Lithuania
NATO and EU state guarding the Suwalki Gap and hooked into Europol, Schengen, Prüm and Nordic-Baltic sharing, with Pegasus confirmed on its soil and its sole submarine cable severed by a Chinese vessel
Overview
EU Member State (since May 2004), NATO (since March 2004). For the EU framework, see the EU Framework page.
Lithuania occupies one of the most strategically sensitive positions in Europe: bordered by Russia’s Kaliningrad exclave and Belarus, controlling one side of the Suwalki Gap, the 100-km corridor NATO considers its most vulnerable point. This geography has driven intelligence capabilities far exceeding what 2.8 million people would suggest. VSD (civilian intelligence) and AOTD (military intelligence, origins 1918) face persistent Russian, Chinese, and Belarusian espionage. Pegasus infections confirmed on Lithuanian territory (May 2024). The BCS East-West Interlink (Lithuania’s sole submarine cable to Sweden) was severed November 2024 by the Chinese vessel Yi Peng 3. Belarus weaponised migration in 2021.[1][2]
Lithuania’s outward data-sharing runs through its alliances and treaties, each detailed below. It is a NATO member (since 2004, hosting the Alliance’s ENSEC Centre of Excellence in Vilnius), and its services take part in the Club de Berne intelligence forum, its Counter-Terrorism Group, the Nordic-Baltic Eight, and Baltic trilateral cooperation with Estonia and Latvia; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds bilateral mutual legal assistance treaties with the United States, its Baltic neighbours, and Russia. These are the channels through which the domestic protections described below are, in practice, bypassed.[13][14][15][16][17]
International Data Sharing Agreements
Mutual Legal Assistance
EU Member States (26 countries): Lithuania cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Lithuania and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[13]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Lithuania is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[14]
Bilateral MLATs: US-Lithuania MLAT signed January 16, 1998, in force August 26, 1999. Trilateral MLA with Estonia and Latvia (Tallinn, November 11, 1992). Bilateral MLA with Russia (pre-independence agreement on legal cooperation). Lithuania’s treaties are published in the Register of Legal Acts, searchable via the Seimas legal-acts database.[10]
Intelligence and Defense Cooperation
NATO (since 2004); hosts ENSEC COE. NB8 (the Nordic-Baltic Eight: Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden).[11] Lithuania’s services participate in the Club de Berne and its Counter-Terrorism Group (CTG); the Club de Berne keeps no public roster, but it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom.[18] Baltic trilateral intelligence cooperation with Estonia and Latvia. EU-US Umbrella Agreement, SWIFT/TFTP, PNR. Interpol I-24/7. Egmont Group.
EU Law Enforcement Cooperation
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[15] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[16]
Europol
As an EU member state, Lithuania is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Lithuanian person data flowing through Europol is reachable onward.[17]
The Privacy Backdoor Effect
- FRA transit: Sole submarine cable terminates in Sweden’s FRA collection jurisdiction
- Intelligence expansion: February 2026 law allows surveillance without clear time limits
- Pegasus: Infections confirmed on Lithuanian territory (Estonian operator suspected)
- Suwalki Gap: Strategic vulnerability drives intelligence capabilities disproportionate to population
- EU Framework: Lithuanian data in SIS II, Prüm, EIO accessible to 27 EU states
- MLAT/CoE Conventions: the US, Estonia, Latvia, and Russia bilateral treaties, plus the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention, can request data through MLA channels
Surveillance and Intelligence
Intelligence Agencies
VSD (State Security Department): Civilian intelligence and counterintelligence, accountable to Seimas and President. AOTD (Second Investigation Department): Military intelligence, counterintelligence, cyber warfare under Ministry of National Defence, origins October 27, 1918. Article 22 of the Constitution requires judicial authorisation for surveillance, but the February 2026 expansion retains provisions criticised for indefinite monitoring without meaningful judicial review.[5]
Pegasus Infections (May 2024)
Access Now and Citizen Lab confirmed Pegasus infections in the Baltic region including at least one Belarusian activist based in Vilnius (infection dating to March 2021). No evidence Lithuania is a Pegasus customer; Estonia (which acquired Pegasus) is believed to operate it across EU jurisdictions. Lithuania’s territory is an active surveillance environment for state-sponsored spyware.[2]
Russian and Belarusian Threats
VSD 2025 National Threat Assessment: Russia actively rebuilding spy networks, conducting sabotage operations across Europe, and could develop capabilities for limited military action against NATO countries within three to five years. Belarus weaponised migration in 2021, directing thousands to the Lithuanian border. Hosts NATO ENSEC COE (Energy Security Centre of Excellence) in Vilnius.[6]
Internet Infrastructure and Transit Exposure
IXPs: LIXP (Vilnius), LITIX (Vilnius, connected to AMS-IX/DE-CIX/LINX), BALT-IX (Vilnius/Kaunas). The BCS East-West Interlink (218 km, Lithuania-Sweden via Gotland) is Lithuania’s sole submarine cable, severed November 17, 2024 simultaneously with C-Lion1, by Chinese vessel Yi Peng 3 (departed Russia’s Ust-Luga), reducing internet capacity by one-fifth. Cross-border fibre: Baltic Highway (3,000 km Tallinn-Frankfurt backbone). Lithuania ranks first in Europe for fiber-optic penetration.[7]
FRA cable-tapping exposure: The BCS East-West Interlink terminates at Katthammarsvik, Gotland, Sweden, within FRA collection jurisdiction. Lithuanian data transiting this cable is subject to Swedish bulk interception under the FRA Law (Type 2 warrants, ministerial only for non-Swedish persons). The ECtHR ruled Sweden’s regime violated Article 8 ECHR in 2021.[8]
Recent Developments
National Property Registry Breach (May 2026): Attackers using stolen government credentials extracted more than 600,000 records from Lithuania’s national real-property registry, including residential addresses that could expose intelligence officers, soldiers, and diplomats to physical targeting. Lithuania’s President stated that “hostile states” orchestrated the theft, framing it as a national-security incident rather than ordinary cybercrime.[12]
Intelligence Law Expansion (February 2026): Significantly expanded VSD/AOTD powers while retaining provisions for surveillance without clear maximum time limits.[4]
BCS East-West Interlink Severed (November 2024): Sole submarine cable cut by Yi Peng 3, simultaneously with C-Lion1. Under investigation.[7]
Pegasus Confirmed (May 2024): Belarusian activist in Vilnius among confirmed targets in Baltic region.[2]
VSD Threat Assessment (2025): Russia could develop limited military action capability against NATO within 3–5 years.[6]
Privacy Framework
The VDAI (State Data Protection Inspectorate) enforces the GDPR and the Personal Data Processing Law. Largest fine: Vinted EUR 2.39 million (July 2024). NIS2 transposed via Cyber Security Law (October 2024). Intelligence law expanded February 1, 2026 with provisions criticised for allowing surveillance without clear maximum time limits and classifying conditions for court-free intelligence methods.[3][4]
Data Retention
6-month retention of traffic and location data (internet) / 12-month (telephony). Lithuania has not repealed or substantially amended retention provisions despite the CJEU’s Digital Rights Ireland invalidation of the underlying EU directive.[9]
Pending Legislation
Lithuania’s major recent measures are already enacted, so the pipeline is dominated by oversight responses and implementation:
- Intelligence Law oversight (surveillance): the expanded Intelligence Law (in force February 1, 2026) granting court-free surveillance methods with a 24-hour post-hoc authorisation drew criticism from the Seimas Ombudsman for lacking maximum-duration limits; corrective amendments and tighter oversight are under discussion.[4]
- Registry-security reform: the May 2026 national property-registry breach (600,000+ records) is expected to prompt access-control and credential-security legislation for state registries.[12]
- NIS2 (Cybersecurity Act): transposition completed March 12, 2026; implementing requirements continue to phase in (organisational measures due by April 17, 2026).
- EU AI Act implementation: Lithuania must designate AI market-surveillance authorities; implementing legislation is pending.
