25-05-2026

GDPR Day: Data Protection Starts with Trust

25 May marks the anniversary of the application of the General Data Protection Regulation (GDPR). The Regulation, which came into force across the European Union in 2018, was an important turning point: it strengthened people’s rights to privacy protection and established clearer responsibilities for organizations regarding how personal data is handled.

In recent years, data protection has become an integral part of everyday life. We use electronic services, register in systems, share information, so a natural question arises: how is it ensured that our data is used responsibly and securely?

Experts from the State Data Agency (Statistics Lithuania) emphasize that today data protection is not limited to technical measures or legal requirements alone. It is a continuous process involving technology, clear rules, employee responsibility, and consistent risk management.

“There is no absolute security in the digital space, so the most important thing is to continuously strengthen protection measures, responsibly assess potential risks, and ensure that data is processed in accordance with the highest standards. Data protection primarily means responsibility and trust”, notes Dovilė Galvanauskaitė, Head of the Data Protection Division at the State Data Agency.

Personal data protection is based on several key principles. One of the most important is that access to data is granted only to those employees who need it to perform their direct functions. In other words, employees can see only the information necessary for a specific task.

All actions within systems are also logged – it is possible to see who accessed the data, when, and for what purpose. Such control helps ensure transparency and reduces the risk of unauthorized use.

An important part also consists of technological protection measures: data encryption, access management, system monitoring, regular security audits, and continuous system updates. However, experts note that technology alone is not enough: human awareness, responsible behavior, and the ability to recognize potential threats are equally important.

In the public sphere, questions often arise about what data can be made publicly available. Data protection specialists at the State Data Agency emphasize that only anonymized or aggregated data, which does not allow the identification of a specific individual, is published. The use of personal data is strictly regulated by legal acts and internal control measures.

According to experts, the significance of the GDPR today goes far beyond legal regulation alone. It is a common standard for responsible data use, helping to build greater public trust in institutions and digital services.

On GDPR Day, it is important to remember that data protection is not a one-time action or a formality. It is a daily effort requiring continuous attention, competence, and responsibility – to ensure that the digital environment is as safe as possible for each of us.