However, this does not mean that the data controller can act as they please.
Let’s see why this case is important for every real estate owner, business, and generally every person.
Situation
The owner of a land plot received a registered letter from a company planning to build a wind turbine with a capacity of more than 30 kW.
The letter stated:
- the applicant’s name and surname;
- residential address;
- the address of her land plot;
- a unique number;
- Real Estate Register data.
According to R. Joskaudienė, the woman contacted the State Data Protection Inspectorate (VDAI) believing that her data was collected without consent; she was not properly informed; the company did not provide all information about the processing of her data.
What did the VDAI decide?
The Inspectorate clearly distinguished several different issues.
1. Was it necessary to obtain the person’s consent?
No.
And this will be surprising to many.
Article 6(1)(c) of the GDPR allows processing personal data when it is necessary for compliance with a legal obligation.
“In this case, the company was fulfilling an obligation set out in Article 49(15) of the Renewable Energy Sources Law, which requires informing owners of land plots in certain territories about the planned construction of a wind turbine.
To do this, the company lawfully obtained data from the Register Center and used it to send the notification,” explained R. Joskaudienė.
Therefore, according to her, consent was not required.
An important GDPR lesson
According to the lawyer, this is one of the most common myths in society.
The GDPR does not mean that consent is required for every use of personal data.
The GDPR provides six independent lawful bases for processing.
“Consent is only one of them. In practice, the following are often applied:
- performance of a contract;
- compliance with a legal obligation;
- public interest;
- legitimate interest.
Therefore, the argument:
“I did not consent.”
does not automatically mean that the data was processed unlawfully,” explained R. Joskaudienė.
2. Was the person properly informed?
Here too, the VDAI did not find a violation.
Since the data was obtained not from the applicant herself, Article 14 of the GDPR was applied.
The Inspectorate found that the first notification provided sufficient information:
- why she received the letter;
- which law was followed;
- who the data controller is;
- where to request additional information.
Therefore, according to the lawyer, the right to be informed was not violated.
3. However, the company did make a mistake
And this is the most interesting part, according to R. Joskaudienė.
The applicant exercised the right established in Article 15 of the GDPR to access her data.
The company:
- provided a copy of the processed data;
- explained the legal basis;
- indicated the purpose of data processing.
However, according to R. Joskaudienė, it did not specify how long it intended to keep the applicant’s personal data.
Read more Can you recognize 10 songs from Lithuanian movies, series, and musicals?

“For this reason, the VDAI found a violation of Article 15(1)(d) of the GDPR.
Why is this important?
Very often organizations think it is enough to write:
“We process your data lawfully.”
But the GDPR requires much more,” emphasized the lawyer.
According to her, the data subject must be provided with all the information required by law, including:
- what data is processed;
- for what purposes;
- on what legal basis;
- to whom it is transferred;
- how long it will be stored or the criteria used to determine the retention period.
“Even if the data collection itself was completely lawful, failure to provide information about the retention period is already considered a GDPR violation,” said the lawyer.
What enforcement measure did the VDAI apply?
Since the violation was the only one and no other GDPR violations were found, the VDAI did not impose a fine.
“However, it obliged the company to properly respond to the applicant by the set deadline and provide information about the data retention period.
This again shows that the VDAI applies the principle of proportionality – not every violation automatically means a financial sanction,” emphasized R. Joskaudienė.
Practical conclusions for residents
- Consent is not required for every use of your data.
- Before claiming a GDPR violation, it is worth clarifying the legal basis on which the data was processed.
- If you apply under Article 15 of the GDPR, you have the right to receive not only a copy of your data but also all the information required by law, including the retention period.
- If you do not receive such information, this may be an independent GDPR violation, even if the data collection itself was lawful.
“This VDAI case is a great example of why the GDPR cannot be assessed solely by emotions or by one sentence: ‘I did not consent, therefore it is a violation.’ First, the legal basis for data processing must be established, and only then should it be assessed whether the data controller has properly fulfilled all GDPR obligations.
In practice, many organizations focus on lawful data collection but forget another important part of the obligations – transparent information and ensuring all data subject rights. It is precisely such, at first glance minor procedural errors that become the cause of violations identified by the VDAI,” said R. Joskaudienė.
According to her, the VDAI decision once again reminds us: lawful data collection does not mean that all GDPR requirements have already been met.