VDAI (Lithuania) - 3R-882

From GDPRhub
VDAI - 3R-882
Authority: VDAI (Lithuania)
Jurisdiction: Lithuania
Relevant Law: Article 12(3) GDPR
Article 15(1) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 15.05.2026
Published:
Fine: n/a
Parties: UAB Whitebridge.ai
National Case Number/Name: 3R-882
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Lithuanian
Original Source: VDAI (in LT)
Initial Contributor: ap

The DPA found that a company providing AI powered reports of the “online presence” of data subjects failed to provide a data subject with access to their data, and ordered it to comply with the access request.

English Summary

Facts

UAB Whitebridge.ai (the controller) is a company that provides AI powered reports of the “online presence” and monitoring of data subjects. In 2025, a data subject filed a complaint with the DPA on the grounds that the controller did not provide them with access under Article 15 GDPR.

The controller argued that the data subject sent their access request to its general email address, and that the request had not been noticed due to the high volume of emails received for that address. Therefore, the controller was not able to process the request within the time frame under Article 12(3) GDPR. In addition, the controller stated it had introduced additional measures to respond to access requests in the future (including updating their privacy policy with the email address of their Data Protection Officer). Finally, the controller stated it would respond to the data subject’s access request.

Holding

The DPA found a violation of Articles 12(3) and 15(1) GDPR, as the controller failed to respond to the data subject’s access request.

The DPA ordered the controller to provide the data subject with access to their data, in accordance with Article 15(1) GDPR.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.

Extract of electronic document
STATE DATA PROTECTION INSPECTORATE
DECISION
2026 m. May No. 3R- (2.13-1.E)
Vilnius
The State Data Protection Inspectorate (hereinafter referred to as the Inspectorate) on 20-02-2025 received a complaint from the applicant [DATA NOT PUBLISHED] (hereinafter referred to as the Applicant) forwarded by the Austrian
data protection supervisory authority (Inspection reg. 1R-1331 (2.13 Mr)) (hereinafter referred to as the Complaint).
In the complaint, the Applicant states that UAB Whitebridge ai (hereinafter referred to as the Company) violated the Applicant
s right to access data in accordance with the provisions of Article 15 of the GDPR1.
The Inspectorate, being competent to act as the leading supervisory authority and to adopt a final decision on the Applicant's Complaint (Article 56, Article 60(7) of the GDPR), stated: On 3 April 2026, the Inspectorate received the Company's explanations (Inspection Reg. No. 1R-2553 (2.13 Mr)), in which the Company indicated that it had received the Applicant's request for access to the data, but it was not noticed and processed in a timely manner. The Company explained that the Applicant's request was submitted via the Company's general email address, through which the Company receives a large amount of various types of correspondence, including general inquiries, commercial offers, technical reports and other information related to the Company's activities. The Company indicated that due to the intensive general email traffic, the Applicant's request was not identified in a timely manner as a request from a data subject and, accordingly, was not properly processed within the time limit set out in Article 12(3) of the GDPR. The Company further explained that in order to ensure compliance with the GDPR, the Company 1) supplemented the privacy policy by indicating the e-mail address of the Company's data protection officer; 2) will clarify and formalize internal procedures related to the processing of data subjects' requests; 3) will increase the awareness of the Company's employees about the obligations provided for by the GDPR; 4) will provide a response to the Applicant's request for access to data.
Article 15, paragraph 1 of the GDPR establishes that the data subject has the right to obtain from the data controller confirmation as to whether personal data relating to him or her are being processed, and if such personal data are being processed, has the right to access the personal data and the information in points a-h of paragraph 1 of this Article. Paragraph 3 of the same Article provides that the data controller shall provide a copy of the personal data being processed.
Article 12(3) of the GDPR provides that the data controller shall, without undue delay and in any event not later than one month after receipt of the request, provide the data subject with information on the action taken in response to the request pursuant to Articles 15–22. In the case at hand, it was established that on 29 September 2025 the Applicant requested the Company to provide information pursuant to Article 15(1) of the GDPR, but the Company did not respond to the Applicant’s request either within the one-month period provided for in Article 12(3) of the GDPR or later. 1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR). 2
The Inspectorate, having assessed the circumstances indicated in the Applicant's Complaint, the Company's explanations and the legal regulation presented above, decides that the Company, by failing to provide a response to the Applicant's 2025-09-29 request for access to data, violated the provisions of Article 12, Part 3 and Article 15, Part 1 of the GDPR.
Based on the above circumstances and in accordance with Article 31, Part 2, Point 1 of the Law on the Legal Protection of Personal Data of the Republic of Lithuania (hereinafter referred to as the LPD) and Article 58, Part 2, Point c of the GDPR, the Company is instructed to properly implement the Applicant's 2025-09-29 request for access to data, as provided for in Article 15, Part 1 of the GDPR2.
The Inspectorate notes that, in accordance with Article 60(3) of the GDPR, on 10 April 2026, this draft decision was submitted to the relevant supervisory authorities for coordination via the European Commission's Internal Market Information System (IMI). Within the 4-week period set out in Article 60(4) of the GDPR (until 8 May 2026), the relevant supervisory authorities did not raise any relevant and reasoned objections to the draft decision. In view of this and in accordance with Article 60(6) of the GDPR, it is deemed that the lead supervisory authority and the relevant supervisory authorities have approved this draft decision, which is why it has become binding on them. Based on the above circumstances, as well as Article 31, Part 1, Point 1, Part 2, Point 1, Article 58, Part 2, Point c, Article 60, Part 7 of the ADTAĮ, the Inspectorate
n u s s e d:
1. To declare the Applicant's Complaint well-founded.
2. For violations of Article 12, Part 3 and Article 15, Part 1 of the GDPR, to issue an order to the Company, within one month from the date of receipt of this decision, to properly implement the Applicant's request of 2025-09-29 for the right to access data, as provided for in Article 15, Part 1 of the GDPR.
3. To inform the Company and the Applicant about the decision taken.
This decision may be appealed to the Regional Administrative Court
(address: Žygimantų g. 2, Vilnius) within one month from the date of its delivery, in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania.
Director Dijana Šinkūnienė
2 When implementing the data subject's right of access to data provided for in Article 15 of the GDPR, data controllers are recommended to refer to the European Data Protection Board Guidelines 01/2022 "on the rights of data subjects. Right of access to data".