<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ECOVIS ProventusLaw</title>
	<atom:link href="https://ecovis.lt/feed/" rel="self" type="application/rss+xml" />
	<link>https://ecovis.lt/</link>
	<description></description>
	<lastBuildDate>Tue, 25 Aug 2026 08:41:37 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://ecovis.lt/wp-content/uploads/2026/02/cropped-ecovis-fav-32x32.png</url>
	<title>ECOVIS ProventusLaw</title>
	<link>https://ecovis.lt/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</title>
		<link>https://ecovis.lt/ai-act-transparency-guidelines/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 12:30:10 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Insight]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11631</guid>

					<description><![CDATA[<p>The European Commission’s Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (20 July 2026), and the accompanying Code of Practice on Transparency of AI-generated Content – what they mean in practice, and when AI-generated content must be marked and labelled</p>
<p>The post <a href="https://ecovis.lt/ai-act-transparency-guidelines/">AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1>AI made it? Say so. What the Commission&rsquo;s new AI Act transparency Guidelines require</h1>
<p>The European Commission&rsquo;s Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (20 July 2026), and the accompanying Code of Practice on Transparency of AI-generated Content &ndash; what they mean in practice, and when AI-generated content must be marked and labeled.</p>
<h2>Summary</h2>
<ul>
<li><em><strong>Four duties, two owners.</strong> Providers must design interactive systems to disclose themselves (Article 50(1)) and embed an invisible, machine-readable mark in synthetic output (Article 50(2)); deployers must notify people exposed to emotion-recognition and biometric categorization systems (Article 50(3)) and add a visible label on deep fakes and on public-interest text (Article 50(4)). The duties are cumulative, none discharges another, and the same organization frequently owes several.</em></li>
<li><em><strong>Not every AI output has to be marked.</strong> Standard editing and minor alterations, AI translation, formatting, source code, single words and captions, machine-to-machine data, and genuine closed-loop internal B2B material all fall outside the scope of duty. That is where most of the practical relief lies.</em></li>
<li><em><strong>AI-generated or manipulated public-interest text deserves particular attention.</strong> AI-touched investor and sustainability reports on a company website need a visible label unless genuine human review and editorial responsibility are both documented &ndash; and that exception collapses the moment AI edits the text after editorial sign-off.</em></li>
<li><em><strong>Article 50 does not stop at the EU border.</strong> A provider or deployer established outside the EU owes the same duties where the output of its system is foreseeably used in the Union &ndash; so a third-country group entity generating content targeted at EU audiences is in scope.</em></li>
<li><em><strong>A label is not a license.</strong> Marking and labeling answer the question &ldquo;is this AI?&rdquo;, not &ldquo;is this allowed?&rdquo;. A properly labeled deep fake can still be unlawful on other grounds, and a 50(3) notice does not legitimize a deployment prohibited under Article 5 or unlawful under data protection law.</em></li>
<li><em><strong>One deadline has passed, one is coming</strong> &ndash; and the fines are real. Chatbot and voice-assistant disclosure under Article 50(1) has been required since 2 August 2026, with no grandfathering; providers of generative systems already on the market have until 2 December 2026 to bring Article 50(2) marking into conformity. Non-compliance amounts to EUR 15 000 000 or 3% of the total worldwide annual turnover, whichever is higher, with RRT supervising in Lithuania.</em></li>
</ul>
<p>Since 2 August 2026, a new layer of Regulation (EU) 2024/1689 (the &ldquo;AI Act&rdquo;) applies to almost every business that lets customers talk to a chatbot, generates images or text with artificial intelligence (AI), or edits media with AI tools.</p>
<p>Article 50 of the AI Act imposes a set of <strong>transparency obligations</strong>: people must be told when they are dealing with AI, and AI-generated or manipulated content must be marked and, in defined cases, visibly labeled. On 20 July 2026, the European Commission (the &ldquo;Commission&rdquo;) adopted detailed Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (the &ldquo;Guidelines&rdquo;), complemented by the Code of Practice on Transparency of AI-generated Content (the &ldquo;Code of Practice&rdquo;).</p>
<p>The Guidelines are non-binding &ndash; only the Court of Justice can give an authoritative interpretation of the AI Act &ndash; but they are the clearest practical map of what is in scope, what is out of scope, and who has to do what.</p>
<p>This article walks through the four obligations, with the emphasis on the question clients actually ask: <strong>what has to be marked or labeled as AI, and by whom?</strong> It pays particular attention to the financial market and its participants &ndash; banks, payment and electronic money institutions, investment firms, crypto-asset service providers, insurers and listed issuers &ndash; for whom AI-touched investor communications, corporate and sustainability reports, client-facing chatbots, marketing content and biometric onboarding tools sit squarely inside Article 50, on top of the disclosure and conduct duties they already owe under financial services regulation.</p>
<h2>The four obligations at a glance</h2>
<p>Article 50 contains four distinct transparency duties, each attaching to a different type of AI system or output, and each falling on either the <strong>provider</strong> (the entity that develops the system and places it on the market under its own name) or the <strong>deployer</strong> (the entity that uses the system under its own authority, unless the use is purely personal and non-professional). The distinction matters because the same organization can be both at once &ndash; for example, a firm that builds an in-house generative tool and then uses it to produce deep fakes wears both hats. The deployer side reaches wider than most clients assume: businesses, public-sector bodies, media outlets, advertising and marketing agencies, and any other legal or natural person using AI content in a professional or economic activity &ndash; including influencers monetizing social media. Purely personal, non-professional use is outside Article 50 altogether.</p>
<ul>
<li><strong>Article 50(1) &ndash; interactive AI.</strong> The provider must design the system so that a person is informed that they are interacting with an AI. Think chatbots, voice assistants, and AI agents.</li>
<li><strong>Article 50(2) &ndash; marking of synthetic content.</strong> The provider must ensure that AI-generated or manipulated audio, images, videos, or text are marked in a machine-readable format and detectable as artificial.</li>
<li><strong>Article 50(3) &ndash; emotion recognition and biometric categorization.</strong> The deployer must inform people exposed to such a system that it is operating.</li>
<li><strong>Article 50(4) &ndash; deepfakes and certain text.</strong> The deployer must clearly and visibly label deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest.</li>
</ul>
<p>A single system can trigger several of these at once. An image generator embedded in a chatbot engages 50(1) and 50(2) for the provider; if the deployer uses it to create a deep fake, 50(4) applies on top. The obligations are cumulative, not alternative.</p>
<p><strong>Article 50 does not stop at the EU border.</strong> A provider or deployer established outside the EU is caught where the output of its AI system is used in the Union &ndash; so a third-country group entity generating content that is disseminated to, or targeted at, EU audiences owes the same duties as an EU actor. The trigger is foreseeable use of the output in the Union: a deployer who directs or authorizes EU distribution, including by posting deep fakes on the open internet, is in scope, whereas purely incidental or unforeseeable downstream use that reaches the Union through channels outside the actor&rsquo;s control is not.</p>
<h2>Two kinds of &ldquo;marking&rdquo; &ndash; and why the difference matters</h2>
<p>The word &ldquo;marking&rdquo; serves two very different functions in Article 50, and conflating them is the most common source of confusion. It is worth pinning down the distinction before going further.</p>
<p><strong>Machine-readable marking (Article 50(2))</strong> is invisible plumbing. It is a technical signal &ndash; a watermark, metadata, a cryptographic provenance tag, a fingerprint &ndash; embedded in the content so that software can later identify it as AI-generated. It is the <strong>provider&rsquo;s</strong> job, and it applies to essentially all synthetic audio, image, video and text output of the system.</p>
<p><strong>Visible labeling (Article 50(4))</strong> is a disclosure a person can see or hear &ndash; a caption, a banner, a spoken statement &ndash; telling the audience that a deep fake or a public-interest text is artificial. It is the <strong>deployer&rsquo;s</strong> job, and it applies to a much narrower set of content.</p>
<p>The Guidelines are explicit that these do not substitute for one another. A deployer cannot discharge the 50(4) labeling duty by pointing to the provider&rsquo;s machine-readable mark, because that mark is not perceptible to the ordinary viewer without special tools. Conversely, a visible label does not relieve the provider of the duty to provide a machine-readable marking under 50(2).</p>
<h2>What must be marked under Article 50(2)</h2>
<p>This is the obligation with the widest reach, and the one clients most often ask about. It applies where all of the following are true: the system is an AI system; it generates or manipulates synthetic content; the content is <strong>audio, image, video or text</strong> (an exhaustive list, but one that includes multimodal, 3-D, and virtual and augmented reality (VR/AR) output); and none of the exceptions applies.</p>
<p>Crucially, content does not have to be wholly AI-generated to count. Content mixed with human-created material still qualifies as synthetic if the AI-generated or manipulated part falls within one of the four modalities. &ldquo;Generation&rdquo; means creating new material (an AI-drawn image, a synthesized song); &ldquo;manipulation&rdquo; means altering existing content beyond standard editing (a face swap, a voice clone).</p>
<p><strong>Marking is only half of it.</strong> Article 50(2) imposes two cumulative duties: the provider must mark the output in a machine-readable format and ensure a means of detection is available to the people exposed to it, one that returns a human-readable result indicating whether the content is AI-generated or manipulated. A mark that no one can read back is not compliance. Where the provider relies on another actor for detection, it remains responsible for ensuring that the solution works and that the result is clearly shown at first exposure.</p>
<h3>In scope &ndash; must be marked</h3>
<ul>
<li>AI-generated summaries of text, or paraphrasing/rewriting that changes style, structure or meaning.</li>
<li>Removal, replacement or insertion of objects or persons in images and videos that change the substance; face replacement or substantial facial modification.</li>
<li>Synthesis of a specific person&rsquo;s voice, or a realistic video of events that did not occur; altering a person&rsquo;s body shape or skin color.</li>
<li>Composite images or clips that modify the depiction of persons, objects, events or facts.</li>
<li>AI agent output that is perceptible to a person as audio, image, video or text.</li>
</ul>
<h3>Out of scope &ndash; no marking required</h3>
<p>The Guidelines carve out a long list of things that do <strong>not</strong> have to be marked, which is just as useful to know:</p>
<ul>
<li><strong>Standard editing and minor alterations &ndash;</strong> grammar and spell-checking, minor stylistic polishing, AI-generated translations, formatting and format conversion, noise reduction, minor cropping or color correction, red-eye removal, background blurring, video stabilization, and converting black-and-white to color.</li>
<li><strong>Non-substantial changes &ndash;</strong> anything that does not significantly alter the input data or its meaning, style or intent.</li>
<li><strong>Source code &ndash;</strong> code in any programming, scripting, markup, query or configuration language (including SDKs, SQL, YAML, JSON, APIs), and integral comments.</li>
<li><strong>Very short outputs &ndash;</strong> single words, image captions, alt-text, UI labels, icon-scale graphics.</li>
<li><strong>Machine-to-machine output</strong> processed automatically and never perceived by a person; internal analytical extraction and structuring of data; mere reproduction, ranking or arrangement of existing content (playlists, recommender systems).</li>
<li><strong>Closed-loop and industrial output &ndash;</strong> strictly technical, business-to-business (B2B) output, perceived only by a limited pre-defined set of professionals inside the organization, not shared externally, with appropriate safeguards. Real-time ephemeral content (e.g. in games or VR) consumed immediately and not stored may also be exempt where marking is not technically feasible, and an in-experience notice is provided.</li>
<li><strong>Law enforcement use</strong> authorized by law to detect, prevent, investigate or prosecute criminal offences.</li>
</ul>
<p>The technical solution must be <strong>effective, interoperable, robust and reliable</strong>, as far as technically feasible and in line with the state of the art. Providers may rely on an adequate Code of Practice to demonstrate compliance; those who do not adhere to one must provide equivalent alternative measures and should expect closer scrutiny and more information requests.</p>
<h2>What must be labeled under Article 50(4)</h2>
<p>This obligation sits on <strong>deployers</strong> and concerns visible, perceivable disclosure. It has two limbs.</p>
<h3>Deepfakes</h3>
<p>A &ldquo;deepfake&rdquo; is AI-generated or manipulated image, audio or video content that (i) appreciably resembles (ii) an existing (iii) person, object, place, entity or event, and (iv) would falsely appear to a person to be authentic or truthful. &ldquo;Existing&rdquo; is read broadly: something that exists, plausibly could exist, or could have plausibly existed. Content that defies physics or biology &ndash; a dragon, an elephant driving a car &ndash; is not a deepfake, because it cannot mislead.</p>
<p>Minor or cosmetic AI manipulation of existing content does not make it a deepfake in the first place, where the change has too little effect on how a viewer perceives the content&rsquo;s authenticity or truthfulness &ndash; for example, editing out a background passer-by, adjusting lighting or color, noise reduction, re-scaling or file compression. This is a threshold question, not an exemption: such content is simply not a deep fake, so no labelling duty arises. Whether a given edit stays on this side of the line is context-dependent: the Guidelines contrast these cosmetic operations with substantial AI editing of journalistic images, where the expectation of authenticity is high enough that a similar change may affect perceived authenticity and cross into deep fake territory.</p>
<p>The fourth criterion is assessed <strong>objectively</strong> and in context; the deployer&rsquo;s intention to deceive is not required. Where the foreseeable audience does not expect the content to be authentic &ndash; for instance, standard special effects in a movie &ndash; the content may not &ldquo;falsely appear&rdquo; authentic and so falls outside the definition. But fully AI-generated actors, digital replicas of real or deceased actors, de-aging, or non-authentic depictions in documentaries generally will be deepfakes.</p>
<p><strong>Deepfakes must be clearly and distinctly labeled.</strong> A lighter regime applies to content that is <strong>evidently</strong> artistic, creative, satirical, fictional or analogous: the disclosure need only be made in a manner that does not hamper enjoyment of the work, but disclosure is still required, and the &ldquo;evidently&rdquo; threshold is read strictly. <strong>Two limits keep this regime narrow.</strong> Where content mixes an informative and a creative character, the informative character prevails labeling, and full labeling applies; and the lighter regime is, in any event, subject to appropriate safeguards for third-party rights, so it is no justification for disregarding data-protection or intellectual-property obligations.</p>
<h3>Public-interest text</h3>
<p>AI-generated or manipulated <strong>text published to inform the public on matters of public interest</strong> must also be labeled. &ldquo;Published&rdquo; means accessible to an indeterminate, fairly large group; &ldquo;public interest&rdquo; covers politics, public administration, justice, fundamental rights, public health and safety, the environment, consumer safety, and economic, financial, scientific or cultural developments meriting public debate.</p>
<p>There is an important <strong>exception</strong>: text that has undergone genuine <strong>human review or editorial control</strong> and for which a natural or legal person holds <strong>editorial responsibility</strong> need not be labeled. Both conditions are cumulative. A superficial spell-check, an automated review, or a mere editorial policy will not do &ndash; the review must engage with the substance, and fact-checking is the minimum. If AI makes any substantive change after editorial sign-off, the exception falls away.</p>
<p>For a regulated financial entity, note the concrete examples the Guidelines give as <strong>in scope</strong>: AI-manipulated corporate reports containing investor information on a listed company&rsquo;s website, and AI-generated sustainability reports &ndash; both of which need labeling unless the human-review/editorial-responsibility exception is satisfied. Conversely, an AI-manipulated advice text prepared by a consultant for a single client on regulatory compliance is <strong>not</strong> &ldquo;published&rdquo; and falls outside 50(4).</p>
<h2>How to label in practice</h2>
<p>Article 50 does not dictate wording. The Code of Practice does the practical work: the AI Office has published three EU icons &ndash; AI involved, fully AI-generated, and human content modified by AI &ndash; free to use, and testing showed that an icon on its own is not enough. The icon plus a few plain words are what people actually understand. &ldquo;AI&rdquo; is the only abbreviation to use.</p>
<p>What that looks like in practice. An icon and &ldquo;Image created with AI&rdquo; in the caption of a social media post &ndash; not in the small print. A spoken line in the first seconds of a podcast produced with a synthetic voice. A badge at the top of an AI-drafted news summary, not in the website footer. A mark that stays in the corner of the screen while an AI presenter is speaking. Give the icon alt text so a screen reader conveys it, leave a temporary label up long enough to be read, and use the same icon and the same words everywhere.</p>
<p><strong>A label is not a license.</strong> The Guidelines are emphatic that complying with Article 50 does not make the content or its use lawful. A properly labeled deep fake can still be unlawful on other grounds &ndash; child sexual abuse material, non-consensual intimate imagery, trademark or copyright infringement, misleading advertising &ndash; and a 50(3) notice does not legitimize an emotion-recognition deployment that is prohibited under Article 5 or unlawful under data protection law.</p>
<p>Marking and labeling answer the question <strong>&ldquo;is this AI?&rdquo;,</strong> not <strong>&ldquo;is this allowed?&rdquo;</strong> The two assessments are separate.</p>
<h2>The other two obligations, briefly</h2>
<h3>When must a chatbot tell users that they are interacting with AI?</h3>
<p>Providers of systems that interact <strong>directly</strong> with people &ndash; chatbots, voice assistants, AI companions, AI agents &ndash; must design them so the person is told they are dealing with AI, at the latest at the first interaction. The disclosure must be clear and in context: a first-turn message, a spoken statement, a persistent badge. Burying it in terms and conditions, or relying on a vague reference to an &ldquo;assistant&rdquo; or &ldquo;this system uses LLMs&rdquo;, is not enough.</p>
<p>There is an <strong>obviousness</strong> exception &ndash; no disclosure is needed where it would be obvious to a reasonably well-informed, observant and circumspect person that they are dealing with AI. But the Guidelines read this narrowly: general awareness that chatbots exist does not mean people recognize them in a given interaction, and the exception is unavailable where vulnerable groups (children, the elderly, the less digitally literate) may be exposed. A professional-only internal helpdesk assistant may qualify; a public-facing helpdesk chatbot generally will not.</p>
<p><strong>AI agents carry an extra layer.</strong> An agent must disclose not only its artificial nature but also the person on whose behalf it acts, reflecting the need for transparency regarding both its origin and delegated authority. Where the provider cannot know in advance whether an agent will meet a natural person, it must be designed to disclose itself in every situation where interaction with a person is reasonably likely, including in multi-agent chains where another agent is the one facing the person. Agents should also re-disclose to the person instructing them at key steps such as authorization, reporting and validation, and at every new interaction.</p>
<h3>Emotion recognition and biometric categorization &ndash; Article 50(3)</h3>
<p>Deployers of these systems must inform the people exposed to them that the system is operating &ndash; for example, a notice at the entrance to a space where facial images are captured to infer age, or a pop-up before a game that reads the player&rsquo;s emotions. This applies whether the system runs in real time or after the fact, and to any biometric categorization system (unless outright prohibited under Article 5).</p>
<h2>Timing, accessibility and penalties</h2>
<p>Whatever the obligation, Article 50(5) requires the information to be given <strong>clearly and distinguishably, at the latest at the first interaction or exposure</strong>, and in an accessible format. &ldquo;First exposure&rdquo; means the start of a video featuring a deepfake, the start of a public-interest text, or the moment a person scrolling through social media encounters the content. Where children are foreseeably in the audience, the disclosure must be child-friendly and age-appropriate.</p>
<p>Non-compliance is not trivial. Fines can reach <strong>EUR 15 000 000 or 3% of total worldwide annual turnover</strong>, whichever is higher (EU institutions face up to EUR 750 000; small and medium-sized enterprises (SMEs) and start-ups face the lower of the two figures). Enforcement sits with national market surveillance authorities, the AI Office for systems based on general-purpose AI (GPAI) models, and the European Data Protection Supervisor (EDPS) for EU institutions.</p>
<p>In Lithuania, the Communications Regulatory Authority (RRT) has already issued public guidance of its own on when AI-generated content must be marked and when it need not be &ndash; an early signal that the national supervisor intends to engage with these obligations actively rather than wait for complaints.</p>
<p><strong>On timing of application:</strong> Article 50 has applied since 2 August 2026 to all in-scope systems on the market on that date, regardless of when they were placed. A targeted grandfathering rule under the AI Omnibus gives providers of existing generative systems until 2 December 2026 to bring the 50(2) marking into conformity &ndash; but the 50(1) interaction disclosure had to be in place by 2 August 2026. Content generated before 2 August 2026 need not be marked or labeled retroactively, but pre-existing text published on or after that date does need labeling.</p>
<h2>What should businesses pay attention to?</h2>
<p>Four practical points to act on:</p>
<ul>
<li><strong>Separate the two &ldquo;markings&rdquo;.</strong> Providers owe invisible, machine-readable markings on synthetic output (50(2)); deployers owe visible labels on deepfakes and public-interest text (50(4)). One does not cover the other.</li>
<li><strong>Get the label right &ndash; and know what needs none.</strong> The EU icon, plus a short, plain-language line (&ldquo;AI&rdquo; is the only abbreviation to use), placed where the content is consumed, with alt text and an audio disclaimer when there is nothing to see. Standard editing, translation, formatting, source code, short labels and genuine internal B2B output fall outside the marking duty entirely &ndash; that is where much of the practical relief lies.</li>
<li><strong>Watch the text limb closely.</strong> AI-touched investor and sustainability reports on a company website count as text published on matters of public interest, so they are squarely in scope unless the human-review and editorial-responsibility exception is properly documented &ndash; and that exception collapses if AI edits the text after sign-off.</li>
<li><strong>Consider the Code of Practice.</strong> Adhering to the adequate Code of Practice is the most predictable way to demonstrate compliance with the 50(2) and 50(4) content obligations; non-signatories should run a gap analysis against it and keep evidence of equivalent measures.</li>
</ul>
<p><strong>Businesses introducing AI systems should assess Article 50 alongside their wider AI governance, data protection and intellectual property obligations. ECOVIS ProventusLaw can assist with this assessment and the implementation of appropriate compliance measures.</strong></p>
<p>This article reflects ECOVIS ProventusLaw&#8217;s interpretation of the Commission&#8217;s non-binding Guidelines and Code of Practice and is provided for general information purposes only. It does not constitute legal advice; specific advice should be obtained before acting on any part of it.</p>
<div class="article-authors">
<h2 class="article-authors__title">About the Author</h2>
<div id="text-2347073171" class="text"><strong>Augustinas Gečas</strong> is a Junior Associate in the FinTech group at ECOVIS ProventusLaw, where he focuses on FinTech regulation and the legal aspects of artificial intelligence, supporting clients navigating the evolving Baltic and EU regulatory landscape.</div>
</div>


<p>The post <a href="https://ecovis.lt/ai-act-transparency-guidelines/">AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What must an activity (business) plan contain to obtain a financial license in Lithuania &#8211; and what the Bank of Lithuania may assess</title>
		<link>https://ecovis.lt/business-plan-requirements-for-financial-license-lithuania/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 16:39:30 +0000</pubDate>
				<category><![CDATA[Fintech]]></category>
		<category><![CDATA[Insight]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11620</guid>

					<description><![CDATA[<p>The Supreme Administrative Court of Lithuania annuls a specialized bank license refusal for inadequate reasoning – and marks out the limits of the supervisor's assessment, with consequences for banks, CASP, EMI, PI and crowdfunding applicants alike.</p>
<h2>What must an activity (business) plan contain to obtain a financial license in Lithuania - and what the Bank of Lithuania may assess</h2>
<p>Any business preparing to apply for a bank or specialized bank, crypto-asset service provider (CASP), electronic money institution (EMI), payment institution (PI), crowdfunding or any other license in Lithuania invests heavily long before it ever sees a decision - capital locked up to form the share capital, hiring the teams, months of drafting, and repeated rounds of comments from the Bank of Lithuania on its activity plan and program of operations. The obvious questions for such an applicant are: <strong>on what basis can the supervisor say „no", and what does a lawful refusal actually have to contain?</strong></p>
<p>The Supreme Administrative Court's ruling gives concrete answers to both of those questions - on what basis the supervisor may say „no", and what a lawful refusal must contain. It marks out what the Bank of Lithuania may legitimately weigh when it assesses whether a future bank will operate „safely and soundly" - and it sets a clear evidentiary standard the supervisor must meet before it can refuse on that ground. For anyone at the pre-application or authorization stage, it is a practical map of where the supervisor's discretion ends and where an applicant's leverage begins.</p>
<p>And although the case concerns a bank license, its most important lessons are not confined to banking. The ruling is <strong>directly relevant beyond bank licensing - to CASPs, PIs and EMIs, crowdfunding companies and financial brokerage companies</strong> - because both rules the Court applied - no refusals on the ground that the business is not worth doing, and no refusals without reasons - come from the Civil Code and general administrative law, not the Law on Banks. Any applicant that has received, or fears, a thinly reasoned refusal from the Bank of Lithuania should read on.</p>
<p>On 17 September 2025 the Supreme Administrative Court of Lithuania (the Court), sitting as an extended chamber, delivered its ruling in <em>UAB Baltic Financial Company v. Bank of Lithuania</em> (administrative case No. eA-111-520/2025). The judgment is a useful read for anyone advising credit-institution licensing applicants, because it confirms how wide the supervisor's discretion is when assessing <strong>an activity plan</strong> - and, at the same time, how firmly that discretion is bound by the duty to give reasons.</p>
<h2>Background</h2>
<p>The applicant, a company with capital from another EU Member State (Bulgaria), applied to the Bank of Lithuania for a specialized bank license. After an extended licensing procedure - a preliminary application under the Newcomer programme, a first application withdrawn and refiled on the same day, several rounds of comments, a meeting, and five revisions of the activity plan - the Bank of Lithuania Board refused the license by Resolution No. 03-18 of 20 January 2022. The stated ground was that <strong>the applicant's activity plan did not ensure the safe and sound operation of the future bank</strong>, contrary to Article 9(12) and Article 9(13)(2) of the Law on Banks, read together with Article 43(1)(3) of the Law on the Bank of Lithuania.</p>
<p>The applicant challenged the resolution and claimed over EUR 1 million in damages. The first-instance court (Vilnius Regional Administrative Court) dismissed the claim in full in June 2023. The applicant appealed.</p>
<h2>What the supervisor may - and may not - assess</h2>
<p>A central plank of the applicant's case was that the refusal was, in substance, a judgment on the economic desirability of its business, which is prohibited. Two rules were invoked: Article 11 of Directive 2013/36/EU (CRD), under which Member States may not require an application for authorization to be examined against the economic needs of the market, and Article 2.79(3) of the Civil Code (a refusal to grant a license may not be based on the inexpediency of the activity and must be reasoned).</p>
<p>The Court drew a careful line here, and it is the part of the judgment most worth remembering.</p>
<p>The supervisor <strong>may not</strong> refuse a license on the basis that the market does not need another participant, or that the proposed activity is not worthwhile. That is the economic-needs test the CRD forbids.</p>
<p>The supervisor <strong>may</strong>, however, assess the viability and sustainability of the business model, the realism of the applicant's projections, and the surrounding business environment - including comparable institutions, market trends and other external factors. Crucially, the Court held that examining the environment and peers is legitimate precisely because it helps the supervisor test whether the applicant's own projections are realistic. <strong>Assessing the environment to verify the plausibility of a forecast is not the same as assessing whether the market needs the entity.</strong> The Court relied on the European Central Bank (ECB) Guide to assessments of license applications, 2nd revised edition, January 2019 (ECB Guide) and the European Banking Authority (EBA) Guidelines on a common assessment methodology for granting authorization as a credit institution (EBA/GL/2021/12), both of which expressly contemplate qualitative and quantitative review of the activity plan, peer comparison, and baseline and adverse scenarios over roughly the first three years of operation.</p>
<p>On this point the applicant's argument failed. The Court agreed with the first-instance court that the Bank of Lithuania had not assessed economic need, and that the sustainability and viability of the business model are proper qualitative criteria in a licensing assessment.</p>
<h2>Wide discretion - but not unbounded</h2>
<p>The Court reaffirmed that decisions on whether to grant a bank license are discretionary in nature. Assessing whether an activity plan ensures safe and sound operation involves complex economic and financial judgment, and it serves a significant public interest - the stability of the financial system, which the Constitutional Court has repeatedly recognized as a significant public interest.</p>
<p>The Court also drew on Court of Justice of the European Union (CJEU) case law on decisions taken by the ECB in the exercise of a wide margin of appraisal. Judicial review of such a decision does not substitute the court's assessment for the supervisor's; it checks whether the decision rests on materially accurate facts, whether there is an error of law, a manifest error of assessment, or a misuse of powers, and whether the supervisor examined all the relevant elements carefully and impartially and observed the procedural guarantees. Discretion, the Court stressed, is never an unreasoned or unconstrained choice.</p>
<h2>Where the resolution failed: the duty to give reasons</h2>
<p>Having upheld the supervisor's power to make the assessment it made, <strong>the Court found the decisive flaw in <em>how</em> the assessment was expressed.</strong></p>
<p>The applicant had submitted an activity plan with baseline, growth and adverse scenarios, together with financial projections for each, and had provided further argument on the plan's realism. Against that, the resolution:</p>
<ul>
<li>asserted only in the abstract that the applicant had failed to substantiate its ability to reach the planned lending volumes, without engaging with specific provisions of the plan or the explanations given;</li>
<li>referred to the competitive environment - the number of active specialized banks in the consumer-lending market, the incumbent's pre-existing client base, the applicant's lack of a track record in Lithuania - without naming the entities, quantifying their activity, or tying any of this to concrete provisions of the applicant's plan;</li>
<li>raised the negative yield on securities without explaining what effect that would actually have on the safety and soundness of the applicant's overall planned activity; and</li>
<li>did not assess at all the adverse-case scenario that the applicant had itself submitted, even though the ECB Guide envisages review under both baseline and adverse scenarios.</li>
</ul>
<p>In short, the conclusion that the plan did not ensure safe and sound operation was not underpinned by concrete data or linked to specific provisions of the plan set against a data-based picture of the business environment.</p>
<p>The Court held this to be a breach of Article 10(5)(5) and (6) of the Law on Public Administration (the requirement to state the factual basis and the reasons for an administrative decision) and of Article 2.79(3) of the Civil Code. Referring to the CJEU, it recalled that the duty to give reasons - an expression of the right to good administration under Article 41 of the EU Charter of Fundamental Rights and of effective judicial protection under Article 47 - exists so that the addressee can assess whether the decision is flawed and so that the reviewing Court can exercise its control. A supervisor's duty to reason its own decisions cannot be shifted onto the Court that later reviews them.</p>
<h2>Outcome</h2>
<p>The Court partially upheld the appeal. It <strong>set aside the first-instance judgment, annulled the Bank of Lithuania resolution for inadequate reasoning, and remitted the damages claim</strong> to the first-instance court for fresh examination - the essence of that claim not having been examined below, and the applicant needing to specify which defendant it targets and on what basis. The requests to refer questions to the CJEU and to the Constitutional Court were refused, the former partly because the deadline-related questions rested on facts the applicant had not proven. The ruling is final.</p>
<h2>Takeaways</h2>
<p>The principal takeaway is that the Court mapped out what the Bank of Lithuania may and may not examine.</p>
<ul>
<li>It <strong>may not</strong> refuse a license on the ground that the market does not need another participant, or that the proposed activity is not worthwhile - that is the economic-needs test the CRD forbids.</li>
<li>It <strong>may</strong> examine the viability and sustainability of the business model; the realism of the applicant's financial projections; the applicant's ability to reach its planned volumes; and the surrounding business environment - comparable institutions, market trends and other external factors - but the environment may be examined only as a tool for testing whether the applicant's own projections are plausible, not as a proxy for market need. It <strong>may</strong> also review the plan qualitatively and quantitatively, compare it against peers, and test it under both baseline and adverse scenarios over roughly the first three years of operation.</li>
</ul>
<p>This is the takeaway that matters during compliance work and at the licensing stage: it tells an applicant which questions it must be ready to answer with data - and which lines of inquiry fall outside the supervisor's remit and can be pushed back on.</p>
<p>The second takeaway is that a refusal must be reasoned, and the judgment says with unusual precision what a reasoned refusal looks like. It is not enough to assert in the abstract that an activity plan does not ensure safe and sound operation. The supervisor must:</p>
<ul>
<li>engage with the specific provisions of the plan and the explanations the applicant gave;</li>
<li>name and quantify the comparators and market data it relies on, rather than referring to the competitive environment in general terms;</li>
<li>explain what effect each factor it invokes would actually have on the safety and soundness of the planned activity; and</li>
<li>expressly assess any adverse-case scenario the applicant itself submitted.</li>
</ul>
<p>A wide margin of appraisal does not lower that evidentiary bar, and the supervisor cannot shift the task of reasoning onto the court that later reviews the decision.</p>
<p><strong>The practical consequence is straightforward.</strong> Where those elements of reasoning are missing, the refusal is vulnerable on judicial review however defensible the underlying supervisory judgment may be - and annulment for inadequate reasoning is a realistic outcome, as it was here.</p>
<h2>What this means for your activity plan</h2>
<p>The third takeaway belongs to the drafting stage. The judgment does not prescribe what an activity plan must contain, but it shows what the plan will be tested against. Present a baseline, a growth and an adverse scenario with financial projections for each over roughly the first three years, and substantiate the planned volumes rather than asserting them - the assumptions behind the targets, the route to customers, and the pricing behind the projected revenue. Expect the plan to be read against peers and market data, and pre-empt that reading with your own comparison, and keep every explanation given during the licensing dialogue on the record.</p>
<p>The post <a href="https://ecovis.lt/business-plan-requirements-for-financial-license-lithuania/">What must an activity (business) plan contain to obtain a financial license in Lithuania &#8211; and what the Bank of Lithuania may assess</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The Supreme Administrative Court of Lithuania annuls a specialized bank license refusal for inadequate reasoning – and marks out the limits of the supervisor&#8217;s assessment, with consequences for banks, CASP, EMI, PI and crowdfunding applicants alike</p>
<h2>What must an activity (business) plan contain to obtain a <a href="https://ecovis.lt/fintech/" target="_blank" rel="noopener">financial license</a> in Lithuania &#8211; and what the Bank of Lithuania may assess</h2>
<p>Any business preparing to apply for a bank or specialized bank, crypto-asset service provider (CASP), electronic money institution (EMI), payment institution (PI), crowdfunding or any other license in Lithuania invests heavily long before it ever sees a decision &#8211; capital locked up to form the share capital, hiring the teams, months of drafting, and repeated rounds of comments from the Bank of Lithuania on its activity plan and program of operations. The obvious questions for such an applicant are: <strong>on what basis can the supervisor say „no&#8221;, and what does a lawful refusal actually have to contain?</strong></p>
<p>The Supreme Administrative Court&#8217;s ruling gives concrete answers to both of those questions &#8211; on what basis the supervisor may say „no&#8221;, and what a lawful refusal must contain. It marks out what the Bank of Lithuania may legitimately weigh when it assesses whether a future bank will operate „safely and soundly&#8221; &#8211; and it sets a clear evidentiary standard the supervisor must meet before it can refuse on that ground. For anyone at the pre-application or authorization stage, it is a practical map of where the supervisor&#8217;s discretion ends and where an applicant&#8217;s leverage begins.</p>
<p>And although the case concerns a bank license, its most important lessons are not confined to banking. The ruling is <strong>directly relevant beyond bank licensing &#8211; to CASPs, PIs and EMIs, crowdfunding companies and financial brokerage companies</strong> &#8211; because both rules the Court applied &#8211; no refusals on the ground that the business is not worth doing, and no refusals without reasons &#8211; come from the Civil Code and general administrative law, not the Law on Banks. Any applicant that has received, or fears, a thinly reasoned refusal from the Bank of Lithuania should read on.</p>
<p>On 17 September 2025 the Supreme Administrative Court of Lithuania (the Court), sitting as an extended chamber, delivered its ruling in <em>UAB Baltic Financial Company v. Bank of Lithuania</em> (administrative case No. eA-111-520/2025). The judgment is a useful read for anyone advising credit-institution licensing applicants, because it confirms how wide the supervisor&#8217;s discretion is when assessing <strong>an activity plan</strong> &#8211; and, at the same time, how firmly that discretion is bound by the duty to give reasons.</p>
<h2>Background</h2>
<p>The applicant, a company with capital from another EU Member State (Bulgaria), applied to the Bank of Lithuania for a specialized bank license. After an extended licensing procedure &#8211; a preliminary application under the Newcomer programme, a first application withdrawn and refiled on the same day, several rounds of comments, a meeting, and five revisions of the activity plan &#8211; the Bank of Lithuania Board refused the license by Resolution No. 03-18 of 20 January 2022. The stated ground was that <strong>the applicant&#8217;s activity plan did not ensure the safe and sound operation of the future bank</strong>, contrary to Article 9(12) and Article 9(13)(2) of the Law on Banks, read together with Article 43(1)(3) of the Law on the Bank of Lithuania.</p>
<p>The applicant challenged the resolution and claimed over EUR 1 million in damages. The first-instance court (Vilnius Regional Administrative Court) dismissed the claim in full in June 2023. The applicant appealed.</p>
<h2>What the supervisor may &#8211; and may not &#8211; assess</h2>
<p>A central plank of the applicant&#8217;s case was that the refusal was, in substance, a judgment on the economic desirability of its business, which is prohibited. Two rules were invoked: Article 11 of Directive 2013/36/EU (CRD), under which Member States may not require an application for authorization to be examined against the economic needs of the market, and Article 2.79(3) of the Civil Code (a refusal to grant a license may not be based on the inexpediency of the activity and must be reasoned).</p>
<p>The Court drew a careful line here, and it is the part of the judgment most worth remembering.</p>
<p>The supervisor <strong>may not</strong> refuse a license on the basis that the market does not need another participant, or that the proposed activity is not worthwhile. That is the economic-needs test the CRD forbids.</p>
<p>The supervisor <strong>may</strong>, however, assess the viability and sustainability of the business model, the realism of the applicant&#8217;s projections, and the surrounding business environment &#8211; including comparable institutions, market trends and other external factors. Crucially, the Court held that examining the environment and peers is legitimate precisely because it helps the supervisor test whether the applicant&#8217;s own projections are realistic. <strong>Assessing the environment to verify the plausibility of a forecast is not the same as assessing whether the market needs the entity.</strong> The Court relied on the European Central Bank (ECB) Guide to assessments of license applications, 2nd revised edition, January 2019 (ECB Guide) and the European Banking Authority (EBA) Guidelines on a common assessment methodology for granting authorization as a credit institution (EBA/GL/2021/12), both of which expressly contemplate qualitative and quantitative review of the activity plan, peer comparison, and baseline and adverse scenarios over roughly the first three years of operation.</p>
<p>On this point the applicant&#8217;s argument failed. The Court agreed with the first-instance court that the Bank of Lithuania had not assessed economic need, and that the sustainability and viability of the business model are proper qualitative criteria in a licensing assessment.</p>
<h2>Wide discretion &#8211; but not unbounded</h2>
<p>The Court reaffirmed that decisions on whether to grant a bank license are discretionary in nature. Assessing whether an activity plan ensures safe and sound operation involves complex economic and financial judgment, and it serves a significant public interest &#8211; the stability of the financial system, which the Constitutional Court has repeatedly recognized as a significant public interest.</p>
<p>The Court also drew on Court of Justice of the European Union (CJEU) case law on decisions taken by the ECB in the exercise of a wide margin of appraisal. Judicial review of such a decision does not substitute the court&#8217;s assessment for the supervisor&#8217;s; it checks whether the decision rests on materially accurate facts, whether there is an error of law, a manifest error of assessment, or a misuse of powers, and whether the supervisor examined all the relevant elements carefully and impartially and observed the procedural guarantees. Discretion, the Court stressed, is never an unreasoned or unconstrained choice.</p>
<h2>Where the resolution failed: the duty to give reasons</h2>
<p>Having upheld the supervisor&#8217;s power to make the assessment it made, <strong>the Court found the decisive flaw in <em>how</em> the assessment was expressed.</strong></p>
<p>The applicant had submitted an activity plan with baseline, growth and adverse scenarios, together with financial projections for each, and had provided further argument on the plan&#8217;s realism. Against that, the resolution:</p>
<ul>
<li>asserted only in the abstract that the applicant had failed to substantiate its ability to reach the planned lending volumes, without engaging with specific provisions of the plan or the explanations given;</li>
<li>referred to the competitive environment &#8211; the number of active specialized banks in the consumer-lending market, the incumbent&#8217;s pre-existing client base, the applicant&#8217;s lack of a track record in Lithuania &#8211; without naming the entities, quantifying their activity, or tying any of this to concrete provisions of the applicant&#8217;s plan;</li>
<li>raised the negative yield on securities without explaining what effect that would actually have on the safety and soundness of the applicant&#8217;s overall planned activity; and</li>
<li>did not assess at all the adverse-case scenario that the applicant had itself submitted, even though the ECB Guide envisages review under both baseline and adverse scenarios.</li>
</ul>
<p>In short, the conclusion that the plan did not ensure safe and sound operation was not underpinned by concrete data or linked to specific provisions of the plan set against a data-based picture of the business environment.</p>
<p>The Court held this to be a breach of Article 10(5)(5) and (6) of the Law on Public Administration (the requirement to state the factual basis and the reasons for an administrative decision) and of Article 2.79(3) of the Civil Code. Referring to the CJEU, it recalled that the duty to give reasons &#8211; an expression of the right to good administration under Article 41 of the EU Charter of Fundamental Rights and of effective judicial protection under Article 47 &#8211; exists so that the addressee can assess whether the decision is flawed and so that the reviewing Court can exercise its control. A supervisor&#8217;s duty to reason its own decisions cannot be shifted onto the Court that later reviews them.</p>
<h2>Outcome</h2>
<p>The Court partially upheld the appeal. It <strong>set aside the first-instance judgment, annulled the Bank of Lithuania resolution for inadequate reasoning, and remitted the damages claim</strong> to the first-instance court for fresh examination &#8211; the essence of that claim not having been examined below, and the applicant needing to specify which defendant it targets and on what basis. The requests to refer questions to the CJEU and to the Constitutional Court were refused, the former partly because the deadline-related questions rested on facts the applicant had not proven. The ruling is final.</p>
<h2>Takeaways</h2>
<p>The principal takeaway is that the Court mapped out what the Bank of Lithuania may and may not examine.</p>
<ul>
<li>It <strong>may not</strong> refuse a license on the ground that the market does not need another participant, or that the proposed activity is not worthwhile &#8211; that is the economic-needs test the CRD forbids.</li>
<li>It <strong>may</strong> examine the viability and sustainability of the business model; the realism of the applicant&#8217;s financial projections; the applicant&#8217;s ability to reach its planned volumes; and the surrounding business environment &#8211; comparable institutions, market trends and other external factors &#8211; but the environment may be examined only as a tool for testing whether the applicant&#8217;s own projections are plausible, not as a proxy for market need. It <strong>may</strong> also review the plan qualitatively and quantitatively, compare it against peers, and test it under both baseline and adverse scenarios over roughly the first three years of operation.</li>
</ul>
<p>This is the takeaway that matters during compliance work and at the licensing stage: it tells an applicant which questions it must be ready to answer with data &#8211; and which lines of inquiry fall outside the supervisor&#8217;s remit and can be pushed back on.</p>
<p>The second takeaway is that a refusal must be reasoned, and the judgment says with unusual precision what a reasoned refusal looks like. It is not enough to assert in the abstract that an activity plan does not ensure safe and sound operation. The supervisor must:</p>
<ul>
<li>engage with the specific provisions of the plan and the explanations the applicant gave;</li>
<li>name and quantify the comparators and market data it relies on, rather than referring to the competitive environment in general terms;</li>
<li>explain what effect each factor it invokes would actually have on the safety and soundness of the planned activity; and</li>
<li>expressly assess any adverse-case scenario the applicant itself submitted.</li>
</ul>
<p>A wide margin of appraisal does not lower that evidentiary bar, and the supervisor cannot shift the task of reasoning onto the court that later reviews the decision.</p>
<p><strong>The practical consequence is straightforward.</strong> Where those elements of reasoning are missing, the refusal is vulnerable on judicial review however defensible the underlying supervisory judgment may be &#8211; and annulment for inadequate reasoning is a realistic outcome, as it was here.</p>
<h2>What this means for your activity plan</h2>
<p>The third takeaway belongs to the drafting stage. The judgment does not prescribe what an activity plan must contain, but it shows what the plan will be tested against. Present a baseline, a growth and an adverse scenario with financial projections for each over roughly the first three years, and substantiate the planned volumes rather than asserting them &#8211; the assumptions behind the targets, the route to customers, and the pricing behind the projected revenue. Expect the plan to be read against peers and market data, and pre-empt that reading with your own comparison, and keep every explanation given during the licensing dialogue on the record.</p>
<div class="article-authors">
<h2 class="article-authors__title">About the Author</h2>
<div id="text-2347073171" class="text"><strong>Augustinas Gečas</strong> is a Junior Associate in the FinTech group at ECOVIS ProventusLaw, where he focuses on FinTech regulation and the legal aspects of artificial intelligence, supporting clients navigating the evolving Baltic and EU regulatory landscape.</div>
</div>

<p>The post <a href="https://ecovis.lt/business-plan-requirements-for-financial-license-lithuania/">What must an activity (business) plan contain to obtain a financial license in Lithuania &#8211; and what the Bank of Lithuania may assess</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Crypto &#038; Investments Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-crypto-investments-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 11:36:57 +0000</pubDate>
				<category><![CDATA[Crypto & Digital Assets]]></category>
		<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11574</guid>

					<description><![CDATA[<p>The EU crypto regulatory framework has now moved decisively from implementation to supervision and enforcement. With the MiCA transitional period ending across the EU on 1 July 2026, regulators are increasingly focused on how authorised CASPs actually operate: custody, operational resilience, client-asset protection, advice, crypto lending, sanctions compliance and exposure to DeFi.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-crypto-investments-regulation-august-2026/">RegRally Insights: Crypto &#038; Investments Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The <a href="https://ecovis.lt/fintech/crypto-currency-exchange-license/" target="_blank" rel="noopener">EU crypto</a> regulatory framework has now moved decisively from implementation to supervision and enforcement. With the MiCA transitional period ending across the EU on 1 July 2026, regulators are increasingly focused on how authorised CASPs actually operate: custody, operational resilience, client-asset protection, advice, crypto lending, sanctions compliance and exposure to DeFi.</p>
<p>At the same time, FATF is highlighting growing risks linked to stablecoins, unhosted wallets, offshore VASPs and decentralised finance, while European supervisors are increasing scrutiny of ICT and AI-related risks.</p>
<p>This month&#8217;s RegRally focuses on the developments most relevant to CASPs, crypto businesses, investment firms, issuers and financial institutions operating with digital assets.</p>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#latvia-10th-mica-licence-nodu-digital">Latvia issues its 10th MiCA licence to Nodu Digital</a></li>
<li><a href="#esma-csa-casp-custody-operational-resilience">ESMA launches EU-wide supervisory action on CASP custody and operational resilience</a></li>
<li><a href="#esma-mica-qa-advice-lending-token-distributions">ESMA clarifies MiCA rules on crypto advice, lending and token distributions</a></li>
<li><a href="#esma-t1-settlement-deadlines">ESMA sets deadlines for the EU move to T+1 settlement</a></li>
<li><a href="#esas-ai-driven-ict-risks">European Supervisory Authorities highlight AI-driven ICT risks for financial entities</a></li>
<li><a href="#fatf-stablecoins-unhosted-wallets-offshore-vasps">FATF identifies growing risks around stablecoins, unhosted wallets and offshore VASPs</a></li>
<li><a href="#fatf-functional-approach-defi-regulation">FATF calls for a functional approach to DeFi regulation</a></li>
<li><a href="#eu-sanctions-crypto-specific-restrictions">EU sanctions package introduces new crypto-specific restrictions</a></li>
<li><a href="#latvia-investment-firm-licence-c-capital-markets">Latvia issues investment firm licence following pre-licensing cooperation</a></li>
<li><a href="#mica-transitional-period-ended">MiCA transitional period has ended: unlicensed CASPs must wind down</a></li>
</ul>
</div>
<h2 id="latvia-10th-mica-licence-nodu-digital">Latvia issues its 10th <a href="https://ecovis.lt/fintech/solutions-for-blockchain-cryptocurrency-ico/" target="_blank" rel="noopener">MiCA licence</a> to Nodu Digital</h2>
<p><strong>Date:</strong> 9 July 2026 | <strong>Source:</strong> Latvijas Banka<br /><i class="fa fa-external-link"></i><a href="https://www.bank.lv/en/news-and-events/news-and-articles/news/17744-latvijas-banka-is-issuing-two-licences-to-nodu-digital-sia" target="_blank" rel="noopener"> Link</a></p>
<p>Latvijas Banka issued Nodu Digital SIA both a MiCA licence for crypto-asset services and a payment institution licence. The CASP authorisation covers the exchange of crypto-assets for funds and the provision of crypto-asset transfer services on behalf of clients.</p>
<p>Nodu Digital became the 10th company authorised under MiCA by Latvijas Banka. Once authorised in one EU Member State, a CASP can provide its authorised services across the EU through the cross-border notification mechanism.</p>
<h3>Why it matters</h3>
<p>The decision illustrates the growing importance of combining crypto-asset and payment regulatory analysis for businesses operating crypto payment models. For businesses whose model involves both fiat payment services and crypto-asset services, the regulatory perimeter may require parallel authorisation strategies.</p>
<h3>Recommended actions</h3>
<ul>
<li>Determine whether the proposed business model requires both CASP and PI authorisation.</li>
<li>Map the regulatory perimeter before preparing the licensing application.</li>
<li>Use Latvijas Banka&#8217;s pre-licensing consultations to resolve classification and authorisation questions early.</li>
<li>Consider whether the business model can benefit from EU-wide cross-border provision following MiCA authorisation.</li>
</ul>
<hr />
<h2 id="esma-csa-casp-custody-operational-resilience">ESMA launches EU-wide supervisory action on CASP custody and operational resilience</h2>
<p><strong>Date:</strong> 8 July 2026 | <strong>Source:</strong> ESMA<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/esma-launches-common-supervisory-action-casps-digital-operational-resilience" target="_blank" rel="noopener"> Link</a></p>
<p>ESMA launched a Common Supervisory Action (CSA) with national competent authorities focusing on the digital operational resilience of CASPs providing custody services.</p>
<p>The supervisory exercise will examine how CASPs manage risks associated with distributed ledger technology, including:</p>
<ul>
<li>governance arrangements;</li>
<li>private key and storage management;</li>
<li>transaction controls;</li>
<li>incident detection and response;</li>
<li>smart contract risks; and</li>
<li>dependencies on third-party providers.</li>
</ul>
<p>National competent authorities will conduct the exercise on a risk-based sample of authorised CASPs from <strong>H2 2026 to H1 2027</strong>, with ESMA&#8217;s consolidated report expected in <strong>H2 2027</strong>.</p>
<h3>Why it matters</h3>
<p>This is a clear indication that MiCA supervision is moving beyond licensing documentation towards testing the operational substance of CASP business models.</p>
<p>Custody arrangements, key management and third-party dependencies are likely to receive particular supervisory attention.</p>
<h3>Recommended actions</h3>
<p>CASPs providing custody services should:</p>
<ul>
<li>review key-management and wallet-storage arrangements;</li>
<li>verify segregation and transaction-control mechanisms;</li>
<li>test incident detection and response procedures;</li>
<li>document smart-contract risk controls;</li>
<li>map critical third-party dependencies, including custody technology and blockchain infrastructure providers; and</li>
<li>assess their framework against both MiCA custody requirements and DORA.</li>
</ul>
<hr />
<h2 id="esma-mica-qa-advice-lending-token-distributions">ESMA clarifies MiCA rules on crypto advice, lending and token distributions</h2>
<p><strong>Date:</strong> 10 July 2026 | <strong>Source:</strong> ESMA<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/new-qas-available-July-2026" target="_blank" rel="noopener"> Link</a></p>
<p>ESMA published a new batch of Q&amp;As providing important clarifications on MiCA.</p>
<p>Three Q&amp;As are particularly relevant to CASPs and crypto businesses.</p>
<h4>Crypto-asset advice – Q&amp;A 2882</h4>
<p>ESMA clarified that the concept of advice on crypto-assets under MiCA is broader than investment advice under MiFID II. Certain introductory or referral activities recommending a crypto-asset service to a potential investor may therefore constitute advice requiring authorisation. A general reference to a CASP that is equally accessible to all investors does not, by itself, constitute advice.</p>
<h4>Crypto-asset lending – Q&amp;A 2883</h4>
<p>ESMA confirmed that CASPs may offer crypto-asset lending as an unregulated service, subject to specific conditions. In particular, clients must provide prior, express and specific consent to the use of their assets. Consent embedded only in general terms and conditions is not sufficient.</p>
<p>The service must also include fair, clear and non-misleading risk disclosures and adequate collateral arrangements. MiCA safeguarding requirements do not apply to assets that have been lent.</p>
<h4>Primary token offerings – Q&amp;A 2417</h4>
<p>ESMA clarified that an issuer transferring crypto-assets directly from an issuance smart contract to purchasers&#8217; wallets in a primary offering does not, by that activity alone, provide custody or transfer services requiring CASP authorisation.</p>
<h3>Why it matters</h3>
<p>These clarifications affect the regulatory perimeter of referral models, crypto lending products and token issuance structures.</p>
<h3>Recommended actions</h3>
<ul>
<li>Review referral, affiliate and introduction arrangements to determine whether they could constitute crypto-asset advice.</li>
<li>Redesign crypto lending consent flows so that client consent is standalone, prominent and specific.</li>
<li>Review risk disclosures and revenue-sharing arrangements for lending products.</li>
<li>For token issuances, document the precise role of the issuer and determine which activities fall within the CASP perimeter.</li>
</ul>
<hr />
<h2 id="esma-t1-settlement-deadlines">ESMA sets deadlines for the EU move to T+1 settlement</h2>
<p><strong>Date:</strong> 20 July 2026 | <strong>Source:</strong> ESMA – T+1 settlement preparations<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/esma-calls-firms-finalise-preparations-ahead-t1-settlement-deadlines" target="_blank" rel="noopener"> Link</a></p>
<p>ESMA published a statement on preparations for the EU&#8217;s transition to a <strong>T+1 settlement cycle</strong>, scheduled for <strong>11 October 2027</strong>.</p>
<p>Two key deadlines apply:</p>
<ul>
<li><strong>7 December 2026</strong> – requirements relating to the exchange of allocations and confirmations, including timing requirements and the default use of international communication standards;</li>
<li><strong>11 October 2027</strong> – requirements aimed at optimising the settlement layer, including earlier submission of settlement instructions and broader use of CSD functionalities.</li>
</ul>
<p>ESMA stresses that preparation must cover the entire trading and settlement chain, including clients, brokers, custodians, CSDs, CCPs, trading venues, vendors and outsourcing providers.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>The transition is particularly relevant for investment firms and businesses with exposure to <strong>tokenised or traditional securities</strong>, where post-trade processes may involve multiple regulated and outsourced providers.</p>
<h3>Recommended actions</h3>
<ul>
<li>Map the complete post-trade chain and identify dependencies.</li>
<li>Confirm vendor and custodian readiness for the December 2026 deadline.</li>
<li>Review Standard Settlement Instructions and reference-data quality.</li>
<li>Identify operational changes required before the 2027 transition.</li>
</ul>
<hr />
<h2 id="esas-ai-driven-ict-risks">European Supervisory Authorities highlight AI-driven ICT risks for financial entities</h2>
<p><strong>Date:</strong> 31 July 2026 | <strong>Source:</strong> ESMA – ESA statement on ICT risks from frontier AI<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision" target="_blank" rel="noopener"> Link</a></p>
<p>The European Supervisory Authorities published a joint statement on ICT risks arising from frontier AI models.</p>
<p>The statement is particularly relevant to CASPs given the increasing supervisory focus on digital operational resilience. AI-enabled cyber tools can accelerate vulnerability discovery and exploitation, target shared infrastructure and exploit single points of failure.</p>
<p>The ESAs recommend strengthening ICT risk management through three areas:</p>
<ul>
<li><strong>Prevention</strong> – comprehensive IT asset inventories, secure-by-design architecture, proactive patching and supply-chain controls.</li>
<li><strong>Detection</strong> – continuous vulnerability scanning, behavioural monitoring and more frequent testing.</li>
<li><strong>Management</strong> – resilience testing against AI-enhanced attack scenarios, dependency mapping and clear management-body accountability.</li>
</ul>
<h3>Why it matters</h3>
<p>For CASPs, AI-related cyber risks may directly affect <strong>private keys, custody infrastructure, smart contracts and critical third-party services</strong>.</p>
<h3>Recommended actions</h3>
<p>CASPs should:</p>
<ul>
<li>include AI/ML components in ICT asset inventories;</li>
<li>update vulnerability-management and monitoring processes;</li>
<li>test resilience against AI-enhanced attack scenarios;</li>
<li>map dependencies on critical ICT providers; and</li>
<li>ensure management bodies receive appropriate information on AI-related cyber risks.</li>
</ul>
<hr />
<h2 id="fatf-stablecoins-unhosted-wallets-offshore-vasps">FATF identifies growing risks around stablecoins, unhosted wallets and offshore VASPs</h2>
<p><strong>Date:</strong> 16 July 2026 | <strong>Source:</strong> FATF – Seventh Targeted Update on Virtual Assets and VASPs<br /><i class="fa fa-external-link"></i><a href="https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-updated-virtualassets-vasps-2026.html" target="_blank" rel="noopener"> Link</a></p>
<p>The FATF&#8217;s Seventh Targeted Update on Recommendation 15 reports continued global progress in implementing requirements for virtual assets and VASPs.</p>
<p>According to the report, 83% of surveyed jurisdictions have now passed Travel Rule legislation, compared with 73% in 2025.</p>
<p>However, significant gaps remain in supervision and enforcement.</p>
<p>For the crypto sector, FATF highlights several emerging risks, including:</p>
<ul>
<li>industrialised virtual-asset-enabled fraud;</li>
<li>misuse of stablecoins, which now feature in most identified on-chain illicit activity;</li>
<li>P2P transactions involving unhosted wallets;</li>
<li>offshore VASPs operating outside effective oversight; and</li>
<li>risks associated with DeFi.</li>
</ul>
<h3>Why it matters</h3>
<p>The report provides a useful benchmark for the risk-based AML/CTF and sanctions controls expected from CASPs.</p>
<h3>Recommended actions</h3>
<p>CASPs should:</p>
<ul>
<li>reassess stablecoin-related risks in their ML/TF risk assessments;</li>
<li>review exposure to unhosted-wallet and P2P transactions;</li>
<li>assess offshore VASP counterparties;</li>
<li>test the quality and completeness of Travel Rule information; and</li>
<li>update transaction-monitoring scenarios to reflect current crypto-specific typologies.</li>
</ul>
<hr />
<h2 id="fatf-functional-approach-defi-regulation">FATF calls for a functional approach to DeFi regulation</h2>
<p><strong>Date:</strong> 21 July 2026 | <strong>Source:</strong> FATF<br /><i class="fa fa-external-link"></i><a href="https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-decentralised-finance-2026.html" target="_blank" rel="noopener"> Link</a></p>
<p>FATF published its Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi), updating its earlier guidance.</p>
<p>The report promotes a functional, risk-based approach: regulators should look beyond the label &#8220;decentralised&#8221; and determine whether identifiable natural or legal persons exercise sufficient control or influence over a DeFi arrangement.</p>
<p>Relevant indicators include governance token concentration, administrative privileges, control over protocol upgrades, and significant economic benefits.</p>
<p>The FATF also highlights risks arising from interactions with DeFi protocols, including chain-hopping, cross-chain bridges, decentralised exchanges, mixers and governance manipulation.</p>
<h3>Why it matters</h3>
<p>Calling a protocol &#8220;decentralised&#8221; does not necessarily remove it from the regulatory perimeter. CASPs and financial institutions interacting with DeFi arrangements need to understand who actually controls or influences the protocol and what risks arise from the interaction.</p>
<h3>Recommended actions</h3>
<p>CASPs integrating DeFi protocols should:</p>
<ul>
<li>conduct and document a control analysis for each relevant protocol;</li>
<li>assess governance-token concentration and administrator privileges;</li>
<li>identify protocol-level and counterparty risks;</li>
<li>reflect DeFi exposure in the business-wide risk assessment; and</li>
<li>verify that appropriate due diligence and control measures can be applied before interacting with a protocol.</li>
</ul>
<hr />
<h2 id="eu-sanctions-crypto-specific-restrictions">EU sanctions package introduces new crypto-specific restrictions</h2>
<p><strong>Date:</strong> 23 July 2026 | <strong>Source:</strong> European Commission – 21st sanctions package against Russia<br /><i class="fa fa-external-link"></i><a href="https://finance.ec.europa.eu/news/eu-adopts-21th-package-sanctions-against-russia-2026-07-23_en" target="_blank" rel="noopener"> Link</a></p>
<p>The EU&#8217;s 21st package of sanctions against Russia introduces several measures directly relevant to the crypto-asset sector.</p>
<p>The package creates a new mechanism that allows third-country legal entities that provide crypto-asset services used to circumvent EU sanctions to be designated. Systematic failure to prevent sanctions circumvention may trigger designation.</p>
<p>The package also introduces transaction bans involving additional third-country crypto platforms and crypto-linked firms, with more than 20 crypto-asset service financial institutions added.</p>
<p>In addition, restrictions on the ownership, control or board membership of companies providing crypto-asset services by Russian and Belarusian nationals have been extended.</p>
<h3>Why it matters</h3>
<p>Crypto businesses need to consider sanctions risk not only when screening direct customers but also when assessing counterparty platforms, liquidity providers, ownership structures and management.</p>
<h3>Recommended actions</h3>
<p>CASPs should:</p>
<ul>
<li>rescreen counterparties and crypto platforms against updated sanctions lists;</li>
<li>review liquidity-provider relationships;</li>
<li>refresh ownership and management nationality checks;</li>
<li>assess third-country crypto counterparties for sanctions-evasion risk; and</li>
<li>update sanctions representations and contractual clauses where necessary.</li>
</ul>
<hr />
<h2 id="latvia-investment-firm-licence-c-capital-markets">Latvia issues investment firm licence following pre-licensing cooperation</h2>
<p><strong>Date:</strong> 23 July 2026 | <strong>Source:</strong> Latvijas Banka – C Capital Markets licence<br /><i class="fa fa-external-link"></i><a href="https://www.bank.lv/en/news-and-events/news-and-articles/news/17754-latvijas-banka-is-issuing-an-investment-firm-licence-to-sia-c-capital-markets" target="_blank" rel="noopener"> Link</a></p>
<p>Latvijas Banka issued an investment firm licence to SIA C Capital Markets, a subsidiary of AS Citadele banka, for the placing of financial instruments on a non-firm-commitment basis and related ancillary services.</p>
<p>The licence was issued less than one month after the official application was submitted, following pre-licensing cooperation with the regulator.</p>
<p>Latvia now has <strong>12 licensed investment firms</strong>.</p>
<h3>Why it matters for crypto businesses</h3>
<p>Although the licence concerns an investment firm rather than a CASP, the case provides a useful indication of the potential efficiency of well-prepared licensing processes in Latvia.</p>
<p>For businesses considering MiCA, investment firm or combined regulatory structures, early regulatory dialogue can help resolve issues before the formal application is submitted.</p>
<h3>Recommended actions</h3>
<p>Applicants considering Latvian authorisation should:</p>
<ul>
<li>use the pre-licensing consultation process;</li>
<li>establish the regulatory perimeter before filing;</li>
<li>prepare a complete and internally consistent application package; and</li>
<li>resolve governance, ownership, business-model and operational questions before formal submission.</li>
</ul>
<hr />
<h2 id="mica-transitional-period-ended">MiCA transitional period has ended: unlicensed CASPs must wind down</h2>
<p><strong>Date:</strong> 2 July 2026 | <strong>Source:</strong> Lietuvos bankas – End of MiCA transitional period<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/mica-reglamento-pereinamojo-laikotarpio-pabaiga-del-kriptoturto-paslaugu-teikeju-veiklos" target="_blank" rel="noopener"> Link</a></p>
<p>The EU-wide <strong>MiCA transitional period ended on 1 July 2026</strong>.</p>
<p>Unlicensed CASPs that are no longer entitled to rely on transitional arrangements must wind down their EU-facing activities in an orderly manner. During the wind-down process, firms must address client communications, positions and assets while maintaining applicable <strong>AML/CTF and Travel Rule controls</strong>.</p>
<p>Third-country CASPs cannot simply continue providing services to EU clients without an appropriate regulatory basis, and custody cannot be delegated to unlicensed providers.</p>
<p>Lietuvos bankas has also established a dedicated <strong>Investment and Crypto-Asset Firms Supervision Division</strong>, signalling a more specialised supervisory approach.</p>
<h3>Why it matters</h3>
<p>The end of the transitional period marks an important shift: operating in the EU crypto market now requires businesses to have a clear legal basis under MiCA or to cease the relevant activities.</p>
<h3>Recommended actions</h3>
<p>CASPs and crypto businesses should:</p>
<ul>
<li>confirm that all EU-facing crypto-asset services are provided through appropriately authorised entities;</li>
<li>review whether any activities remain dependent on transitional arrangements;</li>
<li>ensure orderly wind-down procedures are operational where authorisation has not been obtained;</li>
<li>maintain AML/CTF and sanctions controls throughout any wind-down; and</li>
<li>review outsourcing and custody arrangements to ensure that critical services are not being provided by unlicensed entities.</li>
</ul>
<hr />
<h2>What crypto businesses should focus on now</h2>
<p>The regulatory focus is shifting from &#8220;Are you licensed?&#8221; to &#8220;How are you operating?&#8221;</p>
<p>For CASPs and other businesses active in the crypto-asset market, the developments covered in this edition point to several immediate priorities:</p>
<ul>
<li><strong>MiCA:</strong> confirm that all EU-facing activities have the appropriate regulatory basis.</li>
<li><strong>Custody:</strong> prepare for supervisory scrutiny of key management, wallet segregation, incident response and third-party dependencies.</li>
<li><strong>AML/CTF:</strong> strengthen controls around stablecoins, unhosted wallets, offshore VASPs and DeFi.</li>
<li><strong>Sanctions:</strong> review crypto counterparties, ownership structures, liquidity providers and sanctions-evasion risks.</li>
<li><strong>DORA:</strong> test ICT resilience against increasingly sophisticated and AI-assisted attacks.</li>
<li><strong>Business models:</strong> reassess referral, advisory, lending and other activities against the latest ESMA interpretations.</li>
<li><strong>DeFi:</strong> do not rely on the &#8220;decentralised&#8221; label; assess actual control and influence over the protocol.</li>
<li><strong>Licensing strategy:</strong> where authorisation is still required, use regulatory pre-licensing dialogue to resolve the perimeter and prepare a coherent application.</li>
</ul>
<p>The direction of travel is clear: crypto regulation is becoming increasingly operational, risk-based and supervisory in practice.</p>
<hr />
<h2>Need assistance?</h2>
<p>Our legal and regulatory specialists assist crypto-asset businesses with:</p>
<ul>
<li>MiCA licensing and regulatory perimeter analysis</li>
<li>CASP authorisation and cross-border EU expansion</li>
<li>AML/CTF and Travel Rule compliance</li>
<li>Sanctions and crypto-asset sanctions screening</li>
<li>DORA and ICT risk management</li>
<li>Crypto custody and client-asset arrangements</li>
<li>DeFi regulatory analysis</li>
<li>Crypto lending and business-model structuring</li>
<li>Token issuance and white-paper requirements</li>
<li>Internal policies, procedures and compliance documentation</li>
</ul>
<p>If you have questions about the regulatory developments covered in this edition or would like to assess your crypto-asset business model against the current EU regulatory framework, our team will be happy to assist you.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-crypto-investments-regulation-august-2026/">RegRally Insights: Crypto &#038; Investments Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Payment Services Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-payment-services-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 10:56:43 +0000</pubDate>
				<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11569</guid>

					<description><![CDATA[<p>Payment services regulation is increasingly focused on whether regulated institutions can demonstrate effective controls, financial resilience and operational readiness in practice. Recent supervisory activity in Lithuania and Latvia, together with developments at the EU and UK levels, highlights several areas receiving particular attention: client funds safeguarding, regulatory remediation, wind-down planning, qualifying holdings, ICT resilience and the risks arising from increasingly complex technology dependencies. This month's RegRally highlights the developments most relevant to payment institutions (PIs), electronic money institutions (EMIs), fintech businesses and groups operating across the Baltic and wider European markets.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-payment-services-regulation-august-2026/">RegRally Insights: Payment Services Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Payment services regulation is increasingly focused on whether regulated institutions can demonstrate effective controls, financial resilience and operational readiness in practice.</p>
<p>Recent supervisory activity in Lithuania and Latvia, together with developments at the EU and UK levels, highlights several areas receiving particular attention: client funds safeguarding, regulatory remediation, wind-down planning, qualifying holdings, ICT resilience and the risks arising from increasingly complex technology dependencies.</p>
<p>This month&#8217;s RegRally highlights the developments most relevant to <a href="https://ecovis.lt/fintech/payment-institutions/" target="_blank" rel="noopener">payment institutions (PIs)</a>, electronic money institutions (EMIs), fintech businesses and groups operating across the Baltic and wider European markets.</p>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#lb-nayax-europe-safeguarding-measure">Lietuvos bankas imposes EUR 90,000 measure on Nayax Europe over client funds safeguarding</a></li>
<li><a href="#alphapay-licence-revoked">AlphaPay licence revoked following multiple regulatory breaches</a></li>
<li><a href="#lb-wind-down-plans-weaknesses">Lietuvos bankas finds significant weaknesses in EMI and PI wind-down plans</a></li>
<li><a href="#latvijas-banka-moin-emi-licence">Latvijas Banka grants new EMI licence as Latvian payments sector continues to grow</a></li>
<li><a href="#uk-regulators-critical-third-parties">UK regulators begin oversight of critical cloud and technology providers</a></li>
<li><a href="#eu-regulators-ict-risk-frontier-ai">EU regulators call for stronger ICT risk management against frontier AI threats</a></li>
</ul>
</div>
<h2 id="lb-nayax-europe-safeguarding-measure">Lietuvos bankas imposes EUR 90,000 measure on Nayax Europe over client funds safeguarding</h2>
<p><strong>Date:</strong> 24 July 2026 | <strong>Source:</strong> Lietuvos bankas – Financial Market Supervision Committee decisions<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/finansu-rinkos-prieziuros-komiteto-sprendimai-27" target="_blank" rel="noopener"> Link</a></p>
<p>Lietuvos bankas concluded an administrative settlement with the electronic money institution Nayax Europe UAB, imposing a EUR 90,000 measure for breaches related to client funds safeguarding and associated internal control requirements, identified during a targeted, scheduled inspection.</p>
<p>Nayax Europe had already begun remediation before submitting its settlement proposal and committed to providing an audit firm&#8217;s opinion confirming remediation by 30 April 2027.</p>
<p>In the same set of decisions, Lietuvos bankas reported that an inspection of <strong>Perlas Finance UAB</strong> identified only minor breaches, most of which were promptly remedied. No enforcement measure was imposed.</p>
<p>The decisions also included several qualifying holding assessments involving financial market participants.</p>
<h3>What this means for businesses</h3>
<p>The different outcomes demonstrate that supervisory authorities consider not only the existence of deficiencies but also the institution&#8217;s response, the speed of remediation, and the ability to demonstrate that corrective measures have been implemented.</p>
<p>For EMIs and PIs, client funds safeguarding remains a key supervisory priority. Safeguarding arrangements and the internal controls supporting them should therefore be tested for effective operation, rather than assessed only on the basis of policies and procedures.</p>
<h3>Recommended actions</h3>
<p>EMIs and PIs should:</p>
<ul>
<li>review client funds safeguarding arrangements and related internal controls;</li>
<li>test whether safeguarding controls operate effectively in practice;</li>
<li>ensure supervisory findings are assigned to responsible persons and remediated within defined deadlines;</li>
<li>maintain evidence of remediation and, where appropriate, obtain independent assurance;</li>
<li>review escalation procedures for material safeguarding deficiencies.</li>
</ul>
<p>For qualifying holding transactions, businesses should also ensure that acquisition documentation covers the complete direct and indirect ownership chain, including non-EU entities and entities undergoing corporate reorganisation.</p>
<hr />
<h2 id="alphapay-licence-revoked">AlphaPay licence revoked following multiple regulatory breaches</h2>
<p><strong>Date:</strong> 22 July 2026 | <strong>Source:</strong> Lietuvos bankas – Board resolutions<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/lietuvos-banko-valdybos-nutarimai-251" target="_blank" rel="noopener"> Link</a></p>
<p>Lietuvos bankas revoked the payment institution licence of <strong>AlphaPay, UAB (formerly NovaPay, UAB),</strong> following multiple breaches of regulatory requirements.</p>
<p>The institution no longer met licensing requirements concerning its internal control system and ICT infrastructure, failed to ensure adequate protection of payment service users&#8217; funds and no longer complied with its own funds requirements.</p>
<p>AlphaPay also failed to submit its audited 2025 annual financial statements, audit opinion and shareholder resolution on profit or loss allocation within the prescribed deadlines.</p>
<p>The licence had been suspended in April 2026, with access to client fund accounts restricted. According to Lietuvos bankas, AlphaPay subsequently failed to comply with remediation orders. The institution was found to be insolvent, with negative equity, and Lietuvos bankas announced that it would apply to the court for bankruptcy proceedings.</p>
<h3>What this means for businesses</h3>
<p>The case illustrates how supervisory intervention can escalate from <strong>remediation and suspension to licence revocation and insolvency</strong> where material deficiencies remain unresolved.</p>
<p>It also demonstrates that regulatory compliance extends beyond customer-facing requirements. Internal controls, ICT infrastructure, safeguarding, own funds and timely financial reporting are all integral to maintaining a payment institution licence.</p>
<h3>Recommended actions</h3>
<p>PIs and EMIs should:</p>
<ul>
<li>maintain a central register of supervisory findings and remediation obligations;</li>
<li>assign clear responsibility and deadlines for corrective actions;</li>
<li>provide timely evidence of remediation to the supervisory authority;</li>
<li>monitor own funds and solvency requirements continuously;</li>
<li>ensure audited financial statements and other regulatory reports are submitted on time;</li>
<li>regularly reassess whether internal control and ICT arrangements continue to satisfy licensing requirements.</li>
</ul>
<hr />
<h2 id="lb-wind-down-plans-weaknesses">Lietuvos bankas finds significant weaknesses in EMI and PI wind-down plans</h2>
<p><strong>Date:</strong> 17 July 2026 | <strong>Source:</strong> Lietuvos bankas – Financial Market Supervision Committee decisions<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/finansu-rinkos-prieziuros-komiteto-sprendimai-26" target="_blank" rel="noopener"> Link</a></p>
<p>Lietuvos bankas assessed the wind-down plans of <strong>12 electronic money and payment institutions</strong>, focusing on their content, practical applicability and legal compliance.</p>
<p>Four plans were assessed as comprehensive and implementable, while five were considered insufficiently detailed and three overly formal and theoretical. Each institution received an individual assessment and recommendations, with aggregated findings also published by Lietuvos bankas.</p>
<p>The same supervisory decisions included several qualifying holding assessments, including the proposed acquisition of a qualifying holding exceeding 50% in payment institution <strong>SOLLO, UAB</strong>.</p>
<h3>What this means for businesses</h3>
<p>The findings indicate that a wind-down plan is expected to be <strong>operationally usable</strong>, rather than simply a formal document prepared for licensing purposes.</p>
<p>A credible plan should explain how the institution would actually cease its activities, including how client funds would be returned, how outstanding transactions would be handled, which persons would be responsible and which operational and ICT dependencies would need to remain available during the wind-down.</p>
<h3>Recommended actions</h3>
<p>EMIs and PIs should:</p>
<ul>
<li>reassess existing wind-down plans against the latest supervisory findings;</li>
<li>ensure the plan reflects the institution&#8217;s actual business model and operational dependencies;</li>
<li>document the mechanics and timing of client fund returns;</li>
<li>identify responsible persons and decision-making arrangements;</li>
<li>address critical banking, outsourcing and ICT dependencies;</li>
<li>test the plan against realistic wind-down scenarios rather than relying solely on a theoretical document.</li>
</ul>
<p>The decisions also reinforce the need for complete qualifying holding notifications covering all relevant direct and indirect acquirers.</p>
<hr />
<h2 id="latvijas-banka-moin-emi-licence">Latvijas Banka grants new EMI licence as Latvian payments sector continues to grow</h2>
<p><strong>Date:</strong> 9 July 2026 | <strong>Source:</strong> Latvijas Banka – MOIN Payments licence announcement<br /><i class="fa fa-external-link"></i><a href="https://www.bank.lv/en/news-and-events/news-and-articles/news/17746-latvijas-banka-is-issuing-an-electronic-money-institution-operating-licence-to-sia-moin-payments" target="_blank" rel="noopener"> Link</a></p>
<p>Latvijas Banka granted an electronic money institution licence to <strong>SIA MOIN Payments</strong>, including authorisation to provide money remittance services.</p>
<p>At the time of the announcement, Latvia had 12 licensed and one registered electronic money institution and 10 licensed payment institutions. Latvijas Banka had already issued four EMI licences and five PI licences during 2026.</p>
<p>The Latvian regulator continues to promote pre-licensing consultations for businesses preparing to enter the market.</p>
<h3>What this means for businesses</h3>
<p>The continued licensing activity confirms that Latvia remains an active jurisdiction for payment and e-money businesses.</p>
<p>For prospective applicants, early regulatory engagement and the quality of the licensing package remain important. The business model, governance arrangements, safeguarding framework, AML/CTF controls, financial resources and ICT architecture should be presented as a coherent regulatory framework rather than as separate documentation streams.</p>
<h3>Recommended actions</h3>
<p>Businesses considering a Latvian PI or EMI licence should:</p>
<ul>
<li>use Latvijas Banka&#8217;s pre-licensing consultation process at an early stage;</li>
<li>clearly define the proposed business model and regulated services;</li>
<li>align governance, safeguarding, AML/CTF, risk management and ICT documentation with the actual business;</li>
<li>identify regulatory gaps before submitting the formal application;</li>
<li>ensure the licensing package demonstrates how the proposed controls will operate in practice.</li>
</ul>
<hr />
<h2 id="uk-regulators-critical-third-parties">UK regulators begin oversight of critical cloud and technology providers</h2>
<p><strong>Date:</strong> 10 July 2026 | <strong>Source:</strong> FCA<br /><i class="fa fa-external-link"></i><a href="https://www.fca.org.uk/news/statements/uk-financial-regulators-overseeing-critical-third-parties-announced-treasury" target="_blank" rel="noopener"> Link</a></p>
<p>UK financial regulators began overseeing the first Critical Third Parties (CTPs) from 13 July 2026, following HM Treasury&#8217;s designation of four global cloud and technology providers:</p>
<ul>
<li>Amazon Web Services EMEA SARL;</li>
<li>Google Cloud EMEA Limited;</li>
<li>Microsoft Ireland Operations Ltd;</li>
<li>Oracle Corporation UK Limited.</li>
</ul>
<p>The Bank of England, PRA and FCA will jointly oversee the resilience of critical services provided by these organisations to the UK financial sector, focusing on systemic risks, coordination and information sharing.</p>
<p>The regime complements, rather than replaces, existing outsourcing and operational resilience requirements. Regulated firms remain responsible for their own third-party risk management, due diligence and contingency planning.</p>
<p>The UK regulators have also established arrangements for cooperation with comparable regimes, including the EU&#8217;s DORA framework.</p>
<h3>What this means for businesses</h3>
<p>For financial institutions operating across the EU and UK, ICT third-party oversight is becoming increasingly <strong>cross-border and systemic</strong>.</p>
<p>The designation of a cloud provider as a critical third party does not transfer the regulated firm&#8217;s responsibility for managing outsourcing and ICT risks. PIs and EMIs must still understand their dependencies, assess concentration and exit risks, and maintain appropriate contingency arrangements under DORA.</p>
<h3>Recommended actions</h3>
<p>Financial groups with UK operations should:</p>
<ul>
<li>identify whether critical ICT providers are used across their UK and EU operations;</li>
<li>map material ICT dependencies and concentration risks;</li>
<li>maintain accurate outsourcing and ICT third-party registers;</li>
<li>assess contractual arrangements and contingency measures for critical providers;</li>
<li>distinguish provider-level regulatory oversight from the firm&#8217;s own DORA and operational resilience obligations.</li>
</ul>
<hr />
<h2 id="eu-regulators-ict-risk-frontier-ai">EU regulators call for stronger ICT risk management against frontier AI threats</h2>
<p><strong>Date:</strong> 31 July 2026 | <strong>Source:</strong> ESMA<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision" target="_blank" rel="noopener"> Link</a></p>
<p>The European Supervisory Authorities — EBA, EIOPA and ESMA — published a joint statement calling for a consistent, risk-based approach to ICT risks arising from frontier AI models.</p>
<p>The authorities highlighted the ability of AI-enabled cyber tools to rapidly identify and exploit vulnerabilities, target shared infrastructure and exploit single points of failure across financial entities.</p>
<p>The ESAs recommend strengthening ICT risk management across three areas:</p>
<ul>
<li><strong>Prevention:</strong> asset inventories, secure-by-design practices, proactive patching and supply-chain standards.</li>
<li><strong>Detection:</strong> continuous vulnerability scanning, behavioural monitoring and more frequent testing.</li>
<li><strong>Management:</strong> resilience testing against AI-enhanced scenarios, dependency mapping and management-body accountability.</li>
</ul>
<p>The authorities emphasise that measures should be proportionate to the institution&#8217;s size, risk profile and the nature, scale and complexity of its services, consistent with DORA&#8217;s proportionality principle.</p>
<h3>What this means for businesses</h3>
<p>AI-related cyber risk is increasingly becoming part of the core <strong>DORA ICT risk management framework</strong>.</p>
<p>For PIs and EMIs, periodic cybersecurity reviews may no longer be sufficient where vulnerabilities can be identified and exploited at significantly greater speed. ICT risk management should account for AI-assisted attacks that affect multiple systems, shared infrastructure, and critical third-party providers.</p>
<h3>Recommended actions</h3>
<p>PIs and EMIs should:</p>
<ul>
<li>review ICT risk assessments against AI-enhanced attack scenarios;</li>
<li>assess whether vulnerability scanning and patching cycles remain sufficiently frequent;</li>
<li>map critical ICT dependencies and potential single points of failure;</li>
<li>test business continuity and incident-response arrangements against AI-assisted attacks;</li>
<li>ensure management bodies receive timely information on material ICT risks;</li>
<li>consider AI-driven threats when reviewing risk appetite and DORA compliance frameworks.</li>
</ul>
<hr />
<h2>Key takeaways for payment institutions and EMIs</h2>
<p>The latest regulatory developments point to several priorities for the payments sector:</p>
<ul>
<li><strong>Safeguarding must be effective in practice.</strong><br />Client funds arrangements and the controls supporting them remain a significant supervisory focus.</li>
<li><strong>Remediation needs to be demonstrable.</strong><br />Institutions should be able to show that supervisory findings have been addressed promptly and effectively.</li>
<li><strong>Wind-down plans must be operationally credible.</strong><br />A plan should explain how the business could actually be wound down, including client fund returns, responsibilities and critical dependencies.</li>
<li><strong>Regulatory reporting is part of licensing compliance.</strong><br />Late or incomplete financial reporting can contribute to serious supervisory consequences.</li>
<li><strong>ICT third-party risk is becoming increasingly systemic.</strong><br />DORA compliance requires institutions to understand and manage their dependencies on critical technology providers.</li>
<li><strong>AI is changing the ICT threat environment.</strong><br />PIs and EMIs should consider whether their current vulnerability management, monitoring, resilience testing, and incident response arrangements are adequate for AI-enhanced attacks.</li>
<li><strong>The Baltic payments market remains active.</strong><br />Both Lithuania and Latvia continue to licence and supervise payment and e-money institutions, while cross-border acquisitions and changes of control remain subject to detailed regulatory scrutiny.</li>
</ul>
<hr />
<h2>Need assistance?</h2>
<p>Our payment services and fintech specialists advise PIs, EMIs and other regulated businesses on:</p>
<ul>
<li>PI and EMI licensing and regulatory authorisations</li>
<li>Payment services and e-money regulatory compliance</li>
<li>Client funds safeguarding</li>
<li>DORA and ICT risk management</li>
<li>AML/CTF and risk management frameworks</li>
<li>Wind-down and exit planning</li>
<li>Regulatory inspections and remediation</li>
<li>Qualifying holdings and changes of control</li>
<li>Regulatory reporting and supervisory communications</li>
<li>Baltic market entry and cross-border regulatory matters</li>
</ul>
<p>If you have questions regarding the developments covered in this edition or would like to assess your payment institution&#8217;s regulatory readiness, our team will be happy to assist.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-payment-services-regulation-august-2026/">RegRally Insights: Payment Services Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Consumer Protection Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-consumer-protection-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 09:59:02 +0000</pubDate>
				<category><![CDATA[Consumer protection]]></category>
		<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11564</guid>

					<description><![CDATA[<p>Consumer credit regulation is undergoing significant changes across the Baltic region. In Lithuania, the new consumer credit framework will introduce changes to creditworthiness assessments, responsible lending, advertising and reporting requirements from November 2026. In Latvia, a proposed reform would substantially change the supervision of financial consumer protection, transferring key functions from the Consumer Rights Protection Centre to Latvijas Banka.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-consumer-protection-regulation-august-2026/">RegRally Insights: Consumer Protection Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Consumer credit regulation is undergoing significant changes across the Baltic region. In Lithuania, the new consumer credit framework will introduce changes to creditworthiness assessments, responsible lending, advertising and reporting requirements from November 2026. In Latvia, a proposed reform would substantially change the supervision of financial consumer protection, transferring key functions from the Consumer Rights Protection Centre to Latvijas Banka.</p>
<p>This month&#8217;s RegRally highlights the developments most relevant to <a href="https://ecovis.lt/fintech/consumer-credit-provider/" target="_blank" rel="noopener">consumer credit providers</a>, credit intermediaries, <a href="https://ecovis.lt/fintech/peer-to-peer/" target="_blank" rel="noopener">P2P lending platforms</a> and other businesses providing financial services to consumers in Lithuania and Latvia.</p>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#lithuania-consumer-credit-rules-2026">Lithuania: new consumer credit rules to apply from November 2026</a></li>
<li><a href="#latvia-consumer-supervision-transfer">Latvia: consumer financial services supervision may move to Latvijas Banka from 2027</a></li>
</ul>
</div>
<h2 id="lithuania-consumer-credit-rules-2026">Lithuania: new consumer credit rules to apply from November 2026</h2>
<p><strong>Date:</strong> 16 July 2026 | <strong>Source:</strong> Lietuvos bankas<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/lietuvos-banko-valdyba-patvirtino-vartojimo-kredito-reguliavimo-pakeitimus" target="_blank" rel="noopener"> Link</a></p>
<p>Lietuvos bankas approved amendments to its resolutions regulating consumer credit. The amendments will enter into force on <strong>20 November 2026</strong> and implement the revised Lithuanian Consumer Credit Law adopted by the Seimas on 16 April 2026, which transposes Directive (EU) 2023/2225 on consumer credit agreements.</p>
<p>The amendments also introduce changes concerning the regulation of <strong>peer-to-peer lending platform operators</strong>.</p>
<p>One important change concerns interest-free and fee-free consumer credit. The EU Consumer Credit Directive removed the previous exemption for such products, which are used in practice, among other things, by telecommunications companies.</p>
<p>The revised creditworthiness assessment and responsible lending rules, therefore, introduce a specific exception to the general <strong>40% debt-service-to-income (DSTI) limit</strong>. Lenders may apply a DSTI ratio of up to <strong>60%</strong> where:</p>
<ul>
<li>the credit is provided under a linked interest-free and fee-free agreement; and</li>
<li>the credit finances the purchase of a phone, modem or router required for voice or internet access services.</li>
</ul>
<p>The amendments also introduce more detailed requirements for the statutory consumer credit advertising warning <strong>“Dėmesio! Skolintis pinigus kainuoja.”</strong> They further refine reporting requirements and the public lists of consumer credit lenders, P2P platform operators and consumer credit intermediaries.</p>
<h3>What this means for businesses</h3>
<p>The changes require affected businesses to review not only their legal documentation, but also how consumer credit products are structured, assessed and advertised in practice.</p>
<p>Businesses offering interest-free or fee-free financing linked to telecommunications products should specifically determine whether their products qualify for the new 60% DSTI exception and ensure that the qualifying conditions are consistently documented.</p>
<p>The revised advertising requirements also mean that existing marketing materials should not simply be carried forward after November 2026 without review.</p>
<h3>Recommended actions</h3>
<p>Consumer credit providers and relevant P2P operators should:</p>
<ul>
<li>prepare for the <strong>20 November 2026</strong> entry into force;</li>
<li>review creditworthiness assessment and responsible lending procedures against the revised rules;</li>
<li>identify products that may qualify for the 60% DSTI exception and document the eligibility criteria;</li>
<li>update consumer credit advertising templates and mandatory warning statements;</li>
<li>review agreements, customer journeys and internal procedures affected by the revised Consumer Credit Law;</li>
<li>verify reporting obligations and public-list registration requirements;</li>
<li>ensure compliance teams and relevant business functions are prepared for the new requirements before they take effect.</li>
</ul>
<hr />
<h2 id="latvia-consumer-supervision-transfer">Latvia: consumer financial services supervision may move to Latvijas Banka from 2027</h2>
<p><strong>Date:</strong> 23 July 2026 | <strong>Source:</strong> Saeima – Proposed transfer of financial consumer protection supervision to Latvijas Banka<br /><i class="fa fa-external-link"></i><a href="https://www.saeima.lv/lv/aktualitates/saeimas-zinas/36051-pateretaju-tiesibu-uzraudzibu-finansu-pakalpojumu-joma-planots-uzticet-latvijas-bankai" target="_blank" rel="noopener"> Link</a></p>
<p>The Saeima Budget and Finance (Tax) Committee conceptually supported amendments to the Consumer Rights Protection Law that would gradually transfer supervision of consumer rights in financial services to <strong>Latvijas Banka, starting in 2027</strong>.</p>
<p>The function is currently performed by the Consumer Rights Protection Centre (PTAC).</p>
<p>Under the proposed framework, Latvijas Banka would assume responsibility for:</p>
<ul>
<li>licensing and supervision of consumer lenders;</li>
<li>registration and supervision of credit intermediaries and their representatives;</li>
<li>supervision of financial services advertising and unfair commercial practices;</li>
<li>examination of consumer complaints and assistance with dispute resolution;</li>
<li>supervision of compliance with consumer financial services requirements.</li>
</ul>
<p>The proposed reform would also introduce an <strong>indefinite-term licensing model</strong>, with Latvijas Banka establishing requirements for issuing, suspending and cancelling licences.</p>
<p>A unified reporting system for suspected violations is also planned, with confidentiality protections for whistleblowers. Latvijas Banka would have powers to impose sanctions for significant breaches, including unlicensed lending and unregistered credit intermediation.</p>
<p>Most provisions are proposed to enter into force on <strong>1 January 2027</strong>, while certain rule-making powers would apply from 1 January 2028. Existing CRPC licences and registrations would remain valid during the transition.</p>
<p>The proposed amendments still need to pass the remaining stages of the legislative process.</p>
<h3>What this means for businesses</h3>
<p>The proposed reform would represent a significant change in the supervisory model for financial consumer protection in Latvia.</p>
<p>Consumer lenders and credit intermediaries should prepare for a more integrated financial-sector supervisory framework, in which licensing, advertising, unfair commercial practices, and consumer complaints would fall under the supervision of the country&#8217;s central bank.</p>
<p>The reform is not yet final, so businesses should distinguish between proposed requirements and rules already in force. Nevertheless, the direction of travel provides a useful indication of the supervisory environment businesses should prepare for.</p>
<h3>Recommended actions</h3>
<p>Latvian consumer lenders and credit intermediaries should:</p>
<ul>
<li>monitor the progress of the amendments through the remaining legislative stages;</li>
<li>assess how the proposed transfer of supervision could affect their licensing and registration arrangements;</li>
<li>prepare for the transition to Latvijas Banka supervision and the proposed indefinite-term licensing model;</li>
<li>review consumer credit advertising and commercial practices against the expected supervisory framework;</li>
<li>assess whether internal compliance and reporting arrangements are ready for interaction with the new supervisor;</li>
<li>plan for changes to supervisory fees and related regulatory costs.</li>
</ul>
<p>Businesses should also avoid treating the proposed framework as final until the legislative process is complete.</p>
<hr />
<h2>Key takeaways for consumer credit businesses</h2>
<p>The latest developments in Lithuania and Latvia point to several practical priorities:</p>
<ul>
<li><strong>Prepare early for the Lithuanian rules.</strong><br />The revised Lithuanian consumer credit framework takes effect on <strong>20 November 2026</strong>, leaving businesses a defined implementation deadline.</li>
<li><strong>Review products, not only policies.</strong><br />The new DSTI exception may affect how certain interest-free and fee-free financing products are structured and assessed.</li>
<li><strong>Treat advertising as a compliance issue.</strong><br />Consumer credit marketing materials and mandatory warning statements will be subject to review under the revised Lithuanian rules.</li>
<li><strong>Expect closer integration of financial consumer supervision in Latvia.</strong><br />The proposed transfer of supervisory functions to Latvijas Banka could bring consumer credit regulation closer to the broader prudential and conduct supervision framework applicable to financial institutions.</li>
<li><strong>Separate enacted requirements from proposed reforms.</strong><br />The Lithuanian changes have a confirmed entry-into-force date, while the Latvian reform remains subject to the legislative process.</li>
</ul>
<hr />
<h2>Need assistance?</h2>
<p>Our financial services and regulatory specialists advise consumer credit providers, P2P lending platforms and credit intermediaries on:</p>
<ul>
<li>Consumer credit regulatory compliance</li>
<li>Creditworthiness assessment and responsible lending</li>
<li>Consumer credit agreements and documentation</li>
<li>Consumer credit advertising and marketing compliance</li>
<li>P2P lending regulation</li>
<li>Licensing and regulatory authorisations</li>
<li>Regulatory reporting and supervisory requirements</li>
<li>Consumer protection and unfair commercial practices</li>
<li>Regulatory inspections and remediation</li>
<li>Lithuanian and Latvian financial services regulation</li>
</ul>
<p>If you have questions regarding the regulatory developments covered in this edition or would like to assess your consumer credit compliance ahead of the upcoming changes, our team will be happy to assist.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-consumer-protection-regulation-august-2026/">RegRally Insights: Consumer Protection Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Sanctions Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-sanctions-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 09:10:05 +0000</pubDate>
				<category><![CDATA[RegRally]]></category>
		<category><![CDATA[Sanctions]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11556</guid>

					<description><![CDATA[<p>EU sanctions compliance continues to expand beyond traditional sanctions screening. Recent measures increasingly address indirect exposure, third-country circumvention, shipping and energy infrastructure, financial services and crypto-assets.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-sanctions-regulation-august-2026/">RegRally Insights: Sanctions Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>EU sanctions <a href="https://ecovis.lt/fintech/compliance-services-regulatory-compliance-aml/" target="_blank" rel="noopener">compliance</a> continues to expand beyond traditional sanctions screening. Recent measures increasingly address indirect exposure, third-country circumvention, shipping and energy infrastructure, financial services and crypto-assets.</p>
<p>The latest FATF findings also highlight how virtual assets and decentralised finance are being used to move and obscure illicit funds, including in connection with sanctions evasion and the financing of the proliferation of weapons of mass destruction.</p>
<p>This month&#8217;s RegRally focuses on the developments most relevant to businesses exposed to Russia or Belarus, international trade, shipping, financial services, crypto-assets and higher-risk cross-border transactions.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Russia:</strong> The EU adopted its 21st sanctions package, introducing new restrictions targeting the energy sector, financial services, crypto operators, the Russian shadow fleet and sanctions circumvention. The package includes 218 new listings.</li>
<li><strong>Belarus:</strong> New measures extend restrictions affecting crypto-asset services, ownership and governance, exports and entities supporting the Belarusian or Russian defence and security sectors.</li>
<li><strong>Crypto and sanctions evasion:</strong> FATF identifies stablecoins, offshore VASPs, unhosted wallets and complex DeFi transaction structures as increasingly relevant channels for sanctions evasion and proliferation financing.</li>
<li><strong>Compliance focus:</strong> Effective sanctions compliance increasingly requires businesses to assess ownership, control, transaction flows, counterparties, geography and potential circumvention — not simply perform name screening.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#eu-21st-sanctions-package-russia">EU adopts 21st sanctions package against Russia, expanding restrictions on energy, finance, crypto and the shadow fleet</a></li>
<li><a href="#eu-belarus-sanctions-expansion">EU expands Belarus sanctions, including restrictions affecting crypto-asset services and exports</a></li>
<li><a href="#fatf-virtual-assets-sanctions-evasion">FATF highlights virtual assets as an increasing channel for sanctions evasion and proliferation financing</a></li>
</ul>
</div>
<h2 id="eu-21st-sanctions-package-russia">EU adopts 21st sanctions package against Russia, expanding restrictions on energy, finance, crypto and the shadow fleet</h2>
<p><strong>Date:</strong> 23 July 2026 | <strong>Source:</strong> European Commission / Council of the EU<br /><i class="fa fa-external-link"></i><a href="https://finance.ec.europa.eu/news/eu-adopts-21th-package-sanctions-against-russia-2026-07-23_en" target="_blank" rel="noopener"> Link</a></p>
<p>The EU adopted its 21st package of sanctions against Russia, targeting the energy sector, financial services, crypto-assets, trade and Russia&#8217;s military-industrial complex.</p>
<p>The package introduces <strong>218 new listings — 48 individuals and 170 entities — subject to asset freezes and, for individuals, travel restrictions. It also includes 51 additional anti-circumvention listings, including entities in third countries.</strong></p>
<p>Key energy and shipping measures include:</p>
<ul>
<li>suspension of the oil price cap adjustment mechanism until July 2027, maintaining the cap at <strong>USD 44.10 per barrel</strong>;</li>
<li>designation of <strong>41 additional shadow fleet vessels</strong>;</li>
<li>designation, for the first time, of vessels servicing designated shadow fleet vessels;</li>
<li>transaction bans covering designated Russian ports, locks and airports;</li>
<li>restrictions concerning a third-country refinery processing Russian oil;</li>
<li>a notification obligation concerning the sale of LNG tankers to third countries.</li>
</ul>
<p>The package also targets more than 100 banks and crypto operators and introduces further measures affecting Russia&#8217;s financial infrastructure.</p>
<p>In addition, the EU introduced legal protection measures intended to protect EU operators from certain retaliatory lawsuits connected with sanctions and requires Member States not to recognise or enforce certain Russian judgments linked to sanctions.</p>
<h3>Why does it matter for businesses?</h3>
<p>The new package significantly increases the number of entities, vessels and infrastructure points that businesses need to consider when assessing sanctions exposure.</p>
<p>Importantly, the package also targets <strong>third-country entities involved in circumvention</strong>. A counterparty, therefore, does not need to be Russian or directly listed to create sanctions risk.</p>
<p>For businesses involved in international trade, shipping, financial services or crypto-assets, sanctions controls increasingly need to extend beyond customer screening to transaction-level analysis and assessment of ownership, control and intermediary relationships.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>update sanctions screening lists without delay and <strong>rescreen existing customers, counterparties and relevant third parties</strong>;</li>
<li>review exposure to newly designated banks, crypto operators, vessels, ports, refineries and other infrastructure;</li>
<li>assess third-country counterparties and intermediaries for potential Russia-related circumvention risks;</li>
<li>review payment and trade-finance flows involving higher-risk jurisdictions and counterparties;</li>
<li>strengthen due diligence on shipping transactions involving shadow fleet vessels;</li>
<li>review contractual arrangements with third-country counterparties in light of the new legal protection measures.</li>
</ul>
<p>Businesses with material Russia-related exposure should combine automated screening with <strong>ownership/control analysis and transaction-level due diligence</strong>.</p>
<hr />
<h2 id="eu-belarus-sanctions-expansion">EU expands Belarus sanctions, including restrictions affecting crypto-asset services and exports</h2>
<p><strong>Date:</strong> 23 July 2026 | <strong>Source:</strong> European Commission / Council of the EU<br /><i class="fa fa-external-link"></i><a href="https://finance.ec.europa.eu/news/eu-adopts-21th-package-sanctions-against-russia-2026-07-23_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>Alongside the Russia measures, the EU adopted additional restrictive measures concerning Belarus, including trade-related provisions and measures intended to protect EU operators.</p>
<p>The package extends restrictions on crypto-asset service companies, including a prohibition on Belarusian nationals owning, controlling, or serving on the boards of companies providing crypto-asset services.</p>
<p>It also expands export restrictions on certain goods, including aviation-related products intended for UAVs, and designates four additional Belarusian entities that support the Belarusian or Russian defence and security sectors.</p>
<h3>Why does it matter for businesses?</h3>
<p>The measures create compliance implications beyond direct dealings with sanctioned Belarusian entities.</p>
<p>For crypto-asset service providers, sanctions compliance now requires closer attention to nationality, ownership and governance structures. For exporters, the expanded restrictions require businesses to consider not only the classification of goods but also their intended end use and end user.</p>
<p>The measures also reinforce the importance of checking ownership and control rather than relying exclusively on sanctions-list screening.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>review ownership and governance structures of Belarus-related counterparties;</li>
<li>for crypto-asset service providers, verify whether Belarusian nationals hold relevant ownership, control or board positions;</li>
<li>update export-control screening for newly restricted aviation and UAV-related goods;</li>
<li>strengthen end-use and end-user checks for relevant exports;</li>
<li>rescreen counterparties against the newly designated Belarusian entities;</li>
<li>assess transactions involving Belarus for potential indirect exposure or sanctions circumvention.</li>
</ul>
<hr />
<h2 id="fatf-virtual-assets-sanctions-evasion">FATF highlights virtual assets as an increasing channel for sanctions evasion and proliferation financing</h2>
<p><strong>Date:</strong> 16 July 2026 | <strong>Source:</strong> Financial Action Task Force (FATF)<br /><i class="fa fa-external-link"></i><a href="https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-updated-virtualassets-vasps-2026.html" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>FATF&#8217;s Seventh Targeted Update on implementation of Recommendation 15 highlights the increasing complexity of illicit finance involving virtual assets. The report identifies sanctions evasion and proliferation-financing risks associated with <strong>stablecoins, offshore VASPs, unhosted wallets, and</strong> more complex DeFi transaction structures.</p>
<p>FATF highlights techniques such as chain-hopping, cross-chain bridges, decentralised exchanges, mixers and governance manipulation, which can be used to layer or obscure illicit funds within legitimate financial flows.</p>
<p>The report also highlights significant DPRK-linked activity. According to FATF, two major DeFi attacks attributed to the DPRK in April 2026 accounted for approximately 76% of annual virtual-asset hacking losses identified in the report, with combined proceeds exceeding USD 570 million.</p>
<h3>Why does it matter for businesses?</h3>
<p>For businesses dealing with crypto-assets, sanctions risk can arise even when a transaction does not directly match a sanctions list.</p>
<p>The risk may instead stem from the transaction path, an intermediary VASP, wallet exposure, rapid cross-chain movement<strong>, interaction with mixers or decentralised exchanges, or links to sanctioned jurisdictions or actors</strong>.</p>
<p>This means that sanctions compliance for CASPs and financial institutions increasingly needs to combine traditional screening with blockchain analytics and transaction-level risk assessment.</p>
<h3>Recommended actions</h3>
<p>CASPs and financial institutions exposed to virtual assets should:</p>
<ul>
<li>incorporate stablecoin-related sanctions-evasion typologies into transaction-monitoring scenarios;</li>
<li>assess exposure to offshore VASPs and higher-risk P2P transactions;</li>
<li>apply risk-based controls to transactions involving unhosted wallets;</li>
<li>monitor for chain-hopping, cross-chain bridges, mixers and decentralised exchanges;</li>
<li>ensure sanctions-risk indicators identified through blockchain analytics trigger appropriate escalation and investigation;</li>
<li>assess whether existing blockchain analytics tools can identify <strong>indirect exposure</strong>, rather than only direct wallet matches.</li>
</ul>
<p>Sanctions-evasion indicators should also feed into the wider customer and transaction risk assessment.</p>
<hr />
<h2>What businesses should take from this month&#8217;s developments</h2>
<p>The latest developments reinforce a fundamental shift in sanctions compliance:</p>
<p><strong>Screening names are necessary, but they are no longer sufficient.</strong></p>
<p>The EU&#8217;s 21st Russia sanctions package demonstrates the increasing importance of <strong>ownership, control, shipping, financial flows, third-country intermediaries and anti-circumvention analysis</strong>. Belarusian measures similarly show that nationality and governance can become relevant factors in sanctions control.</p>
<p>FATF&#8217;s latest findings add another dimension for businesses dealing with virtual assets: sanctions evasion can occur through complex transaction structures that may not yield a straightforward sanctions-list match.</p>
<p>Businesses with international operations should therefore consider whether their sanctions framework can identify:</p>
<ul>
<li>indirect exposure to sanctioned persons and entities;</li>
<li>ownership and control risks;</li>
<li>higher-risk third-country intermediaries;</li>
<li>shadow fleet and shipping exposure;</li>
<li>sanctions-evasion patterns in payment and trade flows;</li>
<li>crypto-asset transactions involving higher-risk wallets, VASPs or jurisdictions.</li>
</ul>
<p>The practical test is whether the organisation can <strong>identify and investigate a potentially evasive transaction before it becomes a sanctions breach</strong>, rather than simply demonstrate that its screening system is operating.</p>
<hr />
<h2>Need assistance?</h2>
<p>ECOVIS ProventusLaw advises businesses on EU sanctions and restrictive measures, including:</p>
<ul>
<li>sanctions compliance frameworks and risk assessments;</li>
<li>sanctions screening and internal controls;</li>
<li>ownership and control analysis;</li>
<li>Russia and Belarus sanctions;</li>
<li>sanctions circumvention and third-country exposure;</li>
<li>crypto-asset sanctions compliance and blockchain-related risks;</li>
<li>trade and export-control restrictions;</li>
<li>sanctions investigations and regulatory response;</li>
<li>sanctions policies, procedures and employee training.</li>
</ul>
<p>If your business has exposure to Russia, Belarus, international trade, shipping, financial services or crypto-assets, our team can help assess whether your sanctions controls address both direct restrictions and circumvention risks.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-sanctions-regulation-august-2026/">RegRally Insights: Sanctions Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: AML/CTF Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-aml-ctf-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 08:47:42 +0000</pubDate>
				<category><![CDATA[AML & CTF]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11549</guid>

					<description><![CDATA[<p>AML/CTF supervision is becoming increasingly operational and data-driven. Recent developments show regulators focusing not only on whether businesses have AML policies in place, but on whether those frameworks work in practice: whether customer risk is properly assessed, suspicious activity is identified and reported, transaction monitoring is effective, and new business models such as DeFi are subject to appropriate controls.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-aml-ctf-regulation-august-2026/">RegRally Insights: AML/CTF Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>AML/CTF supervision is becoming increasingly operational and data-driven. Recent developments show regulators focusing not only on whether businesses have <a href="https://ecovis.lt/aml/" target="_blank" rel="noopener">AML</a> policies in place, but on whether those frameworks work in practice: whether customer risk is properly assessed, suspicious activity is identified and reported, transaction monitoring is effective, and new business models such as DeFi are subject to appropriate controls.</p>
<p>This month&#8217;s RegRally highlights the developments most relevant to financial institutions, CASPs, fintechs and other obliged entities operating in Lithuania and across the EU.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Virtual assets:</strong> FATF identifies continuing gaps in Travel Rule implementation, VASP supervision and risk mitigation, while highlighting stablecoins, unhosted wallets and offshore VASPs as growing risk areas.</li>
<li><strong>DeFi:</strong> FATF takes a functional approach to determining when supposedly decentralised arrangements fall within AML/CFT requirements.</li>
<li><strong>EU reporting:</strong> AMLA is developing a harmonised EU format for suspicious transaction reporting and transaction data, potentially replacing fragmented national reporting approaches.</li>
<li><strong>Ongoing monitoring:</strong> AMLA is preparing horizontal guidance on customer information updates and ongoing monitoring applicable across obliged entities.</li>
<li><strong>Lithuania:</strong> FNTT&#8217;s 2025 inspections show that deficiencies in CDD, record keeping, internal controls, employee training and suspicious transaction reporting remain key enforcement risks.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#fatf-vasp-supervision-gaps">FATF identifies continuing gaps in VASP supervision and highlights emerging virtual asset risks</a></li>
<li><a href="#fatf-defi-money-laundering-risks">FATF warns that DeFi is increasingly exposed to money laundering and other financial crime risks</a></li>
<li><a href="#amla-harmonised-str-reporting-format">AMLA moves towards a harmonised EU format for suspicious transaction reporting</a></li>
<li><a href="#amla-ongoing-monitoring-guidance">AMLA develops EU-wide guidance on ongoing monitoring of business relationships</a></li>
<li><a href="#fntt-lithuania-aml-enforcement-data">FNTT enforcement data shows where Lithuanian AML controls continue to fail</a></li>
</ul>
</div>
<h2 id="fatf-vasp-supervision-gaps">FATF identifies continuing gaps in VASP supervision and highlights emerging virtual asset risks</h2>
<p><strong>Date:</strong> 16 July 2026 | <strong>Source:</strong> Financial Action Task Force (FATF)<br /><i class="fa fa-external-link"></i><a href="https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-updated-virtualassets-vasps-2026.html" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>FATF published its seventh targeted update on the implementation of Recommendation 15 concerning virtual assets and virtual asset service providers (VASPs).</p>
<p>The report identifies continued global progress in implementing the Travel Rule: 83% of surveyed jurisdictions have now passed Travel Rule legislation, compared with 73% in 2025.</p>
<p>At the same time, significant implementation gaps remain. These include translating risk assessments into effective mitigation measures, operationalising licensing and registration frameworks, identifying persons conducting VASP activities, and ensuring effective risk-based supervision and enforcement.</p>
<p>FATF also highlights emerging risks involving the use of virtual assets for organised fraud and money laundering, with particular attention to stablecoins, peer-to-peer transactions involving unhosted wallets and offshore VASPs.</p>
<h3>Why does it matter for businesses?</h3>
<p>The report reinforces that virtual asset businesses are moving into a more mature supervisory environment. Having a Travel Rule solution or VASP licence is not, by itself, sufficient: supervisors are increasingly likely to assess whether the underlying risk assessment and controls actually address the relevant typologies.</p>
<p>For CASPs, exposure to stablecoins, unhosted wallets, P2P transfers and offshore counterparties should therefore be reflected in the business-wide ML/TF risk assessment and corresponding controls.</p>
<h3>Recommended actions</h3>
<p>CASPs should:</p>
<ul>
<li>benchmark Travel Rule implementation against the FATF&#8217;s identified implementation gaps;</li>
<li>review whether stablecoin, unhosted-wallet and offshore-VASP risks are adequately reflected in the ML/TF risk assessment;</li>
<li>test whether enhanced due diligence and transaction-monitoring controls respond to the relevant virtual asset typologies;</li>
<li>assess whether existing controls remain appropriate as the business expands into new virtual asset products or transaction models.</li>
</ul>
<hr />
<h2 id="fatf-defi-money-laundering-risks">FATF warns that DeFi is increasingly exposed to money laundering and other financial crime risks</h2>
<p><strong>Date:</strong> 21 July 2026 | <strong>Source:</strong> Financial Action Task Force (FATF)<br /><i class="fa fa-external-link"></i><a href="https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-decentralised-finance-2026.html" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>FATF published a targeted report on regulatory challenges arising from decentralised finance (DeFi).</p>
<p>The report identifies permissionless access, automated smart-contract execution, cross-border reach and pseudonymity as factors that can increase exposure to fraud, ransomware, professional money laundering and proliferation financing.</p>
<p>Implementation of the FATF Standards for qualifying DeFi arrangements remains limited: almost 93% of reporting jurisdictions have not yet implemented the Standards in this area.</p>
<p>Importantly, FATF takes a functional approach to determining whether a DeFi arrangement falls within Recommendation 15. A business or person may be subject to AML/CFT requirements where it exercises sufficient control or influence, even where the arrangement is presented as decentralised.</p>
<p>FATF identifies indicators of potential control both on-chain and off-chain, including governance token concentration, administrative privileges, control over upgrades, economic benefits and influence over development or infrastructure.</p>
<h3>Why does it matter for businesses?</h3>
<p>The report challenges the assumption that describing a product or protocol as “decentralised” automatically places it outside the AML/CFT framework.</p>
<p>This is particularly relevant to CASPs, financial institutions and technology businesses interacting with DeFi protocols. The regulatory analysis may need to focus on <strong>who actually controls or influences the arrangement</strong>, rather than how the protocol is marketed or structured.</p>
<p>FATF also states that financial institutions and VASPs should apply relevant AML/CFT controls when interacting with qualifying DeFi arrangements and refrain from interacting where compliance cannot be achieved.</p>
<h3>Recommended actions</h3>
<p>Businesses interacting with DeFi should:</p>
<ul>
<li>document an assessment of the actual control and influence exercised over each relevant arrangement;</li>
<li>consider FATF&#8217;s on-chain and off-chain indicators when determining whether a DeFi arrangement falls within Recommendation 15;</li>
<li>assess the adequacy of CDD, transaction monitoring and other AML/CFT controls applicable to the relationship;</li>
<li>identify exposure to chain-hopping, cross-chain bridges, decentralised exchanges and mixers;</li>
<li>avoid entering into or maintaining relationships where required AML/CFT controls cannot be effectively implemented.</li>
</ul>
<p>For CASPs and financial institutions, DeFi exposure should also be reflected in the business-wide ML/TF risk assessment.</p>
<hr />
<h2 id="amla-harmonised-str-reporting-format">AMLA moves towards a harmonised EU format for suspicious transaction reporting</h2>
<p><strong>Date:</strong> 2 July 2026 | <strong>Source:</strong> Anti-Money Laundering Authority (AMLA)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/press-release-amla-launches-public-consultation-common-format-reporting-suspicions_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>AMLA launched a public consultation on draft implementing technical standards establishing a common EU format for reporting suspicions and providing transaction records to Financial Intelligence Units (FIUs).</p>
<p>The proposed framework would introduce a harmonised set of data points for suspicious transaction reporting across the EU, replacing the fragmented national reporting formats currently used by obliged entities.</p>
<p>A public hearing is scheduled for 9 September 2026, while written consultation responses remain possible.</p>
<h3>Why does it matter for businesses?</h3>
<p>A common EU reporting format could materially change how compliance teams prepare and submit suspicious transaction reports, particularly for businesses operating across several EU jurisdictions.</p>
<p>For Lithuanian and Latvian businesses, the change may require adjustments to existing reporting processes and the data collected for national FIU reporting.</p>
<p>The impact will be particularly relevant to fintechs, financial institutions and other businesses operating cross-border, where differences between national reporting requirements currently create operational complexity.</p>
<h3>Recommended actions</h3>
<p>Compliance teams should:</p>
<ul>
<li>compare existing STR reporting processes with the proposed EU data points;</li>
<li>identify information currently collected in national systems that may not map easily to the proposed format;</li>
<li>assess whether existing transaction-monitoring and case-management systems can produce the required information;</li>
<li>consider submitting consultation feedback where the proposed requirements create significant operational or proportionality concerns.</li>
</ul>
<p>Businesses operating across multiple EU jurisdictions should begin considering the implications for their reporting architecture rather than waiting until implementation.</p>
<hr />
<h2 id="amla-ongoing-monitoring-guidance">AMLA develops EU-wide guidance on ongoing monitoring of business relationships</h2>
<p><strong>Date:</strong> 2 July 2026 | <strong>Source:</strong> Anti-Money Laundering Authority (AMLA)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/press-release-amla-concludes-public-hearing-draft-guidelines-ongoing-monitoring-business_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>AMLA held a public hearing on its draft guidelines for the ongoing monitoring of business relationships, attracting more than 1,200 stakeholders from the financial and non-financial sectors.</p>
<p>The draft guidance addresses customer information updates and the monitoring of transactions and activities. As horizontal guidance, it is intended to apply across obliged entities, with proportionality and the risk-based approach embedded throughout.</p>
<p>The written consultation remains open until 3 September 2026.</p>
<h3>Why does it matter for businesses?</h3>
<p>Ongoing monitoring is one area where AML frameworks often become operationally inconsistent: customer information may be updated at fixed time intervals without sufficient regard to changes in customer risk, while transaction monitoring may operate separately from KYC refresh processes.</p>
<p>The forthcoming AMLA guidance may therefore influence how businesses structure customer reviews, trigger events, conduct transaction monitoring, and perform periodic KYC refreshes.</p>
<h3>Recommended actions</h3>
<p>Obliged entities should:</p>
<ul>
<li>review current KYC refresh procedures against the draft AMLA approach;</li>
<li>assess whether customer reviews are sufficiently risk-based rather than driven solely by fixed review cycles;</li>
<li>identify trigger events that should result in an earlier review of customer information;</li>
<li>assess whether transaction monitoring outcomes feed effectively into customer-risk reassessment;</li>
<li>Consider submitting consultation responses by 3 September 2026, where the proposed approach creates significant operational challenges.</li>
</ul>
<p>Fintechs and other business models with large or rapidly changing customer populations should pay particular attention to the proportionality of ongoing monitoring requirements.</p>
<hr />
<h2 id="fntt-lithuania-aml-enforcement-data">FNTT enforcement data shows where Lithuanian AML controls continue to fail</h2>
<p><strong>Date:</strong> 16 July 2026 | <strong>Source:</strong> Financial Crime Investigation Service (FNTT)</p>
<p>FNTT published the 2025 activity report of its Money Laundering Prevention Board.</p>
<p>During 2025, FNTT conducted 20 inspections of obliged entities and imposed measures on 11 companies. Fines ranged from €2,435 to €771,400, with total fines reaching approximately €1.46 million.</p>
<p>The most common deficiencies concerned:</p>
<ul>
<li>customer identification and verification;</li>
<li>record keeping;</li>
<li>internal policies and control procedures;</li>
<li>appointment and training of responsible employees;</li>
<li>reporting requirements for transactions of €15,000 or more;</li>
<li>suspicious transaction reporting;</li>
<li>examination of complex, unusually large or unusually structured transactions.</li>
</ul>
<h3>Why does it matter for businesses?</h3>
<p>This is one of the most useful indicators of current AML enforcement priorities in Lithuania because it shows the areas where deficiencies are actually identified during inspections.</p>
<p>The findings also demonstrate that enforcement risk does not necessarily arise from sophisticated money laundering schemes. Basic weaknesses in CDD, documentation, governance, training and escalation processes remain significant.</p>
<p>For obliged entities, the practical question is whether the AML framework would withstand an inspection today — not whether the required policies formally exist.</p>
<h3>Recommended actions</h3>
<p>Lithuanian obliged entities should test their AML framework against the FNTT&#8217;s identified enforcement areas, including:</p>
<ul>
<li>customer identification and verification;</li>
<li>customer and business relationship risk assessment;</li>
<li>record keeping and audit trails;</li>
<li>internal AML policies and controls;</li>
<li>appointment, competence and training of responsible employees;</li>
<li>suspicious transaction identification and escalation;</li>
<li>reporting of transactions subject to mandatory reporting requirements;</li>
<li>assessment of complex, unusually large or unusually structured transactions.</li>
</ul>
<p>Businesses should ensure that evidence of these controls is readily available and inspection-ready, rather than relying solely on written policies.</p>
<hr />
<h2>What businesses should take from this month&#8217;s developments</h2>
<p>The direction of AML/CTF supervision is becoming clear: regulators are moving from formal requirements towards demonstrable effectiveness.</p>
<p>For virtual asset businesses, this means demonstrating that emerging risks — including stablecoins, unhosted wallets, and DeFi — are reflected in the risk assessment and control framework.</p>
<p>For traditional financial institutions and other obliged entities, the same principle applies to CDD, transaction monitoring, suspicious transaction reporting, ongoing KYC and internal governance.</p>
<p>The FNTT&#8217;s Lithuanian enforcement data is particularly clear: weaknesses in fundamental AML controls can still lead to significant financial penalties.</p>
<p>Businesses should therefore assess not only whether their AML framework is documented, but whether it would withstand a regulatory inspection, a complex customer-risk scenario or a suspicious transaction requiring rapid escalation and reporting.</p>
<hr />
<h2>Need assistance?</h2>
<p>ECOVIS ProventusLaw advises financial institutions, fintechs, CASPs and other obliged entities on AML/CTF compliance, including:</p>
<ul>
<li>AML/CTF regulatory assessments and gap analysis;</li>
<li>business-wide ML/TF risk assessments;</li>
<li>AML policies, internal controls and procedures;</li>
<li>customer due diligence and enhanced due diligence frameworks;</li>
<li>transaction monitoring and suspicious transaction reporting;</li>
<li>AML governance, MLRO responsibilities and employee training;</li>
<li>CASP and virtual asset AML/CTF requirements;</li>
<li>regulatory inspections and remediation of identified deficiencies.</li>
</ul>
<p>If your organisation is preparing for increased AMLA or national supervisory scrutiny, our team can help assess whether your AML framework is not only documented but operationally effective and ready for regulatory review.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-aml-ctf-regulation-august-2026/">RegRally Insights: AML/CTF Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: GDPR and ICT Regulation, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-personal-data-protection-and-ict-regulation-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 08:01:43 +0000</pubDate>
				<category><![CDATA[Data protection & ICT]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11542</guid>

					<description><![CDATA[<p>Data protection and cybersecurity enforcement are increasingly moving from formal compliance to demonstrable effectiveness. Recent developments show regulators testing whether organisations can actually control data, respond to incidents, govern AI use and prevent unlawful tracking in practice.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-personal-data-protection-and-ict-regulation-august-2026/">RegRally Insights: GDPR and ICT Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><a href="https://ecovis.lt/data-protection/" target="_blank" rel="noopener">Data protection</a> and cybersecurity enforcement are increasingly moving from formal compliance to demonstrable effectiveness. Recent developments show regulators testing whether organisations can actually control data, respond to incidents, govern AI use and prevent unlawful tracking in practice.</p>
<p>This month&#8217;s RegRally focuses on developments particularly relevant to organisations that use AI, digital advertising, cloud and online services, blockchain, or process personal data at scale.</p>
<p><strong>This month at a glance:</strong></p>
<ul>
<li><strong>AI:</strong> Certain high-risk AI compliance deadlines have been deferred, but AI transparency obligations remain applicable.</li>
<li><strong>AI and GDPR:</strong> The EDPB has issued guidance on anonymisation and web scraping for generative AI.</li>
<li><strong>Blockchain:</strong> The EDPB&#8217;s final guidance highlights the need to address GDPR requirements at the architecture stage.</li>
<li><strong>Cookies and tracking:</strong> European and Lithuanian regulators continue to scrutinise consent mechanisms and actual website behaviour.</li>
<li><strong>Data breaches:</strong> New EU-level reporting proposals and Lithuanian enforcement statistics underline the importance of effective incident-response processes.</li>
<li><strong>Cybersecurity:</strong> Regulators are placing increasing emphasis on continuous vulnerability management and operational resilience.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#digital-omnibus-ai-deadlines">Digital Omnibus on AI enters into force: high-risk AI deadlines deferred, but transparency duties remain</a></li>
<li><a href="#edpb-anonymisation-approach">EDPB proposes a relative approach to anonymisation</a></li>
<li><a href="#edpb-web-scraping-generative-ai">EDPB clarifies GDPR requirements for web scraping used to train generative AI</a></li>
<li><a href="#edpb-blockchain-guidelines">EDPB adopts final Guidelines on blockchain and data protection</a></li>
<li><a href="#edpb-cookie-banner-complaint">EDPB requires the Belgian DPA to assess the cookie-banner complaint on its merits</a></li>
<li><a href="#edpb-breach-notification-template">EDPB&#8217;s common data breach notification template moves closer to implementation</a></li>
<li><a href="#iab-europe-tcf-fine">Belgian DPA fines IAB Europe €250,000 over Transparency &amp; Consent Framework</a></li>
<li><a href="#vdai-h1-2026-data-breaches">VDAI reports 140 personal data breaches in Lithuania in H1 2026</a></li>
<li><a href="#vdai-cookie-consent">VDAI confirms prior consent is required for non-essential cookies</a></li>
<li><a href="#nksc-cyber-resilience">NKSC urges organisations to strengthen cyber resilience</a></li>
</ul>
</div>
<h2 id="digital-omnibus-ai-deadlines">Digital Omnibus on AI enters into force: high-risk AI deadlines deferred, but transparency duties remain</h2>
<p><strong>Source:</strong> European Commission | <strong>Date:</strong> 27 July 2026<br /><i class="fa fa-external-link"></i><a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" target="_blank" rel="noopener"> Link</a></p>
<p>The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and amended the EU AI Act.</p>
<p>The most significant change is the postponement of certain high-risk AI compliance deadlines:</p>
<ul>
<li><strong>Annex III high-risk AI systems:</strong> 2 December 2027, instead of 2 August 2026;</li>
<li><strong>Embedded high-risk systems under Annex I:</strong> 2 August 2028, instead of 2 August 2027.</li>
</ul>
<p>The deferral does <strong>not</strong> apply to Article 50 transparency obligations. Requirements concerning the disclosure of AI interactions, AI-generated content, and deepfakes remain applicable as of 2 August 2026. Obligations applicable to providers of general-purpose AI models also remain in force.</p>
<h3>Why does it matter for businesses?</h3>
<p>The additional time for certain high-risk AI requirements provides organisations with more room to implement compliance frameworks. It should not, however, be treated as a general postponement of AI governance.</p>
<p>Businesses need to distinguish between obligations whose application has been deferred and requirements that are already applicable. In particular, organisations deploying AI systems that interact directly with individuals should review whether their transparency measures are operational now.</p>
<h3>Recommended actions</h3>
<ul>
<li>Review AI systems against the revised implementation timetable.</li>
<li>Prioritise Article 50 transparency requirements, including AI interaction disclosures and labelling requirements for AI-generated or manipulated content.</li>
<li>Continue work on AI governance, risk classification, documentation and accountability rather than postponing implementation generally.</li>
<li>Update internal AI compliance roadmaps and responsibility matrices to reflect the revised deadlines.</li>
</ul>
<hr />
<h2 id="edpb-anonymisation-approach">EDPB proposes a relative approach to anonymisation</h2>
<p><strong>Source:</strong> European Data Protection Board | <strong>Date:</strong> 7 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en" target="_blank" rel="noopener"> Link</a></p>
<p>The EDPB published draft Guidelines 02/2026 on anonymisation, intended to replace the former Article 29 Working Party Opinion 05/2014.</p>
<p>The draft takes a relative approach to identifiability. Whether data is anonymous may depend on the realistic means available to the organisation handling the data to identify individuals. As a result, the same dataset may potentially be considered personal data in one context but anonymous in another.</p>
<h3>Why does it matter for businesses?</h3>
<p>The assessment of anonymisation <strong>cannot</strong> be reduced to whether identifiers have been removed or whether a particular technical anonymisation method has been applied.</p>
<p>Organisations using data for AI development, analytics, research or data sharing may need to demonstrate why identification is not reasonably possible in their particular circumstances and what means of re-identification are realistically available.</p>
<h3>Recommended actions</h3>
<ul>
<li>Reassess existing anonymisation methodologies against the EDPB&#8217;s proposed risk-based approach.</li>
<li>Document the realistic means available for re-identification when assessing whether data remains personal data.</li>
<li>Review data-sharing and AI-data projects where the organisation currently relies on anonymisation to take the processing outside the GDPR.</li>
<li>Monitor the finalisation of the Guidelines before making major changes solely on the basis of the draft.</li>
</ul>
<hr />
<h2 id="edpb-web-scraping-generative-ai">EDPB clarifies GDPR requirements for web scraping used to train generative AI</h2>
<p><strong>Source:</strong> European Data Protection Board | <strong>Date:</strong> 8 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The EDPB published draft Guidelines 03/2026 on the use of web scraping to train generative AI models.</p>
<p>The Guidelines address the processing of personal data obtained through web scraping, including the need to consider lawful basis, purpose limitation and transparency.</p>
<p>The fact that information is publicly accessible does <strong>not</strong>, by itself, remove it from the scope of the GDPR.</p>
<h3>Why does it matter for businesses?</h3>
<p>This is particularly relevant to organisations developing AI systems, procuring AI models, or using datasets obtained from publicly accessible websites.</p>
<p>Public availability does not automatically mean that personal data can be collected and reused for AI training without further assessment. Organisations need to consider the original context in which information was collected and whether its proposed use for AI training is compatible with applicable data protection requirements.</p>
<h3>Recommended actions</h3>
<p>Organisations developing or procuring AI trained on scraped data should:</p>
<ul>
<li>identify and document the applicable lawful basis for collecting and using training data;</li>
<li>assess compatibility between the original purpose of collection and the proposed AI-training purpose;</li>
<li>review transparency measures and privacy notices covering AI-related processing;</li>
<li>assess contractual and due-diligence arrangements where AI models or datasets are supplied by third parties.</li>
</ul>
<hr />
<h2 id="edpb-blockchain-guidelines">EDPB adopts final Guidelines on blockchain and data protection</h2>
<p><strong>Source:</strong> European Data Protection Board | <strong>Date:</strong> 8 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The EDPB adopted its final Guidelines on blockchain and data protection, addressing how GDPR principles such as data minimisation, storage limitation, rectification and erasure apply to blockchain-based processing.</p>
<h3>Why does it matter for businesses?</h3>
<p>Blockchain architecture can create a structural tension with GDPR requirements where personal data is stored directly on-chain and <strong>cannot</strong> subsequently be modified or deleted.</p>
<p>The guidance reinforces the importance of addressing data protection at the <strong>design and architecture stage</strong>, rather than attempting to resolve GDPR compliance after a blockchain solution has already been implemented.</p>
<h3>Recommended actions</h3>
<p>Businesses using blockchain in connection with personal data should:</p>
<ul>
<li>avoid storing personal data directly on-chain where possible;</li>
<li>assess whether personal data can instead be kept in appropriately secured off-chain systems;</li>
<li>consider data minimisation and pseudonymisation before deploying the architecture;</li>
<li>assess how the proposed architecture will support data-subject rights, particularly erasure and rectification.</li>
</ul>
<hr />
<h2 id="edpb-cookie-banner-complaint">EDPB requires the Belgian DPA to assess the cookie-banner complaint on its merits</h2>
<p><strong>Source:</strong> European Data Protection Board | <strong>Date:</strong> 14 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en" target="_blank" rel="noopener"> Link</a></p>
<p>The EDPB ruled that a GDPR complaint concerning cookie banners, lodged with the Belgian DPA, must be assessed on its merits, rejecting the argument that the complaint constituted an abuse of rights.</p>
<h3>Why does it matter for businesses?</h3>
<p>The decision reinforces that cookie compliance remains an active enforcement area.</p>
<p>For organisations, the question is not simply whether a cookie banner is present. Regulators and complainants can examine whether the underlying consent mechanism actually complies with GDPR requirements, including whether consent is freely given, sufficiently granular and capable of being withdrawn.</p>
<h3>Recommended actions</h3>
<p>Organisations using cookies and other tracking technologies should:</p>
<ul>
<li>test whether consent is genuinely freely given and granular;</li>
<li>review cookie-banner design for interfaces that steer users towards acceptance;</li>
<li>verify that non-essential tracking technologies are not activated before valid consent;</li>
<li>review the configuration and actual behaviour of their consent-management platform.</li>
</ul>
<hr />
<h2 id="edpb-breach-notification-template">EDPB&#8217;s common data breach notification template moves closer to implementation</h2>
<p><strong>Source:</strong> European Data Protection Board | <strong>Date:</strong> 5 August 2026<br /><i class="fa fa-external-link"></i><a href="https://www.edpb.europa.eu/news/edpb-meets-with-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification-template_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The EDPB&#8217;s draft common template for notifying personal data breaches under Article 33 GDPR was open for consultation until 5 August 2026.</p>
<p>The proposed template contains approximately 120 fields across seven sections, with predefined response options, and is intended to harmonise breach reporting across the EU/EEA.</p>
<h3>Why does it matter for businesses?</h3>
<p>A standardised reporting approach could increase consistency between national supervisory authorities, but it also places greater emphasis on an organisation&#8217;s ability to obtain accurate incident information quickly.</p>
<p>For businesses, the practical issue is not the template itself but whether their incident-response process can generate the required information within the GDPR&#8217;s 72-hour notification period.</p>
<h3>Recommended actions</h3>
<ul>
<li>Map the proposed information requirements against existing breach-response procedures.</li>
<li>Identify information that cannot currently be obtained quickly during an incident.</li>
<li>Clarify responsibilities between legal, IT, security, HR and management teams during a breach.</li>
<li>Test whether the organisation can assess, document and escalate a personal data breach within the 72-hour timeframe.</li>
</ul>
<hr />
<h2 id="iab-europe-tcf-fine">Belgian DPA fines IAB Europe €250,000 over Transparency &amp; Consent Framework</h2>
<p><strong>Source:</strong> Belgian Data Protection Authority | <strong>Date:</strong> 31 July 2026<br /><i class="fa fa-external-link"></i><a href="https://iapp.org/news/a/belgian-dpa-fines-iab-europe-250k-euros-over-consent-framework-gdpr-violations" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The Belgian Data Protection Authority, acting in agreement with the other European data protection authorities involved in the procedure, imposed a €250,000 fine on IAB Europe concerning its Transparency and Consent Framework (TCF).</p>
<p>The Belgian DPA identified several GDPR compliance shortcomings, including issues relating to legal basis, DPO appointment, DPIA requirements and records of processing activities. IAB Europe disputes the findings and is considering a legal challenge.</p>
<h3>Why does it matter for businesses?</h3>
<p>The decision highlights an important distinction between using an industry-standard consent framework and demonstrating compliance with the GDPR as an individual controller.</p>
<p>A standardised consent signal does <strong>not</strong> necessarily resolve the organisation&#8217;s own obligations concerning lawful basis, transparency, accountability, DPIAs or records of processing. This is particularly relevant to publishers, adtech businesses, and other organisations that use consent management and advertising technology frameworks.</p>
<h3>Recommended actions</h3>
<p>Businesses relying on the TCF or similar industry frameworks should:</p>
<ul>
<li>monitor further developments, including any appeal;</li>
<li>assess whether the consent signals they receive are sufficient for their specific processing activities;</li>
<li>independently verify their legal basis and transparency requirements;</li>
<li>review DPIA and accountability documentation where advertising or profiling activities present higher risks.</li>
</ul>
<hr />
<h2 id="vdai-h1-2026-data-breaches">VDAI reports 140 personal data breaches in Lithuania in H1 2026</h2>
<p><strong>Source:</strong> State Data Protection Inspectorate (VDAI) | <strong>Date:</strong> 16 July 2026<br /><i class="fa fa-external-link"></i><a href="https://vdai.lrv.lt/lt/naujienos/asmens-duomenu-saugumo-pazeidimai-lietuvoje-2026-m-i-pusm-Syn/" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The VDAI received 140 personal data breach notifications in Lithuania during the first half of 2026, affecting more than 1.64 million data subjects.</p>
<p>Cyber incidents accounted for 36% of reported breaches, while human error accounted for 48%. Reported examples included sending information to the wrong recipient, using &#8220;CC&#8221; instead of &#8220;BCC&#8221; and improperly anonymising disclosures.</p>
<p>The VDAI reported that 81% of controllers notified breaches within the required 72-hour period. The authority also imposed fines of €4,500 in March and €450,000 on a healthcare company in June for data security failures.</p>
<h3>Why does it matter for businesses?</h3>
<p>The figures demonstrate that data protection risk is not limited to sophisticated cyberattacks. Human error remains a significant source of personal data breaches.</p>
<p>This means that effective GDPR compliance depends not only on policies and technical security measures but also on access controls, employee practices, escalation procedures and the organisation&#8217;s ability to respond quickly when something goes wrong.</p>
<h3>Recommended actions</h3>
<p>Organisations should test, rather than merely document, their incident-response and security controls, with particular attention to:</p>
<ul>
<li>access management and encryption;</li>
<li>employee handling of personal data;</li>
<li>incident detection and escalation;</li>
<li>internal responsibilities during a breach;</li>
<li>the ability to assess and notify a reportable breach within 72 hours.</li>
</ul>
<hr />
<h2 id="vdai-cookie-consent">VDAI confirms prior consent is required for non-essential cookies</h2>
<p><strong>Source:</strong> State Data Protection Inspectorate (VDAI) | <strong>Date:</strong> 23 July 2026<br /><i class="fa fa-external-link"></i><a href="https://vdai.lrv.lt/lt/naujienos/vdai-primena-butina-uztikrinti-tinkama-slapuku-ir-kitu-sekimo-technologiju-naudojima-Xad/" target="_blank" rel="noopener"> Link</a></p>
<p>The VDAI reiterated that non-essential cookies, tracking pixels and similar technologies may only be used after obtaining the website visitor&#8217;s prior, freely given consent.</p>
<p>The authority expressly stated that legitimate interest <strong>cannot</strong> substitute for consent where prior consent is legally required.</p>
<h3>Why does it matter for businesses?</h3>
<p>Cookie compliance cannot be assessed solely by reviewing the wording of a cookie banner.</p>
<p>The actual technical behaviour of the website and consent-management platform matters. Organisations should verify whether tracking technologies are activated before consent, whether consent is properly recorded and whether users can withdraw it effectively.</p>
<h3>Recommended actions</h3>
<ul>
<li>Test the actual technical behaviour of websites and applications before and after consent is given.</li>
<li>Verify that non-essential cookies and tracking technologies are blocked until valid consent is obtained.</li>
<li>Check that consent can be withdrawn as easily as it was given.</li>
<li>Review whether any processing currently relies on legitimate interest where prior consent is legally required.</li>
</ul>
<hr />
<h2 id="nksc-cyber-resilience">NKSC urges organisations to strengthen cyber resilience</h2>
<p><strong>Source:</strong> National Cyber Security Centre (NKSC) | <strong>Date:</strong> 28 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.nksc.lt/naujienos/kintanti_kibernetiniu_gresmiu_aplinka_nks_7eac0590.html" target="_blank" rel="noopener"> Link</a></p>
<p>The NKSC highlighted the increasingly short period between the discovery of vulnerabilities and their exploitation. The authority noted that AI-assisted tools are enabling attackers to identify and exploit security weaknesses more rapidly.</p>
<p>Organisations are being encouraged to strengthen continuous infrastructure monitoring, vulnerability management and incident response.</p>
<h3>Why does it matter for businesses?</h3>
<p>The speed of exploitation makes periodic security reviews increasingly insufficient for organisations exposed to significant cyber risk.</p>
<p>Vulnerability management needs to operate as an ongoing process, with the ability to identify, prioritise, and remediate critical vulnerabilities before they are exploited.</p>
<h3>Recommended actions</h3>
<p>Organisations should assess whether:</p>
<ul>
<li>vulnerability monitoring is sufficiently continuous;</li>
<li>critical vulnerabilities are prioritised according to actual business risk;</li>
<li>patching processes can respond quickly to newly disclosed vulnerabilities;</li>
<li>incident-response procedures can operate effectively alongside vulnerability management.</li>
</ul>
<hr />
<h2>What businesses should take from this month&#8217;s developments</h2>
<p>Across the EU and Lithuania, regulators are increasingly focusing on how compliance works in practice.</p>
<p>For businesses, the key message is not simply to update policies when new guidance or enforcement decisions are published. Organisations should be able to demonstrate that their controls work: that AI systems are appropriately governed, tracking technologies behave as intended, personal data is protected, and breaches can be assessed and reported quickly.</p>
<p>The same principle applies across GDPR, AI and ICT compliance: documented compliance is becoming less persuasive where operational reality tells a different story.</p>
<hr />
<h2>Need assistance?</h2>
<p>ECOVIS ProventusLaw advises organisations on the practical implementation of data protection, AI and ICT regulatory requirements, including:</p>
<ul>
<li>GDPR compliance programmes and data protection governance</li>
<li>AI governance and GDPR compliance for AI systems</li>
<li>personal data breach assessment and incident response</li>
<li>DPIAs and data protection risk assessments</li>
<li>cookie and tracking technology compliance</li>
<li>cybersecurity and ICT regulatory compliance</li>
<li>data protection policies, procedures and accountability documentation</li>
</ul>
<p>If you are reviewing your organisation&#8217;s GDPR, AI, or ICT compliance framework in light of recent regulatory developments, our team can help assess your current position and identify areas requiring action.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-personal-data-protection-and-ict-regulation-august-2026/">RegRally Insights: GDPR and ICT Regulation, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Payment Institution vs Electronic Money Institution: What to Review in 2026</title>
		<link>https://ecovis.lt/payment-institution-vs-electronic-money-institution/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 13 Aug 2026 16:31:08 +0000</pubDate>
				<category><![CDATA[Fintech]]></category>
		<category><![CDATA[Insight]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11530</guid>

					<description><![CDATA[<p>The distinction between a Payment Institution (PI) and an Electronic Money Institution (EMI) is becoming increasingly important for fintech businesses operating in the European Union.</p>
<p>The post <a href="https://ecovis.lt/payment-institution-vs-electronic-money-institution/">Payment Institution vs Electronic Money Institution: What to Review in 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2>Payment Institution vs Electronic Money Institution: What EU Fintechs Should Review in 2026</h2>
<p>The distinction between a <a href="https://ecovis.lt/fintech/payment-institutions/" target="_blank" rel="noopener">Payment Institution (PI)</a> and an <a href="https://ecovis.lt/fintech/e-money-institutions/" target="_blank" rel="noopener">Electronic Money Institution (EMI)</a> is becoming increasingly important for fintech businesses operating in the European Union.</p>
<p>As the EU payment services regulatory framework evolves, licensed institutions should not rely solely on the scope of their existing authorisation. They should also assess whether their actual products, payment flows and business model remain consistent with the regulatory status under which they operate.</p>
<h2>Why does the PI vs EMI distinction matter?</h2>
<p>A Payment Institution is authorised to provide regulated payment services. An Electronic Money Institution can provide payment services and, importantly, issue electronic money.</p>
<p>This distinction can become less straightforward in practice, where fintech products combine wallets, payment accounts, stored-value functionality, card programmes, merchant services or other embedded payment solutions.</p>
<p>For an established fintech, the relevant question is: &#8220;Does our current business model require the regulatory permissions associated with an EMI?&#8221;</p>
<h2>What should licensed fintechs review?</h2>
<p>EU payment and e-money institutions should consider conducting a structured regulatory review covering:</p>
<ul>
<li>Products and payment flows – identify how customer funds are received, held, transferred and used;</li>
<li>Electronic money analysis – determine whether any products or balances may constitute electronic money;</li>
<li>Safeguarding arrangements – assess whether current arrangements remain appropriate for the activities actually performed;</li>
<li>Capital requirements – consider the potential impact of regulatory classification on own-funds requirements;</li>
<li>Agents, distributors and partners – review whether existing arrangements and regulatory notifications remain appropriate;</li>
<li>Governance and compliance – ensure the regulatory framework, policies and internal controls reflect the actual business model.</li>
</ul>
<h2>Why 2026 is the right time to review</h2>
<p>The EU payment services framework is undergoing significant regulatory development, while supervisory expectations around the substance of financial services activities continue to evolve. The EBA has also issued guidance on the transition between the existing and emerging payment services frameworks.</p>
<p>For fintech businesses, this creates a practical reason to assess regulatory positioning before changes become operationally urgent.</p>
<p>A proactive review can identify potential licensing or compliance gaps, clarify whether the existing authorisation remains appropriate, and help management plan any necessary regulatory engagement.</p>
<h2>How ECOVIS ProventusLaw can help</h2>
<p>ECOVIS ProventusLaw advises electronic money institutions, payment institutions and fintech businesses on:</p>
<ul>
<li>EMI and PI licensing and regulatory strategy;</li>
<li>regulatory requalification and business-model assessments;</li>
<li>payment services and e-money regulatory analysis;</li>
<li>safeguarding and governance requirements;</li>
<li>AML/CFT and compliance frameworks;</li>
<li>regulatory engagement with competent authorities;</li>
<li>cross-border expansion and passporting.</li>
</ul>
<p>Our Partner <strong>Inga Karulaitytė</strong>, Head of Banking &amp; Finance and FinTech, regularly advises financial institutions across the Baltic region on licensing, regulatory requalification and compliance.</p>
<p><strong>Practical takeaway:</strong> licensed fintechs should review their products and payment flows now and confirm that their regulatory permissions continue to match the substance of their business.</p>
<p><strong>Related reading:</strong><br /><i class="fa fa-external-link"></i><a href="https://techbullion.com/payment-institution-licence-vs-electronic-money-licence-what-eu-emis-need-to-know-about-the-2026-requalification/" target="_blank" rel="noopener nofollow"> Payment Institution Licence vs Electronic Money Licence: What EU EMIs Need to Know About the 2026 Requalification — Inga Karulaitytė, TechBullion.</a></p>


<p>The post <a href="https://ecovis.lt/payment-institution-vs-electronic-money-institution/">Payment Institution vs Electronic Money Institution: What to Review in 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Employment &#038; Migration Law Updates, August 2026</title>
		<link>https://ecovis.lt/regrally-insights-employment-migration-law-updates-august-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 13 Aug 2026 09:35:39 +0000</pubDate>
				<category><![CDATA[Employment & Migration]]></category>
		<category><![CDATA[RegRally]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11509</guid>

					<description><![CDATA[<p>Employment law is moving beyond traditional HR compliance. Recent developments show a clear shift towards closer scrutiny of how employers manage disputes, remote and cross-border work, workplace risks, and increasingly technology-driven employment practices.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-employment-migration-law-updates-august-2026/">RegRally Insights: Employment &#038; Migration Law Updates, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><style>.rr-li::marker{color:#c6093b;}</style></p>
<p><a href="https://ecovis.lt/practice-areas/labour-law/" target="_blank" rel="noopener">Employment law</a> is moving beyond traditional HR compliance. Recent developments show a clear shift towards closer scrutiny of how employers manage disputes, remote and cross-border work, workplace risks, and increasingly technology-driven employment practices.</p>
<p>This edition of RegRally Insights: Employment &amp; Migration brings together the key developments that employers, HR professionals, and in-house legal teams should be aware of as they review employment practices, workforce planning, and restructuring decisions.</p>
<p>In Lithuania, recent changes to unemployment insurance are affecting the labour market, while labour dispute statistics indicate a significant increase in employment-related claims. At the EU level, the CJEU has provided important guidance on governing law in cross-border remote work arrangements, while the European Commission is advancing the Quality Jobs Act, with AI and algorithmic management, workplace health and safety, subcontracting chains and enforcement among its priorities.</p>
<p>For employers, the overall direction is clear: employment compliance increasingly requires proactive risk management rather than simply reacting when a dispute or inspection arises.</p>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;"><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span>
<ul>
<li class="rr-li"><a href="#labour-disputes-rising">Labour disputes are rising: VDI reports 17% more applications and 23% more claims</a></li>
<li class="rr-li"><a href="#unemployment-insurance-reform">Unemployment insurance reform changes eligibility and benefits</a></li>
<li class="rr-li"><a href="#cjeu-cross-border-remote-work">CJEU clarifies governing law in cross-border remote work</a></li>
<li class="rr-li"><a href="#quality-jobs-act">Quality Jobs Act: EU consultation puts AI at work firmly on the agenda</a></li>
<li class="rr-li"><a href="#future-of-work">European Commission renews focus on the future of work</a></li>
<li class="rr-li"><a href="#cross-border-inspections">Cross-border labour inspections: stronger cooperation between European authorities</a></li>
<li class="rr-li"><a href="#lithuania-eu-priorities">Lithuania&#8217;s priorities for the EU employment agenda</a></li>
</ul>
</div>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="labour-disputes-rising">Labour disputes are rising: VDI reports 17% more applications and 23% more claims</h2>
<p><strong>Source:</strong> State Labour Inspectorate (VDI) | <strong>Date:</strong> 30 July 2026<br /><i class="fa fa-external-link"></i><a href="https://vdi.lrv.lt/lt/naujienos/darbo-gincu-komisiju-veiklos-rezultatai-2026-m-i-pusmeti-17-proc-daugiau-prasymu-ir-23-proc-daugiau-reikalavimu-yoD/" target="_blank" rel="noopener"> Link</a></p>
<p>The State Labour Inspectorate reported a significant increase in labour disputes during the first half of 2026. Labour Dispute Commissions received 5,142 applications — 17% more than in H1 2025 — and 13,074 claims, an increase of 23%.</p>
<p>Wage-related claims remained the largest category, accounting for approximately 71% of all claims. Claims relating to psychological violence at work also nearly doubled year on year.</p>
<p>The figures are particularly relevant for employers because they indicate where employment-related risks are increasingly materialising in practice.</p>
<h3>Recommended actions</h3>
<p>Employers should:</p>
<ul>
<li class="rr-li">Review internal anti-harassment and anti-bullying policies and reporting channels.</li>
<li class="rr-li">Pay particular attention to payroll accuracy and timely settlement of employment-related payments.</li>
<li class="rr-li">Consider early and constructive resolution of disputes, as 25% of claims were resolved through settlement agreements.</li>
</ul>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="unemployment-insurance-reform">Unemployment insurance reform changes eligibility and benefits</h2>
<p><strong>Source:</strong> Ministry of Social Security and Labour | <strong>Date:</strong> 1 July 2026<br /><i class="fa fa-external-link"></i><a href="https://socmin.lrv.lt/lt/naujienos/keisis-nedarbo-draudimo-ismoku-sistema-geres-priespensinio-amziaus-darbuotoju-padetis-agS/" target="_blank" rel="noopener"> Link</a></p>
<p>The Law on Unemployment Social Insurance has been substantially revised, changing both eligibility requirements and benefit calculations.</p>
<p>Among the key changes are a new minimum unemployment benefit of EUR 370 in 2026, changes to the earnings-related component of the benefit, and extended benefit periods for people approaching retirement age with a sufficiently long pension-insurance record. A new claim generally requires 12 months of insurance record within the previous 24 months.</p>
<p><strong>Key changes include:</strong><br /><strong><span style="color: #c6093b;">1.</span></strong> the benefit&#8217;s fixed component (independent of prior earnings) is reduced from 23.27% to 15% of the relevant base, while the earnings-linked variable component increases &#8211; to 45% of average insured income in months 1-3 (up from 38.79%), 35% in months 4-6 (up from 31.03%), and 25% in months 7-9 (up from 23.27%);</p>
<p><strong><span style="color: #c6093b;">2.</span></strong> a minimum benefit is introduced, set at 5x the base social benefit (5 x EUR 74 = EUR 370 in 2026), and the maximum benefit is capped at 70% of the national average wage;</p>
<p><strong><span style="color: #c6093b;">3.</span> </strong>people within 5 years of old-age pension age who have at least 20 years of pension-insurance record get their benefit period extended from 2 to 6 months in total (an additional 4 months for people already receiving or resuming payments from 1 July);</p>
<p><strong><span style="color: #c6093b;">4.</span></strong> a new unemployment benefit claim now requires a fresh 12-month insurance record within the last 24 months, and periods of receiving unemployment benefits no longer count toward that new qualifying record;</p>
<p><strong><span style="color: #c6093b;">5.</span></strong> transitional rules apply to people who already had an unemployed status before 1 July 2026, including automatic recalculation where a continuing or resumed benefit would otherwise fall below EUR 370.</p>
<h3>Recommended actions</h3>
<p>HR teams handling redundancies and terminations should:</p>
<ul>
<li class="rr-li">Update employee-facing information concerning unemployment benefits.</li>
<li class="rr-li">Take the new eligibility and benefit rules into account when planning redundancies and termination processes.</li>
<li class="rr-li">Be aware that employees close to pension age with 20+ years of insurance record now have a materially longer benefit runway (6 months instead of 2), which may affect redundancy planning and severance discussions.</li>
</ul>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="cjeu-cross-border-remote-work">CJEU clarifies governing law in cross-border remote work</h2>
<p><strong>Case:</strong> Hortis GRC SA, C-768/24 | <strong>Date:</strong> 9 July 2026<br /><i class="fa fa-external-link"></i><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62024CJ0768" target="_blank" rel="noopener"> Link</a></p>
<p>The CJEU provided important guidance on determining the applicable law in cross-border employment relationships involving remote work.</p>
<p>The Court confirmed that where the law chosen by the parties is also the law of the country most closely connected with the employment relationship, that chosen law may apply rather than the mandatory employment protections of the country where the employee habitually works.</p>
<p>Relevant factors may include the currency in which salary is paid, social insurance affiliation and tax residence. The choice-of-law clause itself, however, cannot establish the necessary connection.</p>
<p>The judgment is particularly relevant for employers managing international remote-working arrangements, where the employee, employer and employment-related obligations may be located in different jurisdictions.</p>
<h3>Recommended actions</h3>
<p>Employers should:</p>
<ul>
<li class="rr-li">Review governing-law clauses in cross-border employment contracts.</li>
<li class="rr-li">Assess whether the practical arrangements genuinely support the chosen governing law.</li>
<li class="rr-li">Review salary, tax and social insurance arrangements alongside the contractual framework.</li>
</ul>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="quality-jobs-act">Quality Jobs Act: EU consultation puts AI at work firmly on the agenda</h2>
<p><strong>Source:</strong> European Commission | <strong>Date:</strong> 20 July 2026<br /><i class="fa fa-external-link"></i><a href="https://employment-social-affairs.ec.europa.eu/news/commission-opens-second-phase-consultation-quality-jobs-act-2026-07-20_en" target="_blank" rel="noopener"> Link</a></p>
<p>The European Commission launched the second phase of consultation on the forthcoming Quality Jobs Act, which is expected later in 2026.</p>
<p><strong>The consultation focuses on five areas:</strong></p>
<ul>
<li class="rr-li">algorithmic management and AI at work;</li>
<li class="rr-li">occupational health and safety;</li>
<li class="rr-li">workers&#8217; rights in subcontracting chains;</li>
<li class="rr-li">fair digital and green transitions;</li>
<li class="rr-li">enforcement and the role of social partners.</li>
</ul>
<p>The AI-related proposals are particularly significant. They address transparency and human oversight of automated decisions, as well as protection against excessive workplace monitoring.</p>
<h3>Recommended actions</h3>
<p>Employers and HR/compliance teams should:</p>
<ul>
<li class="rr-li">Monitor developments relating to the Quality Jobs Act as a major upcoming EU initiative, given its likely impact on AI/algorithmic management, workplace heat and psychosocial risk rules, and subcontracting-chain liability.</li>
<li class="rr-li">Review the use of AI in recruitment, scheduling, performance monitoring and employment decisions.</li>
<li class="rr-li">Consider whether existing governance and human oversight mechanisms are adequate.</li>
<li class="rr-li">Consider participating in the consultation before <strong>28 September 2026</strong>, where relevant to the organisation.</li>
</ul>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="future-of-work">European Commission renews focus on the future of work</h2>
<p><strong>Date:</strong> 22 July 2026</p>
<p>The European Commission has renewed its commitment to the European Pillar of Social Rights and identified several areas requiring further EU-level action.</p>
<p>One of the key priorities is harnessing AI for the future of work, including establishing a new high-level group to examine AI&#8217;s impact on the labour market.</p>
<p>The Commission also confirmed that a Quality Jobs Act will follow later in 2026, along with new indicators to measure job quality across the EU.</p>
<p>For employers, this reinforces the importance of treating AI governance as an emerging employment-law issue, not only a technology or data-protection issue.</p>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="cross-border-inspections">Cross-border labour inspections: stronger cooperation between European authorities</h2>
<p><strong>Date:</strong> 21 July 2026</p>
<p>The Lithuanian State Labour Inspectorate participated in a European Labour Authority-coordinated inspection initiative involving authorities from eight European countries.</p>
<p>The inspections covered undeclared work, wage payments, posted workers&#8217; rights, and other EU employment requirements. In total, 26 company sites were inspected and more than 150 workers interviewed.</p>
<p>The initiative demonstrates the growing capacity of national labour authorities to coordinate cross-border investigations.</p>
<h3>Recommended actions</h3>
<p>Employers using posted workers or cross-border staffing arrangements should:</p>
<ul>
<li class="rr-li">Keep posted-worker documentation, wage records and social insurance information accurate and readily available.</li>
<li class="rr-li">Review compliance where third-country nationals are assigned to work in other EU jurisdictions.</li>
<li class="rr-li">Treat recurring wage complaints as a potential regulatory risk, particularly where cross-border arrangements are involved.</li>
</ul>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2 id="lithuania-eu-priorities">Lithuania&#8217;s priorities for the EU employment agenda</h2>
<p><strong>Date:</strong> 6 July 2026</p>
<p>At the informal EPSCO Council meeting, Lithuania highlighted three priorities for the EU social agenda:</p>
<ul>
<li class="rr-li">continued focus on poverty reduction;</li>
<li class="rr-li">ensuring that simplification of labour-market regulation does not weaken worker protection;</li>
<li class="rr-li">improving labour-market inclusion for people with disabilities.</li>
</ul>
<p>These priorities provide further context for the direction of EU employment policy and upcoming regulatory initiatives.</p>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2>What should employers take away?</h2>
<p>Recent developments point to several practical areas that deserve closer attention:</p>
<p><strong><span style="color: #c6093b;">1.</span> Employment disputes are increasing.</strong><br />Wage issues and workplace conduct remain major sources of employment risk.</p>
<p><strong><span style="color: #c6093b;">2.</span> Cross-border work requires more than a well-drafted contract.</strong><br />The actual economic and social circumstances of the employment relationship can determine which law applies.</p>
<p><strong><span style="color: #c6093b;">3.</span> AI is becoming an employment-law issue.</strong><br />Employers should start considering governance, transparency and human oversight where AI is used to manage or evaluate workers.</p>
<p><strong><span style="color: #c6093b;">4.</span> Labour enforcement is becoming increasingly coordinated.</strong><br />Cross-border employment arrangements can attract attention from multiple national authorities.</p>
<p><strong><span style="color: #c6093b;">5.</span> Proactive compliance matters.</strong><br />Regular reviews of contracts, HR policies, payroll, workplace practices and employment-related technology can help identify risks before they become disputes or regulatory issues.</p>
<div class="is-divider divider clearfix" style="margin-top: 20px; margin-bottom: 10px; max-width: 70px; height: 2px; background-color: #c6093b;"> </div>
<h2>Need assistance?</h2>
<p>Employment law is evolving rapidly, with new legislative requirements, court judgments and regulatory expectations affecting employers across sectors.</p>
<p>Our Employment &amp; Migration Law specialists can assist with:</p>
<ul>
<li class="rr-li">Employment law compliance reviews and Labour Code gap assessments</li>
<li class="rr-li">Employment contracts, internal policies and HR documentation</li>
<li class="rr-li">Workplace investigations and disciplinary procedures</li>
<li class="rr-li">Collective redundancies, restructurings and business transfers</li>
<li class="rr-li">Executive employment, termination strategies and settlement agreements</li>
<li class="rr-li">Working time, remuneration and employee benefits compliance</li>
<li class="rr-li">Occupational health and safety obligations</li>
<li class="rr-li">Employment disputes, regulatory investigations and labour inspections</li>
<li class="rr-li">Employment-related GDPR and workplace privacy matters.</li>
</ul>
<p>If you have any questions regarding the developments covered in this edition or would like to assess your organisation&#8217;s employment law compliance, our team will be happy to assist you.</p>

<p>The post <a href="https://ecovis.lt/regrally-insights-employment-migration-law-updates-august-2026/">RegRally Insights: Employment &#038; Migration Law Updates, August 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
