their personal data (video surveillance) in 10 specific Hospital rooms (including the Operating Rooms). In addition, the Balance of Interests test assessed the compatibility of the interests of the data controller (Hospital) and data subjects formally and abstractly. Among other things, the Balance of Interests test is limited to only one of the legitimate interests of the Inspected Person relevant in the case under consideration - ensuring security. However, the Inspected Person did not fully assess his interest in effectively organizing work in the Operating Rooms and the legitimate interests of the data subjects (patients and employees). The Inspectorate, taking into account the above, as well as having assessed the information collected during the inspection, concludes that when conducting video surveillance in the general use Hospital territory and premises, such as the perimeter of the Hospital field, entrances to the Hospital premises, corridors and lobbies of the Hospital departments, video surveillance carried out in pursuit of the legitimate interest of the Hospital to ensure the security of persons and property does not unduly restrict the rights and legitimate interests of the data subjects. The specified areas and premises usually have a constant movement of people, therefore, it is in these zones of the Hospital that incidents related to the safety of people and/or property can most often occur. The Inspectorate also notes that the video surveillance carried out in the premises of the Hospital, such as: 1) Outpatient operating room, 2) Reception and emergency department patient reception and examination room and 3) Geriatric day hospital department, is not per se excessively restrictive of the rights and legitimate interests of data subjects, if the field of surveillance of the video cameras does not include the patient examination area and the permanent workplaces of the employees. In the case under consideration, it was established during the inspection that: 1) part of the patient examination table falls within the field of surveillance of the video camera located in the Outpatient operating room of the Hospital; 2) the field of surveillance of the video camera located in the patient reception and examination room of the Reception and emergency department includes the permanent workplaces of the employees; 3) the field of view of the video camera recording the reception of the Geriatric Day Hospital Department includes the employee's permanent workplace. Having assessed these circumstances, it should be concluded that although video surveillance can be carried out in the aforementioned premises, the field of view must be strictly limited so that it does not include the patient examination area and the permanent workplaces of the employees. Otherwise, the privacy of the data subjects (patients and employees of the Hospital) is excessively violated. Taking into account the above, the Inspectorate concludes that the video surveillance carried out in the Hospital premises: 1) The outpatient operating room, 2) The patient reception and examination room of the Admission and Emergency Department and 3) The Geriatric Day Hospital Department does not comply with the third condition necessary for the processing of personal data based on Article 6(1)(f) of the GDPR, since part of the patient examination area and the employees' permanent workplaces fall within the field of view of the video surveillance cameras. The Inspectorate, having assessed the information collected during the inspection, also concludes that conducting video surveillance in the Hospital's Operating Rooms (surgical operating room, purulent operating room and trauma operating room) in order to achieve the legitimate interest of the Hospital to effectively organize work in the operating rooms is excessively restrictive of the rights and legitimate interests of data subjects (both patients and employees). Although it was established during the inspection that the operating table does not fall within the field of view of the video cameras in the Operating Rooms, the cameras in the Operating Rooms capture the space next to the operating table, therefore it is most likely that a patient being brought to or taken from the operation could be captured. It should be noted that the operating room is, by its nature, a particularly sensitive space in which patients undergo invasive procedures, during which complete or partial body exposure is possible, therefore the expectation of privacy in such an environment is extremely high. According to the Inspectorate, the right to privacy of data subjects (patients) in the case under consideration undoubtedly outweighs the interest of the Hospital in organizing its work more efficiently. Thus, video surveillance in the Hospital's operating rooms does not meet the third condition necessary to justify the processing of personal data under Article 6(1)(f) of the GDPR. The Inspectorate also notes that even when video cameras partially record such places as the patient examination table (in the outpatient operating room) and the operating tables and the close space around them, health data is also processed, therefore the processing of such personal data must be based on at least one of the exceptions to the prohibition on processing health data provided for in Article 9(2)(a)-(j) of the GDPR. In the case under consideration, the Inspected Person did not prove that at least one of the exceptions to the prohibition on processing special categories of data provided for in Article 9(2)(a) of the GDPR exists in the case under consideration. Summarizing the above assessment of the Inspectorate, the following conclusions are drawn:
First, video surveillance in the Hospital's Outpatient Operating Room, to the extent that part of the patient examination area falls within the field of view of the video cameras, does not meet one of the three cumulative conditions
– the reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5(1)(a) of the GDPR and Article 6(1) of the GDPR. In addition, since the Hospital has not proven that the processing of health data in the case under consideration is justified by at least one of the exceptions provided for in Article 9(2) of the GDPR, it is concluded that video surveillance in the Hospital's Outpatient Operating Room, to the extent that part of the patient examination area falls within the field of view of the video cameras, is carried out unlawfully, in violation of Article 9(2) of the GDPR.
Secondly, video surveillance in the patient reception and examination room of the Hospital's Admission and Emergency Department and the Geriatric Day Hospital, to the extent that the permanent workplaces of employees fall within the field of surveillance of video cameras, does not meet one of the three cumulative conditions - reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5, paragraph 1, point a, of the GDPR, and Article 6, paragraph 1, of the GDPR. 
Thirdly, video surveillance in the Hospital's Operating Rooms does not meet two of the three cumulative conditions - necessity and reconciliation of legitimate interests, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5, paragraph 1, point a, of the GDPR, and Article 6, paragraph 1, of the GDPR. In addition, since the Hospital has not proven that the processing of health data in the case under consideration is based on at least one of the exceptions provided for in Article 9(2) of the GDPR, it is concluded that the video surveillance in the Hospital's Operating Rooms is carried out unlawfully, also in violation of Article 9(2) of the GDPR.
4.2. Regarding the lawfulness of the audio recording, the processing of personal data (i.e. each of its operations) must be based on at least one of the conditions for the lawful processing of personal data provided for in Articles 6 and/or 9 of the GDPR (depending on the category of personal data being processed).
In the case under consideration, it was established during the inspection that the video surveillance cameras installed in the Hospital's premises also record audio. Audio recording is not performed by cameras installed outdoors. The person under inspection bases both the video and audio recording on Article 6(1)(f) of the GDPR. Therefore, in order to determine whether the Hospital's audio recording is lawful, in order to base such personal data processing on Article 6(1)(f) of the GDPR, it is necessary to assess all three aforementioned cumulative conditions. 4.2.1 Regarding the condition related to the pursuit of a legitimate interest (first condition) In the case under consideration, the Balance of Interest Test submitted by the Inspected Person states that audio is also recorded when conducting video surveillance in the Hospital. Based on the information submitted to the Inspectorate, the Inspected Person performs audio recording for the same purposes and in order to implement the same interests that it seeks to implement when conducting video surveillance: i.e., the Hospital, by recording audio in the premises (except for the Operating Rooms), seeks to implement the interest in ensuring the safety of persons and property, as well as the prevention of psychological violence, and the Hospital's audio broadcasting in the Operating Rooms is carried out in order to ensure smooth work organization and more efficient provision of services. 12
It is agreed that both the aim of ensuring a safe and appropriate environment for the Hospital's visitors/patients and employees, and the aim of properly and efficiently organising work in the Operating Rooms are
real and legitimate. Taking this into account, it is agreed that the Hospital, by carrying out the audio recording, pursues a legitimate
interest, therefore the audio recording carried out complies with the first condition, the necessary processing of personal data, based on Article 6(1)(f) of the GDPR.
4.2.2 Regarding the condition related to the necessity to process personal data (second condition)
It should be noted that according to Article 6(1)(f) of the GDPR, the processing of personal data is deemed to be necessary only in the case where the specified purpose cannot be achieved by other, less restrictive means of the rights of data subjects.
It should be noted that the Balance of Interests test submitted by the Hospital shows that the processing of personal data – video surveillance and audio recording – was assessed together. Audio recording, as a separate personal data processing operation, is not assessed in the Balance of Interests test and is mentioned only formally. In the case under consideration, the Balance of Interests test submitted by the Inspected Person states that such personal data processing is the only way to achieve the objectives pursued. The Inspected Person did not provide a more detailed explanation of why audio recording on the premises of the Hospital is a necessary measure to ensure the safety of persons and property and the efficient organization of work during the inspection. According to the Inspectorate's assessment, audio recording on the premises of the Hospital, in order to ensure the safety of persons and property, is not the only and necessary measure to achieve this objective. Both the physical and emotional/psychological safety of the Hospital's employees and visitors can be ensured by using other measures (e.g., such as employee training, alarm buttons and physical protection in case of danger, etc.). In addition, video surveillance in the Hospital premises, applied in conjunction with other security measures, should be considered a sufficiently effective way to ensure security and/or resolve conflicts that have arisen. It should be noted that audio recording by itself cannot prevent incidents. The person under review did not explain or provide any objective evidence from which it could be concluded that cases of violence (including psychological) occur in the Hospital premises to such an extent that it would be necessary to take such privacy-restricting measures as audio recording. It should also be noted that the person under review did not justify in any way why audio recording in the Hospital's Operating Rooms is a necessary means of organizing work. Taking into account the above, it is concluded that the person under review did not prove that in order to ensure the safety of the Hospital's employees and visitors, as well as to ensure the smooth organization of the work of the Operating Rooms, audio recording is the only and necessary means to achieve this goal. Thus,
Sound recording carried out in hospital premises (including operating theatres) does not meet the second condition,
necessary for the processing of personal data on the basis of Article 6(1)(f) of the GDPR.
4.2.3. Regarding the condition of the primacy of conflicting rights and interests (third condition)
As already mentioned, the data controller, when basing the processing of personal data on Article 6(1)(f) of the GDPR, must assess, among other things: 1) to what extent the processing of personal data affects the interests, fundamental rights and freedoms of individuals and 2) whether the rights of the data subject are infringed or have adverse consequences in relation to them. In other words, it is
necessary to balance the legitimate interests of the data controller or a third party with the legitimate interests of the data subjects.
The Opinion on legitimate interest states that it is important to consider whether the status of the data controller, its relationship with the data subject or the nature of the service provided [...] may give rise to a legitimate expectation of greater confidentiality and stricter restrictions on further use of the data. The Opinion on legitimate interest also states that it is important to take into account the status of the data controller and the data subject, i.e. whether the data subject is a child or belongs to another vulnerable group in society (such as, for example, people with mental health problems, asylum seekers or the elderly) who need special protection. It is also necessary to take into account whether the data subject is an employee, student or patient and whether the relationship between the data subject and the data controller is characterised by other inequalities. It is important to assess the impact of the actual processing of data on specific individuals. The opinion on legitimate interests also noted that the balancing criterion is not intended to prevent the data subject from experiencing any negative impact – it aims to avoid a disproportionately large impact. The Balance of Interests test submitted by the inspected person to the Inspectorate on 2025-02-03 did not assess whether the audio recording carried out for the purpose of security and efficient work organisation does not infringe the legitimate interests of the data subjects – the Hospital visitors, patients and employees. In the case under consideration, it is necessary to assess the fact that the data controller is the Hospital, and the data subjects are the Hospital visitors/patients and employees, who are considered to be more vulnerable in the context of this relationship. Private conversations between Hospital visitors/patients and employees usually take place in hospital premises, such as ward corridors, lobbies, etc., therefore it is obvious that data subjects have a legitimate expectation that their private conversations will not be recorded. It is also necessary to note that conversations between Hospital visitors and patients may, among other things, include conversations related to their health status, etc., which would mean that health data are recorded and recorded, which, according to Article 9 of the GDPR, are considered to be special categories of data, the lawfulness of the processing of which must be justified not only by the provisions of Article 6 of the GDPR, but also by the provisions of Article 9 of the GDPR. According to the Inspectorate, in the case under consideration, the right to privacy of data subjects (Hospital visitors/patients and employees) prevails over the Hospital's interest in ensuring security and organizing work more efficiently. Thus, audio recording on the Hospital premises also does not meet the third condition necessary for the processing of personal data based on Article 6(1)(f) of the GDPR. In addition, the Hospital did not base the processing of personal data (audio recording) on any of the conditions provided for in Article 9(2) of the GDPR, i.e. has not proven that in the case under consideration there is an exception to the prohibition on processing health data provided for in Article 9(1) of the GDPR.
Summarizing the above assessment of the Inspectorate, it is concluded that the audio recording in the premises of the Hospital does not meet two of the three cumulative conditions – necessity and legitimate interests
, and is therefore carried out unlawfully, in violation of the principle of lawfulness established in Article 5(1)(a) of the GDPR, Article 6(1) of the GDPR and Article 9(2) of the GDPR.
4.3. Regarding the duration of storage of video and audio recordings
The Guidelines on video surveillance state that personal data may not be stored for longer than is necessary to achieve the purposes for which the personal data are processed (Article 5(1)(c) and (e) of the GDPR). The Guidelines on video surveillance also state that the storage period must be
clearly defined and set separately for each specific purpose. It is the data controller, taking into account the principles of necessity and proportionality, who must define the retention period and prove compliance with the GDPR provisions. During the on-site inspection, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the video recordings made are stored on two different video recording devices. After checking the oldest saved recordings, it was established that the dates of the oldest saved video recordings on the first video recording device were 2025-05-03 (i.e. 20 calendar days), and on the second video recording device, the dates of the oldest saved video recordings were 2025-02-27 (i.e. almost 3 months). The video recordings recorded on the first and second video recording devices are viewed only on devices located in a specially designated room, and remote access to the devices is not possible.
14
In the case under consideration, the Inspected Person submitted to the Inspection relevant documents for the inspection.
For example, from the Information for Patients on Personal Data Processed at the Biržai Public Hospital, approved by the Hospital Director's Order No. PVK-42 of 2024-06-18, paragraph 4.9, it can be seen that the established storage period for video data is 14 days. Meanwhile, the PDAV report submitted to the Inspection on 2025-02-03 provides that the storage period for video records is 14 days, except for video records made in the admission and emergency departments; video records made in this department are stored for 30 days. It is indicated that these terms are based on the aim of identifying events related to the security of visitors, employees, documents and property. It is also indicated that after the expiration of the storage period of the recordings, older video recordings are automatically deleted from the video recording device, and new recordings are recorded in the vacated space; backup copies of video recordings are not made. It can be seen from paragraph 22 of the Description of the Procedure for Video and Audio Monitoring and Recording in the Provision of Personal Health Care Services and for the Management of Video and Audio Recording Data of the Public Institution Biržai Hospital, approved by the Hospital Director's Order No. PVK-8 of 25 March 2025, that video and/or audio data are stored in the storage facility for 1 month from the date of their recording. From the above, it is obvious that the Inspected Person has not established a specific and clearly defined storage period for video and audio recordings, i.e. in one place a storage period of 14 days is provided for, in another place a storage period of 30 days. In addition, after the inspection, the Hospital submitted additional explanations (Inspection reg. No. 1R-3973 (2.13 Mr)), in which it acknowledged that the video recordings were actually stored for significantly longer than 30 days7. For this reason, a commission was established by order of the Hospital Director to manually destroy the video data. The Inspected Person explained that the data stored for an excessive period of time has been deleted, and also indicated that it is currently ensured that the video recordings are stored on the devices for no longer than the specified period. Summarizing the above, the Inspectorate concludes that the Inspected Person has not fulfilled its obligation to accurately determine the storage period(s) of video and audio recordings. In addition, the video and audio recordings were actually stored for an obviously excessive period of time (i.e., the video and audio recordings were actually stored for almost 3 months). In view of this, it is concluded that the Person Subject to Inspection has violated the principle of limitation of the storage period established in Article 5(1)(e) of the GDPR by these actions.
4.4. Regarding ensuring access control
According to Article 5(1)(f) of the GDPR, personal data must be processed in such a way that, by applying appropriate technical or organizational measures, appropriate security of personal data is ensured, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage (principle of integrity and confidentiality).
The Guidelines on video surveillance state that in the context of video surveillance, security aspects include the confidentiality, integrity and availability of the system and data. That is, the security of the video and audio recording system includes: 1) the physical security of all system components and 2) access control to the video surveillance system, while data security includes the prevention of data loss or manipulation.
During the on-site inspection, access rights were checked and assessed. During the on-site inspection, it was established that the image monitored by the video surveillance cameras located on the territory and premises of the Hospital (except for the Operating Rooms) is recorded, and the videos made are stored in two different video recording devices. The videos recorded in the first and second video recording devices are viewed only on devices located in a specially designated room, and remote access to the devices is not possible. Access to the said room and to the video recording device is not possible. 7 I.e. During the on-site inspection held on 2025-05-22, it was established that the oldest saved video recording in the video recording device was recorded on 2025-02-27. 15 Only an authorized person [DATA NOT PUBLISHED] who has signed a pledge to maintain the confidentiality of the data can log in. Taking this into account, it is concluded that the security of video and audio recordings made on the territory and premises of the Hospital (except for the Operating Rooms) is sufficiently ensured, i.e. sufficient access control is ensured. However, during the on-site inspection, it was established that the image captured by the video surveillance cameras located in the Hospital's Operating Rooms is broadcast directly to the computer of the authorized employee [DATA NOT PUBLISHED]. The computer workstation of the authorized employee [DATA NOT PUBLISHED] is protected by a password, and the employee's account in the video surveillance program, through which the image and sound from the Operating Rooms are broadcast, is also protected by a password. The aforementioned employee uses only ordinary user rights in the video surveillance program, therefore, does not have the ability to save video recordings. The inspection report concluded that physical access to the authorized employee's computer workstation is sufficiently ensured. However, the Inspection Report states that during the on-site inspection, the Hospital representatives could not indicate who has privileged access rights to the program, nor could they answer whether there is a video recording device for the cameras in the Operating Rooms (and if so, in which location), therefore, the Inspection staff were not given the opportunity to determine which persons have access to the program (i.e. live broadcast video and audio), nor was it possible to determine whether video recordings are made during video surveillance in the Operating Rooms. For this reason, after the on-site inspection, the Inspected Person was additionally contacted with instruction No. 2R-3401 (2.14 E) to provide additional information: 1) to indicate who has privileged access rights to the program through which the images captured by the three video surveillance cameras in the Operating Rooms are monitored and to perform its software and technical maintenance. Also indicate what rights a user with privileged access rights has in this program (e.g. to make video recordings, view the oldest video recordings, etc.), if not, provide supporting evidence; 2) indicate whether a video recording device (NVR / DVR) is used, in which video recordings from video cameras located in the operating rooms are stored. If so, provide the system connection logs of this video recording device (NVR / DVR). Also indicate whether the video recording device (NVR / DVR) used has a remote access function, provide supporting evidence and the model of the video recording device used; 3) indicate whether the device on which the video surveillance program8 is installed can be connected remotely. If so, indicate how the device is connected and who can connect; 4) indicate whether a service agreement has been concluded with third parties for the maintenance or administration of the video surveillance system. If so, provide copies of the service agreement and data processing agreement. The inspected person submitted a response to the Inspectorate's instruction (Inspection reg. No. 1R-5255 (2.14 K)) on 2025-08-07, in which it stated that: 1) privileged access rights to the program through which the images captured by the three video cameras in the Operating Rooms are monitored are held by an authorized employee [DATA NOT PUBLISHED], who is responsible for the software and technical maintenance of the video equipment and their preparation for use; 2) the video recording device is not used, and the video data from the video surveillance cameras in the Operating Rooms are not recorded and are not stored. The image can only be viewed in real time by the aforementioned authorized employee [DATA NOT PUBLISHED]; 3) there is no possibility of remotely connecting to the device containing the program through which the images of the three video cameras in the Operating Rooms are monitored; 4) a service agreement with third parties for the maintenance and administration of the video surveillance system has not been concluded. Together with the response to the Inspection's order, the Inspected Person
did not submit any attachments - evidence substantiating the statements made in the response. Thus, together with the response to the order, the Inspection was not provided with any evidence that would allow it to determine who has
actual access to the program and whether video recordings are actually being made. For these reasons,
8 Name of the program used: "Avtech CMS LITE"
16
The Inspection staff were not given the opportunity to determine who has actual access to the program
(i.e. live broadcast video and audio) and whether the image monitored in the Operations Room is not being recorded.
It should be noted that the Inspectorate has the right to receive free of charge from data controllers and data processors, state and municipal institutions and bodies, other legal and natural persons all necessary information, copies of documents, copies of data, as well as to familiarize itself with all data and documents necessary for performing the tasks and functions of the supervisory authority (Article 12, Part 2, Item 1 of the Personal Data Protection Act). Legal and natural persons must comply with the requirements of the supervisory authority, immediately provide information and (or) explanations, copies of documents, copies of data, and provide access to all data and (or) equipment related to the processing of personal data, and documents necessary for performing the functions of the supervisory authority (Article 14 of the Personal Data Protection Act). Pursuant to Article 5(2) of the GDPR, the accountability principle consists of two parts – the responsibility of the data controller to ensure compliance of its activities with the requirements of the GDPR and the ability of the data controller to demonstrate that compliance to the supervisory authority (Supreme Administrative Court of Lithuania, 2021-07-02, Administrative Case No. eA-745-261/2021). The data controller is responsible for compliance with the principles set out in Article 5(1) of the GDPR relating to the processing of personal data and must be able to demonstrate this. The data controller must prove that the personal data could have been processed and that the principles set out in Article 5(1) of the GDPR relating to the processing of personal data were not infringed as a result (i.e. the principle of lawfulness, fairness and transparency; the principle of purpose limitation; the principle of data minimisation; the principle of accuracy; the principle of storage limitation; the principle of integrity and confidentiality). This means that the data controller has the obligation to provide sufficient supporting evidence (decision of the Supreme Administrative Court of Lithuania of 2020-07-08 in administrative case No. eA-2837-968/2020; ruling of 2021-03-31 in administrative case No. eA-2229-968/2021; ruling of 2021-07-02 in administrative case No. eA-745-261/2021).
According to Article 31 of the GDPR, the controller and the processor must cooperate with the supervisory authority at its request in carrying out the tasks assigned to it. This provision is mandatory and not subject to exceptions. Article 57 of the GDPR defines the tasks of the Inspectorate, including monitoring the application of the GDPR, collecting information and conducting investigations. Article 58(1)(a) of the GDPR establishes that the supervisory authority has the power to order the controller and the processor and, where applicable, the controller's or processor's representative, to provide all information necessary for its tasks.
Taking into account the aforementioned provisions of the GDPR, the Inspectorate, when carrying out an on-site inspection of the Hospital, i.e. in carrying out the task set out in Article 57(1)(a) of the GDPR, ordered the Inspection to provide the information necessary for the performance of the task (Article 58(1) of the GDPR), however, the Inspected
person did not provide the requested information during the on-site inspection (i.e. indicated that he did not know this information), and responded to the written instruction of the Inspection only formally and incompletely, without providing any evidence.
Based on the information set out above, the Inspection decides that the Inspected
person, being informed in advance of the intended on-site inspection and having the obligation to implement the accountability principle established in Article 5(2) of the GDPR, should have been able to provide the information necessary for the inspection related to the security of the personal data processed and access to the video surveillance system. In addition, the Inspected
person was obliged to respond in full to the instruction given by the Inspection after the inspection and to provide evidence confirming the indicated circumstances.
In the case under consideration, the Inspected Person submitted a formal response to the Inspectorate's order, but did not provide the Inspectorate with all the requested information. That is, the response did not indicate and explain what rights a user with privileged access rights has in the program used (e.g. whether he can make video recordings, view the oldest video recordings, etc.) and did not provide evidence from which the Inspectorate could draw conclusions about the aforementioned circumstances. Taking this into account, it is concluded that the Inspected Person did not cooperate sufficiently with the Inspectorate, thus failing to comply with the Inspectorate's orders to provide all the information necessary to perform its tasks (Article 58(1)(a) of the GDPR). According to the most relevant case law of the Supreme Administrative Court of Lithuania, the accountability principle established in Article 5(2) of the GDPR consists of two cumulative conditions, i.e. the data controller must not only comply with the GDPR, but also be able to prove it. The data controller's non-cooperation and inability to eliminate reasonable doubts regarding the processing of personal data shall be to the detriment of the data controller (the Supreme Administrative Court of Lithuania of 17 December 2025 in administrative case No. eA-704-629/2025). It should be noted that the EDPB has noted in the Guidelines on video surveillance that data controllers, when developing their video surveillance policies and procedures, must consider, among other things, who is responsible for the management and operation of the video surveillance system, and must also provide for who has access to the video recordings and for what purposes. Consequently, the data controller has an obligation to know who has access to the video surveillance system and the video and/or audio recordings made. In addition, by Resolution of the Government of the Republic of Lithuania of 6 November 2024 No. 945 “On the Implementation of the Law of the Republic of Lithuania on Cybersecurity” approved by the Cybersecurity Requirements (hereinafter referred to as the Cybersecurity Requirements) in paragraph 66 states that a list of persons granted administrator rights to access networks and information systems must be approved. Taking this into account, the data controller must ensure that a list of persons granted privileged access rights to networks and information systems is drawn up. In the case under consideration, the Inspectorate has been provided with the Order of the Hospital Director No. PVK-11 of 27 March 2025 on granting access to video data (hereinafter referred to as the Order). The Order provides that the right to access the Hospital’s video surveillance camera recording device is granted to the employee [DATA NOT PUBLISHED]. Meanwhile, the right to access the video data recorded in the Hospital’s Operating Rooms is granted to the employee [DATA NOT PUBLISHED]. Thus, it is obvious that the right of access to the video data recorded in the Hospital's Operating Rooms is granted by the Order to only one employee [DATA NOT PUBLISHED]. However, during the on-site inspection, the representatives of the Inspected Person (DPO and the Hospital Director) stated that they did not know who in the program (which is used to monitor the Hospital's Operating Rooms) has privileged access rights (administrator rights) and whether the video recording device of the cameras located in the Operating Rooms is used. The Inspected Person does not have an approved list of persons who have been granted administrator rights in the video surveillance program, as required by the Description of Cybersecurity Requirements. In addition, according to the explanations provided by the Inspected Person in writing on 07-08-2025 (Inspection reg. No. 1R-5255 (2.14 K), it can be seen that the actual privileged access rights (administrator rights) to the video surveillance program used in the Hospital's Operating Rooms are not held by the employee authorized by the Order [DATA NOT PUBLISHED], but by another employee [DATA NOT PUBLISHED], who is not granted the right to access the video data recorded in the Hospital's Operating Rooms by the Order. Having assessed the above, the Inspection concludes that access control to the video and audio broadcasting carried out in the Hospital's Operating Rooms was not properly ensured. The Inspected Person, when carrying out video surveillance and audio recording, especially when doing so in the Hospital's Operating Rooms - extremely sensitive premises where high confidentiality is expected, unequivocally had and must know which specific persons have access to the program and what actions in the program, these
persons can perform. Taking into account the above, the Inspectorate concludes that the Inspected Person
violated the principle of integrity and confidentiality established in Article 5, Part 1, Point f of the GDPR.
Having assessed the violations committed by the Inspected Person, the Inspectorate decided to initiate the procedure for imposing an administrative fine on 30 December 2025
by Decision No. 3R-1876 (2.13-1.E) (hereinafter referred to as the Decision).
18
In accordance with Article 34, Part 1 of the ADTAĮ, the Inspectorate submitted a proposal to impose an administrative fine on the Inspected Person by Letter No. 2R-101 (2.14 E) on 8 January 2026
by Letter No. 2R-101 (2.14 E), indicating: 1) to provide
explanations regarding the circumstances set out in this Letter of the Inspectorate, except for what was already provided during the inspection, and to provide information relevant to imposing an administrative fine (pursuant to Article 83(2) of the GDPR); 2) express an opinion on the procedure for examining the case; 3) provide information on the budget of the Inspected Person for the current year and the amount of other gross annual income received in the previous year, and in the event that the Inspected Person carries out economic and commercial activities, provide information on the gross annual global turnover for the financial year 2025. 5. Written explanations received after the proposal to impose a fine On 21 January 2026, the Inspectorate received written explanations from the Inspected Person regarding the Inspectorate's proposal to impose a fine (Inspection reg. No. 1R-472 (2.13.Mr)) (hereinafter referred to as the Written Explanations), in which the Inspected Person indicated that he or she agreed to the case being examined in accordance with the written procedure. The inspected person also stated that he acknowledged the violations identified by the Inspectorate and sincerely regretted their commission, but emphasized that the violations were not committed intentionally or due to negligence, but due to insufficient knowledge and experience in the field of personal data protection and limited human resources. The inspected person also spoke about the circumstances of the audio recording. The person under inspection stated that he acknowledged that he had applied the audio recording too widely, but also indicated that he was drawing the Inspectorate's attention to the circumstances under which the decision to conduct the audio recording was made - he indicated that an amendment to Article 9, paragraph 5, of the Law on Patients' Rights and Compensation for Damage to Health of the Republic of Lithuania (hereinafter referred to as the Law on Patients' Rights and Compensation for Damage to Health) came into force on 1 January 2025, which establishes that when providing personal health care services outside the premises of a personal health care institution and (or) emergency medical assistance services in the premises of the emergency medical assistance unit of a personal health care institution, video and (or) audio monitoring and (or) recording may be carried out in accordance with the procedure established by the Minister of Health for the purposes of ensuring the safety of patients and (or) healthcare professionals. The person under inspection also indicated that by Order No. 21 of the Minister of Health of 2025-03-21 of the Minister of Health V-252 approved the Description of the Procedure for Video and Audio Monitoring and Recording in the Provision of Personal Healthcare Services and for the Processing of Video and Audio Data, which provides that video and/or audio data may be processed: 1) for the purpose of ensuring the safety of patients and/or healthcare professionals; 2) for the prevention, detection and investigation of administrative offences and criminal acts; 3) for the examination of complaints related to the provision of personal healthcare services. The person under inspection emphasized that the Ministry of Health actively encouraged healthcare institutions to combat psychological and physical violence against healthcare professionals. The person under inspection indicated that, taking into account the aforementioned legal acts and in order to protect his employees from psychological violence, he began to process audio data, being convinced that he was doing so in accordance with the requirements of legal acts. It noted that the goals and interests of the Hospital were legitimate and met the requirements of the PTŽSAĮ and the Ministry of Health, but due to ignorance and inexperience, the audio recording was applied too broadly. The Hospital also drew the attention of the Inspectorate to the fact that without audio recording, it is practically impossible for the Hospital to prove psychological violence against employees by patients and/or their relatives. The Hospital noted that, to its knowledge, the Inspectorate has not published specific guidelines on how video and audio data should be processed in personal health care institutions in accordance with the new legal regulation.
The Hospital stated that it disagreed with the Inspectorate's conclusion regarding inadequate cooperation. The Hospital
indicated that it believed that cooperation with the Inspectorate was sufficient and fair. The Hospital
noted that the alleged non-cooperation with the Inspectorate could only have occurred due to a lack of communication, and not due to a desire to conceal information. The written explanations stated that
19
Hospital representatives with medical education found it difficult to understand the technical terms used by the Inspectorate's specialists, so it may have seemed to them that not all of the information was provided. The written explanations stated that the Hospital created all the conditions for the inspection to the best of its ability, and that misunderstanding of information technology terms cannot be considered non-cooperation. It emphasized that the Hospital responded to the Inspectorate's instruction No. 2R-
3401 (2.14 E), and the Inspectorate, having received the Hospital's responses, did not submit any additional requests or clarifications.
The written explanations also drew attention to the fact that the Hospital is a small public institution belonging to the Lithuanian national health system, providing personal health care services, does not carry out any commercial activities and is financed exclusively from the funds of the Mandatory Health Insurance. The Hospital indicated that the gross annual income for the 2025 financial year amounted to EUR 7,574,678, and the estimated budget for 2026 is EUR 7,570,000. It noted that as much as 83.9% of the total Hospital budget is allocated to employee salaries, 6% to the purchase of medicines and medical devices, and 9% to utility and operating costs.
The hospital also indicated that it requested the Inspectorate, when deciding on the amount of the fine, to take into account the fact that the violations committed were not intentional and did not cause any harm to the data subjects, i.e. there is no information that the video or audio recordings were illegally disclosed to third parties or used for purposes other than their intended purpose. In addition, the violations were not committed intentionally, but due to negligence arising from insufficient knowledge and experience in the field of personal data protection. The hospital honestly believed that its actions met the requirements of legal acts and sought to implement new requirements for combating psychological violence, provided for in the Act on the Protection of Personal Data and Order No. V-252 of the Minister of Health of 21 March 2025. It also noted that the Hospital promptly complied with all the Inspectorate's instructions: it terminated video surveillance in the Hospital's operating rooms, terminated audio recording, established precise terms for storing video recordings and adjusted the camera surveillance fields. The Hospital also states that the Hospital had implemented organizational and technical measures in accordance with the available resources: a data protection officer was appointed, a data protection impact assessment was conducted, internal documents were prepared; the violations arose due to the insufficient effectiveness of these measures, and not due to their absence. Attention was also drawn to the fact that the Hospital had not previously been fined for GDPR violations, the Hospital cooperated with the Inspectorate within its capabilities and competences, created conditions for the inspection, and responded to inquiries in a timely manner. It also indicated that although it was established during the inspection that health data could theoretically have been processed, there is no evidence that such data was actually collected or used for purposes other than its intended purpose. The Hospital additionally noted that it is a public institution financed from state funds, therefore a large fine would significantly affect the Hospital's ability to provide quality healthcare services, and therefore the public interest could be violated in this way. It also indicated that the Hospital has not received a single complaint from patients or employees regarding the use of video surveillance cameras. The Hospital requests the Inspectorate: 1) not to impose an administrative fine or, if a fine is imposed, to impose a minimum fine, taking into account the above-mentioned mitigating circumstances; 2) to take into account the fact that the Hospital is a public institution that does not carry out commercial activities and is financed exclusively from state funds, therefore a large fine would negatively affect the Hospital's ability to carry out its main mission - to provide healthcare services to the residents of the district. 6. Assessment of the explanations received from the Inspected Person after the proposal to impose a fine regarding the circumstances of the audio recording, the Inspectorate, taking into account the Written explanations submitted by the Hospital, first of all draws the Hospital's attention to the full wording of Article 9, Paragraph 5 of the PTŽSAĮ, and not only its first part. It should be noted that although Article 9(5) of the Act on Personal Data Protection provides that “when providing personal health care services outside the premises of a personal health care institution and/or emergency medical care services in the premises of the emergency medical care unit of a personal health care institution, video and/or audio monitoring and/or recording may be carried out in accordance with the procedure established by the Minister of Health for the purposes of ensuring the safety of patients and/or healthcare professionals”, the same legal norm also states that the processing of video and/or audio data must comply with the requirements established by the GDPR. By Order No. 21/2025 of the Minister of Health V-252 approved description (hereinafter referred to as Description9) in paragraph 1 establishes that this Description establishes the procedure for video and audio monitoring and recording when providing personal health care services outside the premises of a personal health care institution (hereinafter referred to as a PHC) (emergency medical care services, outpatient home care services, family medicine services at home, family doctor teams or primary outpatient dental personal health care services in a mobile clinic, mobile outpatient dental care (assistance) services, etc.) and (or) emergency medical care services in the premises of the emergency medical care unit of a personal health care institution (hereinafter referred to as services) and the procedure for processing video and audio data. Thus, the aforementioned legal acts regulate the procedure for processing video and/or audio data when video monitoring and audio recording are carried out in specifically named places, and not in all (or any) premises of a PHC (e.g. hospital corridors, operating rooms, etc.). Therefore, in the case under consideration, the aforementioned legal acts are relevant only when assessing the processing of video and audio data in emergency medical care facilities. When assessing the lawfulness of the processing of video and audio data in other hospital facilities (such as corridors, operating rooms, etc.), the aforementioned legal acts are not relevant. It should be noted that Article 9(5) of the Act on the Protection of Personal Data and the Description provide for the possibility of recording video and/or audio in emergency medical care facilities in order to ensure safety, prevent psychological or physical violence, etc. However, the provision of such a possibility constitutes the basis for substantiating the existence of legitimate interests of the data controller in specific situations based on the aforementioned legal acts – one of the three cumulative conditions for the application of Article 6(1)(f) of the GDPR. The Inspectorate emphasizes that the mere fact that legal acts provide for the possibility of video and/or audio recording to a certain extent in order to achieve the above-mentioned purposes does not mean that the data controller may process personal data without assessing whether the other two cumulative conditions of lawfulness actually exist, i.e. without qualitatively assessing whether the processing of personal data is necessary to implement an existing legitimate interest (second cumulative condition) and without qualitatively assessing the primacy of opposing rights and interests (without conducting a balancing test of interests) (third cumulative condition). Regarding cooperation with the Inspectorate, the Inspectorate also notes that the Inspectorate has the right to receive free of charge from data controllers
and data processors, state and municipal institutions and bodies, other legal and natural persons
all necessary information, copies and transcripts of documents, copies of data, as well as to familiarize itself with
all data and documents necessary for performing the tasks and functions of the supervisory authority
(Article 12, Part 2, Item 1 of the ADTAĮ).
Legal and natural persons must comply with the requirements of the supervisory authority, immediately
provide information and (or) explanations, copies and transcripts of documents, copies of data, create
conditions for familiarization with all data and (or) equipment related to the processing of personal data, and
documents necessary for performing the functions of the supervisory authority (Article 14 of the ADTAĮ).
9 March 21, 2025 Order No. V-252 approved the Description of the Procedure for Video and Audio Surveillance and Recording in the Provision of Personal Health Care Services and for the Processing of Video and Audio Data.
21
According to Article 31 of the GDPR, the data controller and the data processor must cooperate with the supervisory authority at its request in carrying out the tasks assigned to it. This provision is mandatory and is not subject to exceptions.
Article 57 of the GDPR defines the tasks of the Inspectorate, including monitoring the application of the GDPR, collecting information and conducting investigations.
Article 58(1)(a) of the GDPR establishes that the supervisory authority has the authority to instruct the data controller and the data processor and, where applicable, the data controller's or the data processor's representative to provide all information necessary for its tasks.
Taking into account the aforementioned provisions of the GDPR, the Inspectorate, when conducting an on-site inspection of the Hospital (in pursuance of the task set out in Article 57(1)(a) of the GDPR), asked the Hospital's representatives questions relevant to the inspection. It should be noted that the Inspectorate conducted the on-site inspection after warning the Inspected Person, so the latter had the opportunity to prepare for the planned inspection. However, the Inspection Report states that during the on-site inspection, the Hospital representatives stated that they were unable to indicate who has privileged access rights to the program used for video monitoring and audio listening/recording of the Hospital's Operating Rooms, and were also unable to answer the question of whether there is a video recording device for the cameras in the Operating Rooms (and if so, where it is located), therefore, the Inspection staff were not given the opportunity to determine which persons actually have access to the program (i.e. live broadcast video and audio), and were also not given the opportunity to determine whether video recordings (and audio recordings, respectively) are made during video monitoring in the Operating Rooms. It should be noted that for this reason, after the on-site inspection, the Inspected Person was additionally contacted with instruction No. 2R-3401 (2.14 E) to provide additional information. It should be noted that although the Inspected Person submitted declarative responses to the Inspectorate's order, he did not submit any annexes or evidence together with the response substantiating the statements of the Inspected Person in the response. For these reasons, the Inspectorate's employees were not given the opportunity to determine who has actual access to the program (i.e. live broadcast video and audio) and whether the video and audio are not recorded in the Operations. For this reason, the Inspectorate concluded that the Inspected Person did not cooperate properly by not providing the requested information in accordance with Article 58(1)(a) of the GDPR.
It should be noted that in the event that during the on-site inspection, the Hospital representatives had difficulty in understanding the essence of the questions asked or the terms used, the latter had both the opportunity and the obligation to cooperate - to ask, clarify, etc. It is worth noting that the Inspectorate, specifically having assessed the circumstance that during the on-site inspection it was difficult for the Hospital representatives to consistently respond to the questions asked, requested that the information be provided in writing and set a sufficient deadline for explanations and the submission of the necessary evidence. However, the Inspected Person also responded to the questions submitted in writing only formally, without substantiating his stated statements with objective evidence.
The Inspectorate will address other arguments presented in the Written Explanations of the Inspected Person related to the determination of the amount of the fine further in this decision.
7. Reasons for the decision to impose/not impose an administrative fine
In accordance with Article 83(1) of the GDPR, the supervisory authority shall ensure that the administrative fines imposed in accordance with this Article of the GDPR for infringements referred to in paragraphs 4, 5 and 6 of this Regulation are, in each case, effective, proportionate and dissuasive. In accordance with Article 83(2) of the GDPR, administrative fines shall be imposed in addition to or instead of the measures referred to in points (a) to (h) and (j) of Article 58(2) of the GDPR, taking into account the circumstances of each case.
When deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine, due account shall be taken of the following in each case: a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected and the extent of the damage suffered by them; (b) whether the breach was committed intentionally or negligently; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the extent of the liability of the controller or processor, taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32; (e) any significant previous breaches by that controller or processor; (f) the cooperation with the supervisory authority to remedy the breach and to mitigate its potential adverse effects; (g) the categories of personal data affected by the breach; (h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach (and if so, to what extent); (i) where the measures referred to in Article 58(2) have previously been taken against the controller or processor in respect of the same subject matter, whether those measures have been complied with; (j) compliance with approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; (k) other aggravating or mitigating factors relating to the circumstances of the case, such as financial benefits gained or losses avoided, directly or indirectly as a result of the infringement. According to recital 129 of the GDPR, the measure taken by the supervisory authority should be appropriate, necessary and proportionate to ensure compliance with the GDPR, taking into account the circumstances of each case, respect the right of each individual to be heard before any specific measure which would adversely affect them is taken, and be applied in a way that does not entail unnecessary costs or disproportionate inconvenience for the individuals concerned. Recital 129 of the GDPR states that, in order to ensure consistent monitoring of the application of this Regulation and its enforcement throughout the European Union, supervisory authorities in each Member State should carry out the same tasks and exercise the same effective powers, including investigative powers, powers to take corrective action and impose sanctions, as well as authorisation and advisory powers, in particular in cases where complaints are received from natural persons, and, without prejudice to the powers of criminal prosecution authorities under Member State law, to bring infringements of this Regulation to the attention of judicial authorities and/or to be a party to legal proceedings. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards laid down in Union and Member State law, impartially, fairly and within a reasonable time. In particular, any measure should be appropriate, necessary and proportionate to ensure compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of each individual to be heard before a specific measure is taken which would adversely affect them, and be applied in a way that does not entail unnecessary costs and disproportionate inconvenience for the individuals concerned. In order to ensure a consistent approach to the imposition of administrative fines, the EDPB has adopted Guidelines on the calculation of administrative fines10, which state that the administrative fines imposed should be proportionate to the nature, gravity and consequences of the infringement. Those Guidelines state that each case must be assessed individually, and Article 83(2) of the GDPR is the starting point for such an individual assessment. These Guidelines provide an interpretation of the assessment criteria set out in Article 83(2) of the GDPR, which is relied upon below in this Decision. In addition, the aforementioned guidelines set out the methodology for calculating fines and state that the following three elements must be taken into account when imposing fines: the classification of the infringements by nature, the gravity of the infringement and the turnover of the undertaking, and also state that data protection authorities must also take into account aggravating or mitigating circumstances, which may increase or decrease the fine and which are explained in a consistent manner by the EDPB. 10 European Data Protection Board Guidelines No. 04/2022 of 24 May 2023 on the calculation of administrative fines under the GDPR (hereinafter referred to as the Guidelines on the calculation of administrative fines). 23
When assessing the information collected during the inspection and provided in this decision, when deciding whether to impose an administrative fine on the Inspected Person and when deciding on the amount of the administrative fine, the Inspectorate shall take into account the following aspects set out in Article 83(2) of the GDPR:
24
i) Article 83(2)(a) of the GDPR – nature, severity and duration of the infringement
The infringements of Article 5(1)(a), (e) and (f) of the GDPR, as well as the infringements of Article 6(1) of the GDPR and Article 9(2) of the GDPR, and the infringement of Article 58(1)(a) of the GDPR established in respect of the Inspected Person, comply with the provisions of Article 83(5)(a) and (e) of the GDPR. It should be noted that the infringements of Article 83(4) of the GDPR are classified as minor infringements, while the infringements of Article 83(5) of the GDPR are classified as more serious.
The Guidelines on the calculation of fines state that the seriousness of the infringement is assessed in accordance with the specific circumstances and this includes, among other things, the nature of the processing, as well as the scope, the purpose of the processing, the number of data subjects affected (actually and potentially) and the amount of damage. The Inspectorate further comments on each of them: a) The nature of the data processing and the purpose of the data processing. In the case under consideration, the infringements identified relate to unlawful video surveillance and recording, unlawful audio recording and eavesdropping on the premises of the Hospital (including such premises as the Operating Theatre), as well as insufficient cooperation with the Inspectorate by failing to provide the requested information in accordance with Article 58(1)(a) of the GDPR. It should be noted that although the Hospital, when processing personal data on the premises of the Hospital, pursued legitimate objectives (ensuring security and proper work organization, etc.), it failed to fulfill its obligation as a data controller to assess the necessity of processing personal data and the legitimate interests of data subjects. The Hospital processes the personal data of patients and visitors, as well as Hospital employees, therefore, in the case under consideration, there is a clear imbalance of power between the data subjects and the data controller11. In addition, the Hospital's insufficient cooperation directly hindered the establishment of factual circumstances relevant to the inspection. b) Regarding the scope of data processing. The Guidelines on the Calculation of Administrative Fines state that the greater the scope of data processing, the more importance the supervisory authority may attach to this factor. In the case under consideration, the data controller is a public institution classified at the district level, providing personal healthcare services to the residents of the Biržai district. Thus, the Subject does not carry out activities on a national or international scale, and therefore does not process personal data on a national or international scale. c) Regarding the number of data subjects affected. The EDPB Guidelines on the calculation of administrative fines state that assessing the number of data subjects affected is necessary to determine whether it is an isolated incident or a sign of a systemic breach. In many cases, it can also be considered that the breach is based on “systemic” implications and may therefore affect additional data subjects who have not submitted complaints or notifications to the supervisory authority, even at different times12. In the case at hand, taking into account the nature of the personal data processing, i.e. i.e., that the unlawful video surveillance and recording, as well as the audio recording and eavesdropping were carried out on the premises of the Hospital, it is obvious that the data processing is not related to the processing of data of individual persons, and therefore should be assessed as the systematic processing of personal data of each person (patients, visitors, employees) present on the premises of the Hospital. d) Regarding the amount of damage. When assessing the damage, it should be noted that the damage caused by the unlawful processing of personal data does not necessarily have to be material. Paragraph 75 of the GDPR preamble explains that risks of varying likelihood and seriousness to the rights and freedoms of natural persons may also arise from such data processing, where data subjects may lose the opportunity to exercise their rights and freedoms and are prevented from controlling their personal data. The Guidelines on the calculation of administrative fines
note that it is necessary to pay attention not only to the damage suffered (according to Recital 75 of the GDPR, the amount of damage suffered means bodily injury, material or non-material damage),
but also to the likely damage. The aforementioned Guidelines indicate that damage is assessed only to the extent that is functionally necessary
in order to correctly assess the gravity of the infringement and not to duplicate the activities of judicial authorities, which are tasked
11 Guidelines on the calculation of administrative fines, paragraph 53, point a, sub-point i
12 Guidelines on the calculation of administrative fines, paragraph 53, point a, sub-point iv
25
to determine different forms of individual damage,13. According to the Inspectorate's assessment, data subjects could have suffered only non-material damage due to the unlawful processing of image and audio data.
e) Duration of the infringements. The EDPB Guidelines on the calculation of fines indicate that the supervisory authority
may generally give greater weight to the infringement of longer duration. The longer the duration of the infringement,
the more weight the supervisory authority may give to this factor14. In the case under consideration,
it was established that the Hospital started to carry out the unlawful video surveillance and audio recording/listening of the investigated scope in the Hospital premises
(including the Operating Rooms) in March 2025, i.e. for less than a year.
Taking into account the above, as well as the fact that in the case under consideration the violations are not related to individual data subjects, but to a large number of them, as well as the fact that in the case under consideration the data subjects are to be considered more vulnerable (patients, employees), and in addition, taking into account the fact that the video and audio data of the data subjects were recorded in an environment where a high degree of privacy is expected (e.g. hospital operating rooms), the Inspectorate considers the actions of the Hospital to be an aggravating factor pursuant to Article 83(2)(a) of the GDPR. (ii) Article 83(2)(b) GDPR – whether the infringement was committed intentionally or negligently
The Guidelines on the calculation of administrative fines indicate that, in terms of the elements of an infringement, “intentional” includes both knowledge and deliberate action, while “negligent” means that there was no intention to commit an infringement, although the controller and/or processor breached a legal duty of care. The aforementioned Guidelines indicate that the intentional or negligent nature of the infringement (Article 83(2)(b) GDPR) should be assessed in the light of objective elements of conduct established in the assessment of the factual circumstances of the case. Taking into account the circumstances of the case, the supervisory authority may also give weight to the degree of negligence. In the best case, negligence could be considered neutral.
The Inspectorate, assessing the circumstances established during the inspection, states that there was no intent in the Hospital's actions. In the Inspectorate's assessment, although the Hospital, by choosing the form of data processing related to video and audio recording/direct observation and eavesdropping, sought to protect both its own interests and the interests of the data subjects, it did not fully assess the GDPR requirements and thus violated the duty of care established in the legal acts. Taking into account the above, the Inspectorate considers the Hospital's actions to be a neutral factor in accordance with Article 83(2)(b) of the GDPR. iii) Article 83(2)(c) of the GDPR – actions taken to mitigate the damage suffered by the data subjects The Guidelines on the Calculation of Administrative Fines state that appropriate measures to mitigate the damage suffered by the data subjects must be assessed primarily taking into account the element of timeliness, i.e. the time when the controller or processor implements them and their effectiveness. The EDPB emphasises that measures that were implemented spontaneously before the supervisory authority started the investigation and the controller or processor became aware of it are more likely to be considered as mitigating circumstances than those that were implemented after that point. In the case at hand, the Inspected Person did not take any independent action, therefore the Inspectorate considers the actions of the Inspected Person to be a neutral factor under Article 83(2)(b) of the GDPR. 13 Guidelines on the calculation of administrative fines, paragraph 53(a)(v)
14 Guidelines on the calculation of administrative fines, paragraph 53(c)
26
iv) Article 83(2)(d) GDPR – level of liability taking into account the technical and organisational measures implemented by the data controller in accordance with Articles 25 and 32
Articles 25 and 32 GDPR regulate the obligation of the data controller to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks involved in the processing of personal data. The Guidelines on the calculation of administrative fines note that, taking into account the increased level of accountability under the GDPR, it is likely that the degree of responsibility of the data controller or processor will be considered as an aggravating or neutral factor and only in exceptional circumstances, where the data controller or processor exceeds their obligations under Articles 25 and 32 of the GDPR, will this be considered as a mitigating circumstance. The Inspectorate did not establish that the Hospital exceeded its obligations under the GDPR and therefore considers the extent of the Hospital's liability to be a neutral factor. v) Article 83(2)(e) of the GDPR – Previous infringements of the person subject to inspection This criterion is intended to assess the reputation of the entity that committed the infringement. The Guidelines on the calculation of administrative fines indicate that the existence of previous infringements may be considered as an aggravating circumstance when calculating the fine. The importance of this factor must be determined taking into account the nature and frequency of previous violations. The aforementioned guidelines also note that the presence of previous violations may be considered an aggravating factor when calculating the administrative fine. The nature and frequency of previous violations are taken into account. However, it is emphasized that the absence of previous violations could not be considered a mitigating factor, since compliance with the GDPR is the norm and the fact that there are no previous violations could be considered neutral. The Inspectorate has no information that the Inspected Person has previously violated the provisions of the GDPR, therefore it considers the factor set out in Article 83(2)(e) of the GDPR to be neutral. vi) Article 83(2)(f) GDPR – cooperation with the Inspectorate in order to remedy the infringement and mitigate its potential negative impact
Article 83(2)(f) GDPR provides that cooperation with the supervisory authority may be “due regard” when deciding whether to impose an administrative fine and when setting the amount of the fine.
The Guidelines on the calculation of administrative fines state that, pursuant to Article 31 GDPR, the controller and the processor have a joint obligation to cooperate and that insufficient cooperation may lead to a fine under Article 83(4)(a) GDPR. Therefore, it should be considered that the normal obligation to cooperate is mandatory and should therefore be considered neutral (and not a mitigating circumstance).
In the case at hand, the Inspectorate, having carried out the inspection and adopted the Decision, gave instructions to the Inspected Person. It should be noted that the Inspected Person sent a letter to the Inspectorate on 14 January 2026 (Inspection reg. No. 1R-292 (2.13 Mr)), in which he indicated that he had complied with the instructions given by the Inspectorate. Considering that the Inspected Person, having received the instructions of the Inspectorate, seeks to comply with them and communicates with the Inspectorate on this issue, the Inspectorate considers the factor set out in Article 83(2)(f) of the GDPR to be neutral. vii) Article 83(2)(g) of the GDPR – categories of personal data affected by the breach The Guidelines on the calculation of fines note that the GDPR clearly specifies the types of data that require special protection and, therefore, a stricter response when imposing fines. This concerns at least the types of data referred to in Articles 27
9 and 10 of the GDPR and data falling outside the scope of these Articles, which directly harm or strain the data subject (such as, for example, location data, private conversation data, national identification numbers or financial data such as transaction overviews or credit card numbers). In general, the more categories of such data or the more sensitive the data, the more importance the supervisory authority may attach to this factor. It is also important to determine the amount of data relating to each data subject, taking into account that the increase in the amount of data of each data subject increases the infringement of the right to privacy and the protection of personal data. Considering that during the examination of the complaint it was established that the Person Subject to Inspection carried out video surveillance and audio recording/listening in the premises of the Hospital (including the Operating Rooms), i.e. personal data of patients were also processed (recorded), the Hospital considers the actions of the Hospital under Article 83(2)(g) of the GDPR as an aggravating factor.
viii) Article 83(2)(h) of the GDPR – The Inspectorate’s learning of the breach
The supervisory authority may learn of the breach during an investigation, after receiving complaints, from the media, anonymous reports or a report from the data controller. The Guidelines on the calculation of administrative fines state that special attention may be paid to the question of whether the data controller or data processor reported the breach on its own initiative before the supervisory authority learned of the breach, for example, after receiving a complaint or after conducting an investigation.
In the case under consideration, the breach was established after the Inspectorate conducted an inspection on its own initiative, after receiving information from the media, therefore this circumstance is considered neutral.
ix) Article 83(2)(i) of the GDPR – application of measures referred to in Article 58(2) of the GDPR to the inspected person
Article 83(2)(i) of the GDPR is related to the circumstance of assessing whether the data controller
complied with the measures referred to in Article 58(2) of the GDPR if these measures were previously applied to the data controller for the same matter.
Considering that no corrective measures were previously applied to the Inspected Person (prior to the inspection), the Inspectorate does not assess the factor referred to in Article 83(2)(i) of the GDPR.
x) Article 83(2)(j) of the GDPR – codes of conduct or certification mechanisms are applied to the inspected person
Considering that no certification mechanisms or a code of conduct are applied to the Inspected Person, this factor is not assessed.
xi) Article 83(2)(k) GDPR – other mitigating or aggravating factors
The Inspectorate has not identified any other mitigating or aggravating factors.
Taking into account the arguments set out above by the Inspectorate, the Inspectorate decides
to impose an administrative fine on the person subject to inspection.
28
8. Determination of the amount of the administrative fine
The Guidelines on the calculation of administrative fines establish that when imposing an administrative fine,
it is necessary to take into account three elements that are the basis for calculating the administrative fine:
the classification of infringements into categories according to their nature in accordance with Article 83(4)-(6) GDPR,
the gravity of the infringement and
the turnover of the undertaking as one of the important elements that must be taken into account in order to impose an effective, dissuasive and proportionate fine in accordance with
Article 83(1) GDPR.
The inspected person is a budgetary institution15. Article 33(2) of the GDPR provides that the supervisory authority has the right to impose an administrative fine on a government institution or body that has violated the provisions of Article 83(5)(a)–(e) of the GDPR and/or Article 83(6) of the GDPR in the amount of up to 1 percent of the government institution or body’s budget for the current year and other gross annual income received in the previous year, but not more than EUR 60,000.
In the case under consideration, the Inspected Person indicated that the gross annual income for the 2025 financial year amounted to EUR 7,574,678, and the estimated budget for 2026 is EUR 7,570,000. Taking this into account, the maximum amount of the fine cannot exceed EUR 60,000.
The Guidelines on the calculation of administrative fines state that, after assessing the infringement, the infringement may be classified as a minor, medium or major infringement. Accordingly, the initial amount of the fine is determined: for minor infringements, 0–10% of the maximum amount established by law; for medium infringements, 10–20% of the maximum amount established by law; for major infringements, 20–100% of the maximum amount established by law. The aforementioned Guidelines on the calculation of administrative fines explain that the severity of the infringement is determined taking into account points a, b and g of Article 83(2) of the GDPR, i.e. the severity of the overall infringement is determined by assessing the nature, gravity and duration of the infringement (point a of Article 83(2) of the GDPR); whether the violation was committed intentionally or negligently (Article 83(2)(b) of the GDPR) and the categories of personal data affected by the violation (Article 83(2)(g) of the GDPR).
The Inspectorate did not establish that the violations committed by the Inspected Person were committed intentionally, but
it established that the systematic processing of personal data (video surveillance and recording, audio recording
and eavesdropping), which are assessed as aggravating factors established in Article 83(2)(a) and (g) of the GDPR, constitute grounds for concluding that the violations committed by the Hospital are classified as violations of medium severity and in such a case the initial minimum fine shall be set at 10 to 20 percent of the maximum amount of the applicable fine.
The Inspectorate, taking into account the fact that out of the eight factors applied to the Inspected Person in accordance with Article 83(2) of the GDPR, two aggravating factors have been identified, the rest are neutral, and decides that the Inspected Person should be imposed a fine of 10% of the maximum amount applied (EUR 60,000), i.e. EUR 6,000 (the initial minimum fine). The Guidelines on the calculation of administrative fines state that when determining the final amount of the administrative fine, it is necessary to take into account other aggravating and mitigating factors specified in Article 83(2) of the GDPR and assessed in the decision on the imposition of a fine, which were not assessed when classifying the infringement as a minor, medium or major infringement. The Inspectorate, taking into account that no other mitigating factors have been established in the case under consideration, decides that the Inspected Person should be fined EUR 6,000. In the Inspectorate's assessment, a fine of this amount should be considered a proportionate measure of punishment. The Inspectorate, having regard to the provisions of this decision and in accordance with Article 58(2)(i), Article 83(1), (2), Article 83(4)(a) and (5)(a) of the GDPR, Article 34(10) of the ADTAĮ,
15 Data from the Register of Legal Entities
29
determines:
1. For the established violations of Article 5(1)(a), (e), (f) of the GDPR, violations of Article 6(1) of the GDPR and Article 9(2) of the GDPR and improper cooperation with the Inspectorate,
by failing to provide the requested information in accordance with Article 58(1)(a) of the GDPR,
to impose a fine of EUR 6,000 (six thousand euros) on the Inspected Person.
2. To inform the Inspected Person about the decision taken.
This decision may be appealed to the Regional Administrative Court (address: Žygimantų g. 2, Vilnius) within one month of its delivery in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania. In accordance with Article 35(1) of the Law on Administrative Procedure of the Republic of Lithuania, the fine imposed must be paid to the budget revenue collection account16 (contribution code 6803, recipient of funds State Tax Inspectorate under the Ministry of Finance of the Republic of Lithuania, legal entity code 188659752) no later than three months from the date of acceptance of the fine. Director Dijana Šinkūnienė16 No. LT787290000000130151 (AB “Citadele” bankas); No. LT744010051001324763 and No. LT122140030002680220
(Luminor Bank AS Lithuanian branch); No. LT057044060007887175 (AB SEB bankas); No. LT327180000000141038 (AB Šiaulių bankas); No. LT247300010112394300 (AB „Swedbank“); LT427230000000120025 (UAB Medicinos bankas).