Lithuanian justice minister addresses data breach: too many overseers leaves no one accountable

Thursday 28th May 2026 on 20:45 in Lithuania Lithuania

data breach, governance, lithuania

Too many institutions overseeing Lithuania’s Register Centre has created a lack of clear responsibility in the wake of a major data breach, Justice Minister Rita Tamašunienė said in an interview with LRT’s Dienos tema on Wednesday.

Speaking about the ongoing investigation into the unauthorised disclosure of personal data from the Register Centre, Tamašunienė acknowledged that while her ministry holds formal oversight as the “data controller,” technical and cybersecurity responsibilities fall under the Register Centre itself, which operates under the Economy and Innovation Ministry. The Interior Ministry is also involved through its Migration Department.

“We are responsible for the legal framework—for ensuring the register functions and contains the necessary data,” Tamašunienė said. “But when it comes to security, cybersecurity, technical parameters, and functionality, those powers are granted to the Register Centre.”

The minister defended the delayed public notification of the breach, stating that an initial decision was made to allow a pre-trial investigation to gather critical evidence before disclosure. The Register Centre first reported the incident to the Justice Ministry and the State Data Protection Inspectorate in early April, but the full scale of the breach—including the number of affected records—was only made public in late May.

Tamašunienė emphasised that the Register Centre had been granted the authority to handle notifications under a 2020 ministerial order, which outlined how and when affected individuals should be informed. “They received those powers,” she said. “Under those powers, the Register Centre is obligated to provide information to legal or natural persons about incidents—either directly or upon request, such as through lawyers.”

The breach has raised questions about coordination between the Justice Ministry and the Register Centre. While the inspectorate had demanded public notification by May 27, the Register Centre claimed it had not received clear instructions from the ministry on how to proceed. Tamašunienė maintained that the tactical pause was necessary to identify systemic vulnerabilities before alerting the public.

Further details on the source of the leak and potential institutional failures remain under investigation.

Source 
(via LRT)