VDAI (Lithuania) - Decision No. 3R-1700
| VDAI - Decision No. 3R-1700 | |
|---|---|
| [[File:|center|250px]] | |
| Authority: | VDAI (Lithuania) |
| Jurisdiction: | Lithuania |
| Relevant Law: | Article 5(1)(a) GDPR Article 6(1) GDPR Article 13 GDPR Article 13(1)(e) GDPR Article 28 GDPR |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | |
| Decided: | |
| Published: | |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | Decision No. 3R-1700 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Lithuanian |
| Original Source: | VDAI (in LT) |
| Initial Contributor: | lde |
The DPA held that the operator of a gambling site lawfully transferred data to a processor for sending invitations to sporting events since the engagement of a processor does not require a separate legal basis. However, the court found that the controller breached transparency obligations by not informing the data subject about the recipients of their personal data.
English Summary
Facts
The data subject lodged two complaints, later joined, with the DPA against a gambling operator, UAB Nesė (operating the website twinsbet.lt), alleging unlawful sharing of his personal data with third parties. The complaints concerned unsolicited telephone calls and messages inviting the applicant to sporting events sponsored by the operator, as well as a later customer service call regarding potential technical issues with the applicant’s gambling account.
The applicant claimed that his personal data, including his name, telephone number, and age, had been disclosed to third parties without a legal basis and without providing adequate information to the data subject. He further stated that the controller was unable to explain how his data had been obtained or shared, and that messages and call records had subsequently been deleted. The controller confirmed that the data subject had created an account on its platform in April 2024 and that his personal data had been transferred, on an ad hoc basis, to a service provider for the purpose of implementing a corporate social responsibility initiative. This initiative involved distributing invitations to sporting events to customers, and was described as non-commercial in nature. The controller and the service provider had concluded both a service agreement and a personal data processing agreement pursuant to Article 28 GDPR.
The controller stated that the service provider acted solely as a data processor and that the transferred data were limited to the applicant’s first name, surname, telephone number, and confirmation that he belonged to the age group over 20 years. The later customer service call in May 2025 was carried out by the controller’s own employee and was justified as necessary for the performance of the contract under Article 6(1)(b) GDPR.
Holding
The DPA first found that the transfer of the applicant’s personal data to the service provider constituted processing by a data processor acting on behalf of the controller within the meaning of Articles 4(8) and 28 GDPR. As such, the transfer did not require an independent legal basis under Article 6(1) GDPR and could not, in itself, be objected to by the data subject. The complaint concerning the alleged unlawful transfer of data to a third party was therefore rejected.
The Inspectorate further accepted that the customer service call made by the controller’s employee in May 2025 was lawful under Article 6(1)(b) GDPR, as it was directly related to the performance and quality assurance of the contractual gambling services. However, the Inspectorate found that the controller had breached the transparency principle under Article 5(1)(a) GDPR and information obligations under Article 13(1)(e) GDPR. Although the controller’s privacy policy listed categories of data recipients, the category relied upon (“other persons related to the provision of services, such as archiving and postal service providers”) was deemed insufficiently specific and misleading in the context of transferring data for the purpose of distributing invitations to sporting events.
The DPA emphasised that transparency requires the data subject to be able to clearly understand to whom their data may be disclosed and for what purposes. The generic reference to certain categories of service providers did not allow the data subject to reasonably foresee that his data would be shared for sporting invitations unrelated to the core gambling services.
Accordingly, while no unlawful disclosure to a third-party controller was established, the DPA held that the controller failed to comply with its GDPR transparency obligations under Article 13 GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.
STATE DATA PROTECTION INSPECTORATE DECISION 2025 m. November 28. No. 3R-1700 (2.13-1.E) Vilnius The State Data Protection Inspectorate (hereinafter – the Inspectorate) on 2025-04-18 received from the Gambling Supervision Service under the Ministry of Finance of the Republic of Lithuania [DATA NOT PUBLISHED] (hereinafter – Applicant) 2025-04-16 Notification (Inspection reg. No. 1R-2494 (2.13 Mr)) (hereinafter – Complaint 1) regarding the actions of Nesė, UAB (twinsbet) (hereinafter – the person complained of). The complaint states that the Complainant shares the Applicant's contact details with other individuals who call and offer invitations to sports competitions, free food, and alcoholic beverages, thus violating the Applicant's data privacy and GDPR1. The Applicant claims that while he was using gambling services on the twinsbet.lt website, the Applicant was contacted on 2024-09-11 by a representative of the Complainant (by phone [DATA NOT PUBLISHED]) and offered invitations to the Vilnius basketball team competition sponsored by the Complainant or to a martial arts event taking place at a similar time. When the Applicant inquired about the basis on which his telephone number was being used for advertising and how it related to the possible promotion of gambling, he was told that he had received the number from a colleague and intended to provide more information later, but was never contacted again. Complaint 1 states that a similar story began to repeat itself on 2025-03-18, when the Applicant received a call from another number ([DATA NOT PUBLISHED]) and an invitation to the basketball match on 2025-03-23; it was mentioned that a guest could be invited, whose age should be at least 20 years. The Applicant points out that the person complained about shares not only the Applicant's first name, surname, phone number, but also his age. The Applicant states that on 2025-03-20 he received tickets to the event in the Viber app; the ticket buyer is indicated as “[DATA NOT PUBLISHED]”. The Applicant claims that he did not use the tickets he received. The complaint draws attention to the fact that the Applicant contacted the respondent regarding such sharing of his personal data and promotion of gambling, but the respondent could not explain these actions2, and later it turned out that the messages received from the respondent via Viber were deleted, and the phone number from which the Applicant was first called is no longer in use. The Applicant requests a thorough investigation into a possible violation of the GDPR. On 2025-06-02, the Inspectorate again received the Applicant's 2025-05-26 Notification (Inspection reg. No. 1R-3610 (2.13 Mr)) (hereinafter referred to as Complaint 2) from the Gambling Supervision Service under the Ministry of Finance of the Republic of Lithuania regarding the actions of the same respondent. The Applicant indicated that on 2025-05-16 he again received a phone call from tel. connection number [DATA NOT PUBLISHED]. The caller introduced himself as calling from twinsbet, addressed the Applicant on behalf of and asked if there were any technical obstacles that prevented the Applicant from connecting to play. The Applicant claims that the person complained about continues to violate the GDPR. Regarding the merger of Complaint 1 and Complaint 2 Article 23, paragraph 4 of the Law on the Legal Protection of Personal Data of the Republic of Lithuania (hereinafter referred to as the Law on the Legal Protection of Personal Data) establishes that if the supervisory authority determines that it is examining the applicant's 1 2016 m. April 27 Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR) 2 Indicated that it was not aware of anything 2 2 or more complaints concerning the same complainant or complaints submitted by different applicants, but concerning the same violations and the same complainant, by its decision, these complaints may be merged and examined as a single complaint before the end of the deadline for examining the complaint. The Inspectorate, taking into account the fact that Complaint 1 and Complaint 2 were submitted by the same Applicant regarding the potentially unlawful use of personal data by the same complainant, hereby decides to merge both complaints and examine Complaint 1 and Complaint 2 as a single complaint (hereinafter referred to collectively as the Complaint). The Inspectorate, within its competence, examining the Complaint of the Applicant, declared that the Inspectorate received the responses of the Complainant on 2025-06-11 and 2025-08-13 (Inspection reg. No. 1R-3837 (2.13 Mr) and No. 1R-5408 (2.13 Mr)) (hereinafter referred to as the Response). In the Response, the Complainant indicated that the Applicant created an account on the platform www.twinsbet.lt managed by the Complainant on 2024-04-15 in order to use the gambling services provided by the Complainant. The Complainant noted that during registration it is mandatory to confirm that the user has read the valid privacy policy3 (hereinafter referred to as the Privacy Policy). During registration, this information notice is provided in a clear and accessible form, with the opportunity to read it before submitting registration data, therefore registration is not possible without indicating that the user has read it. The Privacy Policy establishes a provision that personal data may be transferred to data processors and provides several groups of data processors, including “Other persons related to the provision of services by UAB “Nesė”, such as archiving and postal service providers”. It is this group of data processors that the complainant associates with the provision of the Applicant’s personal data to a third party complained about in Complaint 1. The response emphasizes that the complainant did not transfer the Applicant’s personal data to any third party as an independent data controller; that, consistently implementing its business social responsibility strategy and actively supporting Lithuanian sports initiatives, on 05 July 2024 it concluded a service provision agreement with [DATA NOT PUBLISHED] (hereinafter referred to as the Data Processor) and, at the same time, a separate personal data processing agreement (hereinafter referred to collectively as the Agreement). The parties agreed on cooperation, the purpose of which is to implement the complainant’s social responsibility initiative aimed at sports for the promotion of culture, the popularization of basketball and the promotion of active leisure, while strengthening the involvement of customers in the activities supported by the complainant. The complainant notes that this initiative is exclusively non-commercial in nature, it is not and was not intended to directly or indirectly encourage the Applicant or any other person to gamble or to use the services of the complainant more actively. The Annex to the Agreement sets out the purpose of the processing of the personal data of the Data Controller - ensuring the performance of the main contract - Distribution of invitations to sports events to customers in the performance of the Cooperation Agreement; provision of customer engagement and activation services. The response notes that the relationship between the data controller and the processor is one of the essential GDPR institutes that allow economic entities to operate effectively by engaging specialized service providers. In implementing the principle of accountability (pursuant to Article 5(2) of the GDPR), the complainant takes all necessary measures to ensure that the Data Controller engaged would comply with the requirements stipulated in the legal acts. For this purpose, an Agreement has been concluded between the Complainant and the Data Processor, which complies with the imperative requirements of Article 28 of the GDPR. The Complainant indicates that the Applicant's personal data were transferred to the Data Processor only on an ad hoc basis, for the implementation of specific loyalty campaigns under the service provision (and personal data processing) agreement concluded on 05-07-2024, i.e. only immediately before the calls made in September 2024 and March 2025. The Complainant provided the Data Processor with the following personal data: first name, last name, telephone number and information about belonging to the age group over 20 years. When speaking about the information about age indicated by the Applicant, the Complainant assured that the Data Processor did not The Applicant's date of birth or exact age was disclosed. In order to ensure compliance with the provisions of the Law on Alcohol Control of the Republic of Lithuania during the event, only information was provided that the person belongs to the age group over 20 years. This was necessary in order to responsibly inform about the circumstances of the event and ensure compliance with legal acts. In response to the Inspectorate's instruction regarding the telephone call of 2025-05-16 from the telephone number +37066101879 indicated by the Applicant in Complaint 2, the complainant confirmed that in the period from 2025-04-17 to 2025-06-02, he did not transfer the Applicant's personal data to any third parties, including the Data Processor. All processing of the Applicant's personal data during the aforementioned period was carried out only within the complainant, its employees, in order to ensure proper provision of services. The complainant noted that the Applicant The telephone number specified in the complaint on 16-05-2025 and the telephone conversation described were not related to the transfer of any personal data to third parties. The call was made by an employee of the complainant - a customer service specialist, working under an employment contract and acting only on behalf of and in the interests of the complainant and in accordance with the direct instructions of the complainant. The purpose of the call was to ensure the quality of services - to check whether the Applicant had any technical difficulties when connecting to the system, and to promptly eliminate any potential problems. Such actions are directly related to the contractual relationship between the Company and the Applicant regarding the provision of gambling services. Therefore, such processing of personal data is lawful under Article 6(1)(b) of the GDPR, as it is necessary for the performance of the contract and to ensure that the services are provided properly, securely and uninterruptedly. The complainant additionally noted that the European Data Protection Board's Guidelines 2/2019 on the processing of personal data processing pursuant to Article 6(1)(b) of the General Data Protection Regulation, when online services are provided to data subjects (hereinafter referred to as the Guidelines on lawful processing under a contract), Article 6(1)(b) of the GDPR may apply where the processing is an integral part of the performance of a contract or the provision of a service. The Complainant takes the position that such activities may also include the quality assurance actions carried out by the Complainant in accordance with its contractual obligations with the Applicant. The Respondent has provided other information in the Response related to a possible violation of the provisions of the Law on Electronic Communications of the Republic of Lithuania in relation to the Applicant, however, taking into account that the Applicant's complaint is related to a violation of the provisions of the GDPR, the Inspectorate will not present either the information provided by the Respondent or its assessments on this issue in this decision. The processing of personal data is regulated by the GDPR and the ADTAĮ4. According to the GDPR, the processing of personal data is considered lawful only if it complies with the principles related to the processing of personal data set out in Article 5 of the GDPR and is justified by at least one of the conditions for lawful personal data processing set out in Article 6(1) of the GDPR. Article 5(1)(a) of the GDPR provides that personal data must be processed lawfully, fairly and transparently in relation to the data subject (principle of lawfulness, fairness and transparency). According to the accountability principle established by the GDPR (Article 5(2) of the GDPR), the data controller is responsible for ensuring compliance with Article 5(1) of the GDPR and must be able to demonstrate compliance. According to the description of the actions complained of in the Complaint, the Inspectorate decides that the Applicant is complaining about the lawfulness and transparency of the transfer of his personal data (name, telephone number and age) to the recipients of the data who offered to visit sports competitions by telephone and via the Viber application on 2024-09-11, 2025-03-18 and 2025-03-20, and about the actions of the complainant when inquiring by telephone on 2025-05-16 about the technical obstacles that the Applicant may be experiencing. 4 Law of the Republic of Lithuania on the Legal Protection of Personal Data (hereinafter referred to as the Law on the Legal Protection of Personal Data) 4 It should also be noted that the Inspectorate, in accordance with its competence established by legal acts, does not have the authority to assess possible gambling promotion actions5, although the Applicant indicates such actions in the complaint. 1. Regarding the compliance of the actions of the complained person on 2024-09-11, 2025-03-18 and 2025-03-20 with the provisions of the GDPR The Applicant indicated in the Complaint that the complained person shares his contact details when inviting the Applicant to sports events sponsored by the complained person, however, more detailed information about the legality of such actions, including the identity of the caller and the relationship with the complained person, was not provided to the Applicant. The Respondent does not dispute the actions indicated by the Applicant and claims that, before the dates indicated by the Applicant, it transferred the personal data of its clients, including the Applicant, to the Data Controller for the purpose of implementing the Respondent's social responsibility initiative aimed at fostering sports culture, popularizing basketball and promoting active leisure, while strengthening the engagement of clients in the activities supported by the Respondent. As already indicated, the purpose of the Data Controller's processing of personal data is to ensure the performance of the main contract - distribution of invitations to sports events to clients in the framework of the Cooperation Agreement; provision of client engagement and activation services. Thus, according to the Respondent, the Data Controller used the personal data of the Applicant transferred to it lawfully, on behalf of the Respondent, acting in accordance with the Agreement, which complied with the provisions of Article 28 of the GDPR. When assessing the information provided by the complainant, the Inspectorate notes that the complainant himself indicated that the Applicant created an account on the platform managed by the complainant www.twinsbet.lt on 2024-04-15 in order to use the gambling services provided by the complainant. The Applicant also indicated that he received an unwanted call while using the gambling services on the twinsbet.lt website. It should also be noted that the complainant indicated that when registering on the complainant's website the Applicant should have read the Privacy Policy, which specifies the groups of data controllers. The Complainant claims that the Data Processor mentioned in the Complaint is included in the group of data processors specified in the Privacy Policy – “Other persons related to the provision of services by UAB “Nesė”, such as providers of archiving and postal services”. Article 5(1)(a) of the GDPR stipulates that personal data must be processed lawfully, fairly and transparently in relation to the data subject (principle of lawfulness, fairness and transparency). Point 39 of the GDPR preamble stipulates that any processing of personal data should be lawful and fair. Applying the principle of transparency, natural persons should be clear about how personal data relating to them are collected, used, accessed or otherwise processed, as well as the extent to which those personal data are or will be processed. According to the principle of transparency, information and notifications relating to the processing of those personal data must be easily accessible and understandable, and presented in clear and plain language. That principle in particular, it concerns the information of data subjects about the identity of the data controller and the purposes of the processing, as well as further information to ensure fair and transparent processing in relation to the natural persons concerned, their right to obtain confirmation regarding the processing of personal data concerning them and the right to obtain those data. Natural persons should be informed about the risks, rules, safeguards and rights relating to the processing of personal data and about how to exercise their rights in relation to the processing of such personal data. In particular, the specific purposes for which personal data are processed should be explicit, legitimate and determined at the time of collection. Personal data should be adequate, relevant to the purposes for which they are processed and limited to what is necessary in relation to the purposes for which they are processed. 5 As this activity is established in the Law on Gambling of the Republic of Lithuania (hereinafter referred to as the Law on Gambling) 6 name, surname, telephone number and information on belonging to the age group over 20 5 1.1. Regarding the lawfulness of the actions of the complainant in transferring the Applicant's personal data to the Data Controller A data controller is understood as a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of data processing (Article 4(7) of the GDPR). Data processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller (Article 4(8) of the GDPR). Pursuant to Article 28(3) of the GDPR, the processing of data by the data processor shall be governed by a contract or other legal act in accordance with European Union or Member State law to which the data processor is bound in relation to the data controller and which specifies the subject matter and duration of the data processing, the nature and purpose of the data processing, the types of personal data and categories of data subjects, and the obligations and rights of the data controller. According to the provisions of the GDPR, the data controller may to process the data themselves and/or to authorise a data processor who processes the data on behalf of the data controller. The GDPR does not provide for the right of the data subject to object to the data controller transferring their personal data to the data processor, nor does it provide for any circumstances under which the data controller cannot authorise the data processor to process the data; on the contrary, the GDPR regulates the relationship between the data controller and the data processor (Chapter IV of the GDPR). It should also be noted that the European Data Protection Board Guidelines No. 07/2020 of 07/07/2020 on the concepts of “data controller” and “data processor” under the GDPR, paragraph 80, states that the lawfulness of data processing under Article 6 of the GDPR is determined by the activities of the data controller, and the data processor may not process the data otherwise than as instructed by the data controller. Accordingly, when the data controller provides personal data to the data processor, the conditions of lawfulness set out in Article 6(1) of the GDPR do not apply. Accordingly, the above provisions of the GDPR and the Agreement allow the Inspectorate to conclude that the relationship between the complainant and the Data Processor in the processing of the Applicant's personal data is a relationship between the data controller and the data processor. Sub-clause 3.1.1 of the Agreement states that "The Partner, in the performance of this Agreement, will process personal data on behalf of Ness, as a data processor." It should be noted that under the provisions of the GDPR, the data controller is responsible for the lawfulness, transparency and other principles set out in paragraphs 1 and 2 of Article 5 of the GDPR, whose lawful instructions must be carried out by the data processor acting on behalf of the data controller. Taking into account that the Applicant is complaining about the transfer of his personal data, and having established in this decision that the Applicant's personal data were transferred to the Data Processor before the dates specified in the complaint7 in accordance with the Agreement, the Inspectorate concludes that the Applicant's complaint regarding the actions of the complained person in transferring the Applicant's personal data to the Data Processor is to be rejected as unfounded. 1.2. Regarding the transparency of the actions of the complained person in providing information about the data recipients Article 13(1)(e) of the GDPR states that the data controller shall, at the time of receiving the personal data, provide the data subject with the following information - if any, the recipients of the personal data or the categories of recipients of the personal data. According to Article 4(9) of the GDPR - data recipient - a natural or legal person, public authority, agency or other body to which the personal data are disclosed, regardless of whether it is a third party or not. However, public authorities which may receive personal data in the course of a specific investigation under Union or Member State law shall not be considered as recipients of the data; when processing those data, those authorities shall comply with the applicable data protection rules appropriate to the purposes of the processing. 7 2024-09-11, 2025-03-18 and 2025-03-20 6 When assessing whether the complainant has provided the Applicant with information on the recipients or categories of recipients, it is important to assess the information provided in the complainant's Privacy Policy on the transfer of personal data. The Privacy Policy states that personal data may be transferred to data processors and lists eight categories of data processors. The response states that the Data Processor who performed the complained actions falls into the category of data processors - other persons related to the provision of services by UAB "Nesė", such as providers of archiving and postal services. It should be noted that, as established in Article 5(1)(b) of the GDPR, the processing of personal data for archiving purposes is not considered incompatible with any primary purposes. The Inspectorate decides that postal services are also an integral part of any personal data processing purpose related to the delivery of the parcel to the recipient, however, there is no basis for such a conclusion when personal data is intended to be provided for the purpose of sending invitations to sports events, when the data subject (Applicant) concluded a contract with the complained person for the processing of his personal data for the purpose of providing gambling services. As already stated, according to recital 39 of the GDPR, the principle of transparency requires that information and communications relating to the processing of personal data be intelligible and presented in clear and plain language. That principle concerns in particular the information to data subjects of the identity of the controller and the purposes of the processing, as well as further information to ensure fair and transparent processing in relation to the natural persons concerned. It is important to note that the complainant himself stated in the Reply that the principle of transparency under the GDPR does not constitute an absolute requirement to indicate the specific name of the service provider in each version of the policy if that provider falls within a clearly defined category of recipients; that it is sufficient to provide a detailed and specific definition of the categories of recipients if this enables the data subject to clearly understand to which entities his or her data may be transferred. Taking into account the information provided in the Response and the Privacy Policy, the Inspectorate concludes that the Applicant's information about the category of data recipient to which the complainant classified the Data Processor was not comprehensive and was not defined by any specific characteristics, therefore it did not constitute a basis for clearly understanding to which entity (data processor) the Applicant's personal data would be transferred. The Inspectorate also decides that, based on the information provided in the Privacy Policy of the complainant, the Applicant could not clearly understand that the services provided by the Data Processor on behalf of the complainant - the provision of invitations to sports events - are related to the gambling services provided by the complainant, and the Applicant did not receive a more detailed explanation about the Data Processor's actions from either the complainant or the Data Processor. This circumstance is confirmed by the correspondence of the Applicant with the representative of the person complained of dated 24-03-2025 - 28-03-2025, attached to the complaint. The person complained of did not comment on this circumstance in his Response, although he was accordingly informed that the Inspectorate concluded that the person complained of did not provide the Applicant with clear and understandable information about the recipient of his personal data or its category, and therefore, by such actions (omissions) he violated the obligation set out in Article 13, paragraph 1, point e, of the GDPR. Summarizing the circumstances established in this subsection of the decision and the legal regulation provided, the Inspectorate decides that the person complained about, by not providing the Applicant with clear and understandable information about the purposes of processing his personal data and the recipients or categories of data, violated the principle of transparency established in Article 5(1)(a) of the GDPR and, accordingly, Article 13(1)(e) of the GDPR, therefore the Applicant's complaint in this section should be recognized as justified. 2. Regarding the compliance of the actions of the person complained about on 2025-05-16 with the provisions of the GDPR The Applicant indicated that on 2025-05-16 he received a phone call again; the caller introduced himself as calling from twinsbet, addressed the Applicant on his behalf and asked if there were any technical obstacles that prevented the Applicant from connecting to play. The Applicant claims that the person complained about continues to violate the GDPR. 7 The Respondent assured that in the period from 2025-04-17 to 2025-06-02, it did not transfer the Applicant's personal data to any third parties, including the Data Processor, and explained that the processing of the Applicant's personal data was carried out only within the Respondent, by its employees, in order to ensure the proper provision of services. The purpose of the call was to ensure the quality of services - to check whether the Applicant had any technical difficulties when connecting to the system, and to promptly eliminate any potential problems. Therefore, such processing of personal data is lawful pursuant to Article 6(1)(b) of the GDPR, as it is necessary for the performance of the contract and to ensure that the services are provided properly, securely and uninterruptedly. The Respondent further noted that in the Guidelines on lawful processing pursuant to a contract, Article 6(1)(b) of the GDPR may apply where the processing is an integral part of the performance of a contract or the provision of a service. The Respondent takes the position that such activities may also include service quality assurance actions carried out by the Respondent under its contractual obligations with the Applicant. In this case, neither the Applicant nor the Respondent has indicated any circumstances that would allow it to be concluded that the Applicant may have experienced some technical disruptions when using the gambling service provided by the Respondent. It is important to note that according to the content of the conversation described by the Applicant, the reason for the call from the Respondent's representative was that the Applicant was not connecting to play. The definitions of remote gambling provided in the Gambling Law do not constitute grounds for concluding that the gambler is obliged to log in and play within the specified periods, therefore the Inspectorate had doubts whether the use of the Applicant's personal data without any necessary reason for calling for the purpose of performing the contract was necessary and complied with the condition set out in Article 6(1)(b) of the GDPR and the purpose limitation principle set out in Article 5(1)(b) of the GDPR. The Inspectorate contacted the respondent, requesting justification that the telephone call made by the respondent on 16 May 2025 (using the Applicant's telephone number) was necessary for the performance of the contract with the Applicant. In the event that no specific reasons were recorded for the Applicant's possible technical obstacles, the Inspectorate requested an explanation for the purpose of tracking the Applicant's (possibly other customers') actions related to logging in and/or gambling, and to indicate where and in what manner the Applicant was informed about the tracking of his actions in his account. On 18 November 2025, the Inspectorate received a response from the complainant (Inspection Reg. No. 1R-8002 (2.13.Mr)). The complainant indicated and attached evidence that in 2025 In May, the technology solutions provider serving the gaming platform used by the complainant informed the complainant about scheduled updates to the platform's technical infrastructure, carried out on 2025-05-08, 2025-05-14 and 2025-05-15, which may have caused platform malfunctions - user interface loading problems, data synchronization delays, etc. After the aforementioned updates, the complainant received reports from users about malfunctions when connecting to the platform or performing routine actions. The complainant noted that when assessing the available data, it was not possible to technically determine either the extent of the specific malfunctions or which users may have been affected. As a result, the complainant took additional measures - it was decided to make random customer calls in order to realistically assess whether the service was functioning properly and whether the malfunctions were not continuous. Thus, the calls were made for the sole purpose of determining whether the service is functioning properly for users or whether there are problems that require immediate technical action. The Complainant noted that the call indicated by the Applicant was made in order to check whether customers, including the Applicant, are not experiencing technical difficulties when connecting to the platform, therefore, from the Complainant's point of view, such use of personal data (telephone number) was objectively necessary for the performance of the contract concluded with the Applicant, as provided for in Article 6(1)(b) of the GDPR. The Complainant emphasized that it does not and does not have the technical capabilities to monitor the actions of an individual customer, which would allow it to see whether a specific user experienced technical difficulties when connecting to the platform or using its functions at a certain time. The technological provider of the gambling platform administers the system activity, which records only general technical indicators, such as module stability, load, error types or system response time. Thus, based on these data, the complainant does not and cannot have information about which specific user may have encountered disruptions. For this reason, the complainant cannot: (i) determine whether a technical error affected a specific user; (ii) identify which users failed to log in; (iii) link a general system failure to the actions of a specific user's account. That is why, in the event of a risk of platform instability, the only possibility to objectively assess whether the service is actually working for users is to randomly contact a portion of customers. The complainant emphasized that the call specified in the Complaint was not related to either the assessment of the Applicant's behavior on the platform or the history of registration or logins, since such individual information is not verified or otherwise technically generated. In addition, the Applicant was selected on a random basis, guided by the sole purpose of ensuring the quality of the services and responding in a timely manner to possible disruptions to the platform. Accordingly, the use of the Applicant's telephone number during the call was in no way related to the monitoring or profiling of user behaviour. Having assessed the information provided in the respondent's response and the attached evidence8, the Inspectorate decides that the respondent has proven that the use of the Applicant's personal data - telephone number - on 16 May 2025, as specified in the Complaint, inquiring about possible technical obstacles, complied with the main purpose of the processing of the Applicant's personal data - the provision of gambling services - and the condition of lawfulness set out in Article 6(1)(b) of the GDPR - the performance of the contract. The Inspectorate concludes that the circumstances established in this part of the decision constitute grounds for stating that the actions taken by the person complained of on 16 May 2025, when processing the Applicant's telephone number, complied with the principles of lawfulness and purpose limitation set out in Article 5(1)(a) and (b) of the GDPR, therefore the Applicant's complaint in this part must be rejected as unfounded. In accordance with Article 31(2)(1) of the GDPR, in the event that the complaint or part thereof is deemed justified, the Inspectorate shall provide the data controller and/or data processor with reasoned instructions, recommendations and/or apply other measures specified in Article 58(2) of the GDPR, Article 33 of the GDPR and other laws regulating the protection of personal data and/or privacy. When deciding on the application of enforcement measures, point 129 of the GDPR preamble shall be considered relevant, which states that each measure should be appropriate, necessary and proportionate to ensure compliance with the GDPR. Having assessed the identified violations of the principle of transparency set out in Article 5(1)(a) of the GDPR and Article 13(1)(e) of the GDPR and taking into account the fact that the Inspectorate has not received any complaints from other persons regarding the actions of the person complained about and, accordingly, has not identified any violations, the Inspectorate decides that a reprimand and an instruction should be issued to the person complained about. The Inspectorate, taking into account the above and in accordance with Article 31, Part 1, Points 1 and 2 and Part 2, Point 1, of the ADTAĮ, Article 58, Part 2, Points b and d of the GDPR, decides: 1. To reject the Applicant's complaint in parts regarding the legality of the actions of the complainant on 2024-09-11, 2025-03-18 and 2025-03-20 in transferring the Applicant's personal data to the data recipients and regarding the compliance of the actions of the complainant on 2025-05-16 with the provisions of the GDPR as unfounded. 2. To recognize the Applicant's complaint in part regarding the transparency of the actions of the complainant in providing information on the data recipients as justified. 3. To issue a reprimand to the person complained about for violations of the principle of transparency established in Article 5(1)(a) of the GDPR and Article 13(1)(e) of the GDPR. 8 Copies of notifications on planned platform infrastructure updates and User inquiries regarding technical obstacles 9 4. To order the person complained about to take measures no later than 2026-01-05 so that the Applicant (and other service recipients) are properly informed about the data recipients, including data processors, or their categories. 5. To inform the Applicant and the person complained about the decision taken. This decision may be appealed to the Regional Administrative Court (address: Žygimantų g. 2, Vilnius) within one month from the date of its service, in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania). Director Dijana Šinkūnienė



