<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ECOVIS ProventusLaw</title>
	<atom:link href="https://ecovis.lt/feed/" rel="self" type="application/rss+xml" />
	<link>https://ecovis.lt/</link>
	<description></description>
	<lastBuildDate>Wed, 16 Sep 2026 17:31:52 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://ecovis.lt/wp-content/uploads/2026/02/cropped-ecovis-fav-32x32.png</url>
	<title>ECOVIS ProventusLaw</title>
	<link>https://ecovis.lt/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>RegRally Insights: Personal Data Protection &#038; ICT Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-personal-data-protection-ict-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 17:09:57 +0000</pubDate>
				<category><![CDATA[Data protection & ICT]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=12055</guid>

					<description><![CDATA[<p>The September edition of RegRally covers the data protection and information and communication technology (ICT) developments of August that matter most to businesses processing personal data in Lithuania and across the EU.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-personal-data-protection-ict-regulation-september-2026/">RegRally Insights: Personal Data Protection &#038; ICT Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>One decision dominated August: the Dutch Data Protection Authority fined Uber nearly EUR 825 million for the fully automated blocking of drivers, one of the largest penalties ever issued under the General Data Protection Regulation (GDPR). The same weeks brought a cease-and-desist letter to the credit agency SCHUFA over data that should have been deleted, joint Lithuanian guidance on video surveillance cameras, and plain-language GDPR material from the State Data Protection Inspectorate (VDAI).</p>
<p>The September edition of RegRally covers the <a href="https://ecovis.lt/data-protection/">data protection</a> and information and communication technology (ICT) developments of August that matter most to businesses processing personal data in Lithuania and across the EU.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Automated decisions:</strong> the Dutch Data Protection Authority fined Uber nearly EUR 825 million under Article 22 GDPR for deactivating drivers by automated decision-making without meaningful human intervention.</li>
<li><strong>Retention and erasure:</strong> noyb sent SCHUFA a cease-and-desist letter over an alleged shadow database, demanding genuine erasure, complete access responses and transparency, and opened an interest list for a possible class action.</li>
<li><strong>Video surveillance:</strong> Lithuania&#8217;s National Cyber Security Centre (NKSC), together with the Second Investigation Department under the Ministry of National Defence (AOTD) and the State Security Department (VSD), published recommendations on the secure use of video surveillance cameras.</li>
<li><strong>Plain-language GDPR:</strong> VDAI published material explaining data protection requirements in accessible language, useful for internal policies, staff training and privacy notices.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px;">
<p><i class="fa fa-list-ul" aria-hidden="true"></i> <strong>Quick Navigation</strong></p>
<ul>
<li><a href="#uber-automated-decisions-fine">Uber’s EUR 825 million GDPR fine for automated decisions</a></li>
<li><a href="#noyb-schufa-shadow-database">SCHUFA and the GDPR: retention, erasure and access requests</a></li>
<li><a href="#video-surveillance-camera-security">Video surveillance cameras: security recommendations from Lithuanian authorities</a></li>
<li><a href="#vdai-plain-language-guidance">VDAI explains data protection in plain language</a></li>
</ul>
</div>
<h2 id="uber-automated-decisions-fine">Uber’s EUR 825 million GDPR fine for automated decisions</h2>
<p><strong>Date:</strong> 21 August 2026 | <strong>Source:</strong> Autoriteit Persoonsgegevens (Dutch Data Protection Authority)<br />
<i class="fa fa-external-link"></i> <a href="https://www.autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking" target="_blank" rel="noopener" aria-label="Dutch Data Protection Authority announcement, opens in a new tab">Link</a> | <i class="fa fa-external-link"></i> <a href="https://www.cnil.fr/en/automated-decisions-uber-fined-nearly-eur-825-million" target="_blank" rel="noopener" aria-label="CNIL summary of the decision, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>On 21 August 2026, the Dutch Data Protection Authority fined Uber EUR 824,990,000, nearly EUR 825 million, for the fully automated deactivation (blocking) of drivers. It is one of the largest GDPR penalties ever issued.</p>
<p>The decision turns on Article 22 GDPR. Drivers were deactivated by automated decision-making with no meaningful human intervention, and without the safeguards and transparency that provision requires for decisions producing legal effects or similarly significantly affecting data subjects.</p>
<h3>Why does it matter for businesses?</h3>
<p>The decision is significant for organizations using AI-supported or other algorithmic decision-making tools affecting individuals, including in HR, onboarding, offboarding, fraud prevention, compliance, risk scoring and account termination. It also confirms that regulators will treat the absence of genuine human review as a substantive breach of Article 22 GDPR rather than a mere procedural defect.</p>
<h3>Recommended actions</h3>
<p>Businesses using automated decision-making should:</p>
<ul>
<li>prepare an inventory of the decisions the organization makes about individuals without human involvement, for example blocking an account, terminating a contract or refusing a client on risk grounds</li>
<li>assess for each whether Article 22 GDPR allows it to be taken on a fully automated basis</li>
<li>make sure the human review behind an automated decision is genuine and can be evidenced: the reviewer should see the underlying data, have authority to change the outcome and leave a record of the review</li>
<li>remember that a formal sign-off alone does not meet the Article 22 GDPR standard, as this was the central failing in the Uber decision</li>
<li>check that privacy notices tell individuals when a decision about them is automated and what logic is involved</li>
<li>keep a working procedure through which individuals can contest an automated decision and obtain human review, and document the safeguards in writing</li>
</ul>
<hr>
<h2 id="noyb-schufa-shadow-database">SCHUFA and the GDPR: retention, erasure and access requests</h2>
<p><strong>Date:</strong> 26 August 2026 | <strong>Source:</strong> noyb (European Center for Digital Rights)<br />
<i class="fa fa-external-link"></i> <a href="https://noyb.eu/en/shadow-database-scandal-noyb-sends-schufa-cease-and-desist-letter-interest-list-class-action" target="_blank" rel="noopener" aria-label="noyb announcement on the SCHUFA case, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>On 26 August 2026, noyb sent a cease-and-desist letter to the German credit information agency SCHUFA over an alleged shadow database and opened an interest list for a prospective class action. noyb demands that SCHUFA stop storing data beyond its own published retention periods, provide affected individuals with their historical data in response to access requests under Article 15 GDPR, and ensure transparency about its processing practices.</p>
<p>SCHUFA rejected the demands, so noyb has confirmed it will file for an injunction, and an interest list has been opened for a possible damages class action.</p>
<h3>Why does it matter for businesses?</h3>
<p>The dispute turns on retention and genuine erasure, and on the completeness of access responses. The allegation is that records which should have been deleted are only hidden from view and still used, including to develop and test scores.</p>
<h3>Recommended actions</h3>
<p>Businesses holding personal data should:</p>
<ul>
<li>map every dataset in which the organization holds personal data, including archives, backups and historical records</li>
<li>check that the retention period the organization itself publishes is actually applied, and that data is genuinely erased at the end of that period, not merely hidden from everyday view while remaining available for other uses</li>
<li>make sure responses to access requests under Article 15 GDPR cover all personal data held about the individual, including archived and historical records, not only what appears in the active system</li>
<li>state in the privacy notice how long each category of data is kept and on what basis</li>
<li>where historical data is reused for a further purpose, for example to develop or test scoring models, confirm that the further use has its own lawful basis and is disclosed to the individuals concerned</li>
</ul>
<hr>
<h2 id="video-surveillance-camera-security">Video surveillance cameras: security recommendations from Lithuanian authorities</h2>
<p><strong>Date:</strong> 26 August 2026 | <strong>Source:</strong> National Cyber Security Centre (NKSC)<br />
<i class="fa fa-external-link"></i> <a href="https://www.nksc.lt/naujienos/nuo_privatumo_iki_nacionalinio_saugumo_ko_708b9bc5.html" target="_blank" rel="noopener" aria-label="NKSC announcement, opens in a new tab">Link</a> | <i class="fa fa-external-link"></i> <a href="https://www.nksc.lt/doc/biuleteniai/Vaizdo-stebejimo-kameru-pazeidziamumo-vertinimas-ir-praktines-rekomendacijos-11.pdf" target="_blank" rel="noopener" aria-label="NKSC recommendations document, PDF, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>On 26 August 2026, NKSC, AOTD and VSD jointly published recommendations on the secure use of video surveillance cameras, framing the issue as running from privacy to national security. The authorities stress that even a single unprotected camera can serve both as a source of valuable information and as an access point into the whole network of a home, company or organization.</p>
<p>Cameras deployed for security and monitoring are themselves attractive targets. Attackers who gain access can collect sensitive information for criminal purposes or in the interests of foreign states. The authorities point to the Dutch intelligence services&#8217; July 2026 disclosure of systematic Russian digital espionage operations exploiting internet-connected cameras in the West and in Ukraine, where intercepted video feeds were used to identify military vehicle routes, weapons delivery routes and troop positions.</p>
<h3>Why does it matter for businesses?</h3>
<p>Poorly configured or unpatched devices create both a personal data exposure and a national security exposure. For businesses, camera security raises both GDPR and ICT security issues. The guidance also highlights the growing focus of public authorities on supply-chain security risks associated with connected devices and surveillance technologies.</p>
<h3>Recommended actions</h3>
<p>The baseline recommendations issued by the authorities are in substance the following:</p>
<ul>
<li>change the factory administrator password on every device to a strong and unique password that is not reused across units, and change it periodically</li>
<li>update camera software and firmware regularly, and do not use devices the manufacturer no longer supports, replacing them with newer equipment from reliable manufacturers</li>
<li>make sure there are no abandoned or unmonitored cameras still connected to the network</li>
<li>where there is no genuine need, do not allow the camera to be reached directly from the internet. For remote access use only the manufacturer&#8217;s recommended solution or a VPN, and keep surveillance equipment in a separate network segment</li>
<li>do not install or upgrade to surveillance equipment from untrusted manufacturers, in particular devices produced in China, Russia or Iran</li>
<li>use features such as partial blurring where the image may otherwise reveal sensitive information, for example GPS location, and limit the camera&#8217;s field of view so that it does not capture excessive detail, such as an exact address, or confidential detail, such as computer screens or documents</li>
<li>monitor whether cameras that do not belong to the organization have appeared on its property or are pointed at it</li>
<li>include camera systems in the assessment of security of processing under Article 32 GDPR and, where the organization is subject to ICT rules such as the NIS2 Directive or the Digital Operational Resilience Act (DORA), also in its ICT risk management and incident reporting arrangements</li>
</ul>
<hr>
<h2 id="vdai-plain-language-guidance">VDAI explains data protection in plain language</h2>
<p><strong>Date:</strong> 28 August 2026 | <strong>Source:</strong> State Data Protection Inspectorate (VDAI)<br />
<i class="fa fa-external-link"></i> <a href="https://vdai.lrv.lt/lt/naujienos/apie-duomenu-apsauga-paprastai-ir-aiskiai-C6g" target="_blank" rel="noopener" aria-label="VDAI announcement, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>On 28 August 2026, VDAI published material explaining data protection requirements in plain and accessible language, as part of its ongoing effort to make GDPR obligations comprehensible to controllers and data subjects.</p>
<h3>Why does it matter for businesses?</h3>
<p>The material shows how the Inspectorate itself explains key GDPR principles, and is useful when reviewing internal policies, staff training materials and privacy notices.</p>
<h3>Recommended actions</h3>
<p>Businesses processing personal data should:</p>
<ul>
<li>review the Inspectorate&#8217;s material and circulate it internally to the staff who handle personal data</li>
<li>use it as a reference when reviewing internal policies, staff training materials and privacy notices</li>
</ul>
<hr>
<h2>What should businesses take from this month&#8217;s developments?</h2>
<p>The Uber decision is relevant to any business that uses automated decisions about individuals. If an account can be blocked, a contract terminated or a client refused without a person genuinely reviewing the decision, human review has to be real, evidenced and capable of changing the outcome.</p>
<p>Retention promises have to be kept in practice. The SCHUFA dispute turns on exactly that pattern: data kept beyond published retention periods, hidden from everyday view but still in use, and access responses that stop at the active system.</p>
<p>Camera systems can raise both data protection and ICT security issues. They belong in the Article 32 GDPR assessment of security of processing, and, for organizations under the NIS2 Directive or DORA, in ICT risk management and incident reporting arrangements.</p>
<hr>
<h2>How ECOVIS ProventusLaw can help</h2>
<p>ECOVIS ProventusLaw advises businesses on <a href="https://ecovis.lt/practice-areas/telecommunications-it-and-data-protection-en/">telecommunications, IT and data protection</a> matters, including GDPR compliance, automated decision-making, retention and erasure practices, privacy notices and the ICT requirements applying to connected devices.</p>
<p>For financial institutions, our team also covers <a href="https://ecovis.lt/fintech/data-protection-in-fintech-companies-time-to-prepair-for-the-new-regulation/">data protection in fintech companies</a>. As your legal advisors, we will be happy to assist with all questions related to these developments, including legal advice as well as the revision and preparation of your internal documents.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-personal-data-protection-ict-regulation-september-2026/">RegRally Insights: Personal Data Protection &#038; ICT Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Legal and Investment Update in Estonia, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-legal-and-investment-update-in-estonia-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 10:37:08 +0000</pubDate>
				<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=12049</guid>

					<description><![CDATA[<p>Estonia made development projects easier to implement and expanded access to large-scale investment support. At the same time, new EU AI transparency and packaging requirements began to apply. The August changes matter most for investment decisions in three areas: project financing, permitting and construction timelines, and product or service compliance. Legal preparation should begin before binding investment or supply contracts are signed.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-legal-and-investment-update-in-estonia-september-2026/">RegRally Insights: Legal and Investment Update in Estonia, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Estonia made development projects easier to implement and expanded access to large-scale investment support. At the same time, new EU AI transparency and packaging requirements began to apply. The August changes matter most for investment decisions in three areas: project financing, permitting and construction timelines, and product or service compliance. Legal preparation should begin before binding investment or supply contracts are signed.</p>
<p>This edition of RegRally covers the period from 1 to 31 August 2026 and is written for businesses and international investors operating or investing in Estonia.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Investment support:</strong> the general threshold for large-scale investment support was lowered from EUR 100 million to EUR 70 million, with EUR 35 million for priority technology projects and EUR 20 million for defense industry projects, and the job creation requirement reduced from 30 to 20. The amendment entered into force on 8 August. The grant cap is EUR 20 million per project, and supported activities must not begin before the application is submitted.</li>
<li><strong>Construction:</strong> the Building Code reform took effect on 1 August. Building notice validity was extended from two to four years, one use permit can cover several buildings, and a use notice replaces the use permit for one- and two-apartment dwellings. Requirements became stricter for certain alterations of residential buildings with three or more apartments.</li>
<li><strong>AI Act:</strong> Article 50 transparency obligations apply from 2 August. The AI Omnibus moved the high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), and systems placed on the market before 2 August 2026 must meet the Article 50(2) marking requirements from 2 December 2026.</li>
<li><strong>Packaging:</strong> the EU Packaging and Packaging Waste Regulation entered general application on 12 August, including limits on PFAS in food-contact packaging. Most recyclability, labeling and reuse requirements follow in later stages, predominantly from 2028 or 2030.</li>
<li><strong>Electricity:</strong> from 1 August, consumption points with a bidirectional meter are billed on 15-minute net quantities, which changes the economics of on-site generation.</li>
<li><strong>From 1 September:</strong> online traders must offer consumers a clearly visible withdrawal button. The Consumer Protection and Technical Regulatory Authority flagged this at the end of August as an immediate preparation item.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px;">
<p><i class="fa fa-list-ul" aria-hidden="true"></i> <strong>Quick Navigation</strong></p>
<ul>
<li><a href="#estonia-investment-support">Large-scale investment support expanded</a></li>
<li><a href="#construction-code-reform">Construction procedures became more flexible</a></li>
<li><a href="#ai-act-article-50">AI transparency obligations began to apply</a></li>
<li><a href="#eu-packaging-regulation">New EU packaging rules started to apply</a></li>
<li><a href="#electricity-netting">Electricity billing moves to 15-minute netting</a></li>
<li><a href="#e-commerce-withdrawal-button">E-commerce withdrawal button required from 1 September</a></li>
</ul>
</div>
<h2 id="estonia-investment-support">Large-scale investment support expanded</h2>
<p><strong>Date:</strong> 8 August 2026 | <strong>Source:</strong> Minister of Economic Affairs and Industry Regulation No. 25, Riigi Teataja<br />
<i class="fa fa-external-link"></i> <a href="https://www.riigiteataja.ee/akt/105082026001" target="_blank" rel="noopener" aria-label="Amending regulation in Riigi Teataja, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>Minister of Economic Affairs and Industry Regulation No. 25 of 3 August 2026 amended the conditions for large-scale investment support. The amendment was published on 5 August (RT I, 05.08.2026, 1) and entered into force on 8 August.</p>
<p><strong>Estonia’s large-scale investment support thresholds after the August 2026 amendment:</strong></p>
<ul>
<li><strong>General investment threshold:</strong> lowered from EUR 100 million to EUR 70 million</li>
<li><strong>Priority technology projects:</strong> EUR 35 million, where previously the general EUR 100 million threshold applied</li>
<li><strong>Defense industry projects:</strong> EUR 20 million, where previously the general EUR 100 million threshold applied</li>
<li><strong>Jobs to be created:</strong> at least 20, down from at least 30</li>
</ul>
<p>The thresholds concern eligible project costs. An applicant must be <a href="https://ecovis.lt/practice-areas/company-formation-and-holding-companies-in-estonia/">registered in the Estonian Commercial Register</a>, and may be an Estonian company owned by a foreign investor. Priority projects include strategic digital and net-zero technologies, deep and biotechnology, and food and beverage production.</p>
<p>The grant cap is EUR 20 million per project. The standard maximum intensity is 10%. Up to 15% may apply outside Harju County, the region around Tallinn, where the average gross salary for newly created jobs exceeds 1.5 times the benchmark referred to in <a href="https://eis.ee/wp-content/uploads/2026/08/grant_regulation-6.pdf" target="_blank" rel="noopener" aria-label="EIS translation of the grant regulation, PDF, opens in a new tab">the regulation</a>. Location outside Harju alone does not qualify a project for 15%. Applicable State aid ceilings must also be checked.</p>
<p>Supported project activities must not begin, and commitments for their implementation must not be undertaken, before the application is submitted. Pre-consultation and pre-assessment with the <a href="https://eis.ee/en/services/large-scale-investment-grant/" target="_blank" rel="noopener" aria-label="Estonian Business and Innovation Agency, large-scale investment grant conditions, opens in a new tab">Estonian Business and Innovation Agency (EIS)</a> must be completed before applying. A binding order or investment commitment may therefore jeopardize eligibility even if construction or equipment delivery has not yet started.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>Lower thresholds make Estonia a realistic candidate for medium-sized international industrial projects as well. Grant eligibility, site rights and the order of contract signing should be integrated into one investment plan.</p>
<h3>Recommended actions</h3>
<p>Businesses considering an application should:</p>
<ul>
<li>verify eligible costs, salary conditions and the timing of commitments before applying</li>
<li>complete EIS pre-consultation and pre-assessment before submitting the application</li>
<li>not begin supported activities or undertake binding commitments, including orders, before the application is submitted</li>
<li>check the applicable State aid ceilings</li>
</ul>
<p><strong>Additional sources:</strong> <a href="https://investinestonia.com/estonia-investment-support-threshold/" target="_blank" rel="noopener">Invest Estonia announcement</a></p>
<hr>
<h2 id="construction-code-reform">Construction procedures became more flexible</h2>
<p><strong>Date:</strong> 1 August 2026 | <strong>Source:</strong> Act amending the Building Code and related legislation (RT I, 11.07.2026, 3)<br />
<i class="fa fa-external-link"></i> <a href="https://www.riigiteataja.ee/et/akt/111072026003" target="_blank" rel="noopener" aria-label="Act amending the Building Code in Riigi Teataja, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>The Act amending the Building Code and related legislation reduced procedural burden in several situations. The changes affect both new developments and the reconstruction and regularization of existing buildings, as set out in the <a href="https://kliimaministeerium.ee/uudised/ehitamine-muutub-lihtsamaks" target="_blank" rel="noopener" aria-label="Ministry of Climate explanation of the Building Code reform, opens in a new tab">Ministry of Climate explanation</a>.</p>
<p><strong>What changed on 1 August 2026:</strong></p>
<ul>
<li><strong>Building notice validity:</strong> extended from two to four years, so there is less need to repeat proceedings if construction is delayed</li>
<li><strong>Design conditions (projekteerimistingimused):</strong> their use was expanded, and where permitted, the solution can be refined without amending the detailed plan</li>
<li><strong>Use permits:</strong> a single use-permit application can cover several buildings in the same project, so they can be commissioned together</li>
<li><strong>One- and two-apartment dwellings:</strong> the use permit was replaced by a use notice</li>
<li><strong>Small non-residential buildings and selected structures:</strong> requirements were eased, with the procedure depending on the structure’s size, type and intended use</li>
</ul>
<p>The reform is not a blanket simplification of all construction works. Requirements for a building permit became stricter for certain alterations and extensions of residential buildings with three or more apartments. Project schedules should therefore be based on the procedure applicable to the specific activity, not on the reform’s general purpose.</p>
<p>For buildings constructed before 1 July 2015, regularization continues to focus on safety. Buildings constructed before 22 July 1995 are treated as lawful. The EUR 500 state fee for registering a previously unregistered building was abolished. The publication of personal data in the Building Register was also clarified: personal data may be disclosed only where necessary for the proceedings or to demonstrate compliance.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>The four-year building notice validity gives developers more time to start construction after the notice has been submitted. This can reduce the need to repeat the procedure where a project is delayed.</p>
<p>When acquiring real estate, compare the physical situation with registry data, permits and planning instruments. Simplified procedures may help remedy defects, but the purchase agreement must still allocate responsibility, remediation duties and deadlines clearly. The availability of design conditions does not automatically guarantee the desired development rights.</p>
<h3>Recommended actions</h3>
<p>Developers and buyers should:</p>
<ul>
<li>base project schedules on the procedure applicable to the specific activity</li>
<li>check whether previously unregistered buildings can now be registered, as the EUR 500 state fee was abolished</li>
</ul>
<p><strong>Additional sources:</strong> <a href="https://www.maaruum.ee/uudised/1-augustil-joustuvad-ehitusseadustiku-muudatused-toovad-uuendused-ka-ehitisregistrisse" target="_blank" rel="noopener">Land and Spatial Development Board on Building Register changes</a></p>
<hr>
<h2 id="ai-act-article-50">AI transparency obligations began to apply</h2>
<p><strong>Date:</strong> 2 August 2026 | <strong>Source:</strong> Regulation (EU) 2024/1689 (AI Act), European Commission<br />
<i class="fa fa-external-link"></i> <a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act" target="_blank" rel="noopener" aria-label="Commission FAQ on Article 50 transparency obligations, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>Article 50 of the EU Artificial Intelligence Act applies to certain providers and deployers of AI systems. It is relevant to customer-service chatbots, AI-enabled software, and synthetic marketing or media content.</p>
<p><strong>Who has to do what under Article 50:</strong></p>
<ul>
<li><strong>Provider of an AI system interacting directly with people:</strong> ensure the person is informed that they are interacting with AI, unless this is obvious from the circumstances</li>
<li><strong>Provider of a system generating synthetic content:</strong> ensure machine-readable marking and detectability of AI origin to the applicable extent</li>
<li><strong>Deployer of a deepfake system:</strong> disclose that content was artificially generated or altered, subject to statutory exceptions</li>
<li><strong>Deployer publishing AI text on a matter of public interest:</strong> observe the disclosure duty and the human-review or editorial-control exception</li>
</ul>
<p>The <a href="https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations" target="_blank" rel="noopener" aria-label="Commission guidelines on AI transparency obligations, opens in a new tab">European Commission’s guidance</a> helps define roles, exceptions and practical compliance methods. Neither the guidance nor the <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noopener" aria-label="Code of practice for AI-generated content, opens in a new tab">voluntary code of practice</a> replaces the obligations laid down in the Regulation.</p>
<p>The <a href="https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force" target="_blank" rel="noopener" aria-label="AI Omnibus entry into force, opens in a new tab">AI Omnibus</a>, which entered into force on 27 July 2026, changed the implementation calendar for high-risk systems. Requirements under Annex III of the AI Act apply from 2 December 2027. Requirements for high-risk systems integrated into regulated products under Annex I apply from 2 August 2028. It is therefore inaccurate to say that all high-risk AI requirements applied from 2 August 2026.</p>
<p>Article 50 has its own narrow transition rule. For providers of systems placed on the market before 2 August 2026, the marking and detectability requirements under Article 50(2) must be met from 2 December 2026. This is not a general four-month extension covering all transparency obligations.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>An AI-using business should identify its role for each solution, verify user-facing notices, and agree with its supplier on content marking and the delivery of compliance information. In a technology acquisition, this review should form part of legal due diligence.</p>
<p>A business does not need to build AI to be affected. The duty follows from how a bought chatbot, drafting tool or content generator is used, and a company can be a deployer for one system and a provider for another. The contract should clearly allocate responsibility for marking, detectability and the information needed to demonstrate compliance.</p>
<h3>Recommended actions</h3>
<p>Businesses using or acquiring AI systems should:</p>
<ul>
<li>identify whether each relevant system makes the business a provider or a deployer and which Article 50 obligations apply</li>
<li>review user-facing notices, marking and labeling arrangements, including the 2 December 2026 transition for systems placed on the market before 2 August 2026</li>
<li>allocate compliance responsibilities and access to the required evidence in supplier and technology agreements</li>
</ul>
<hr>
<h2 id="eu-packaging-regulation">New EU packaging rules started to apply</h2>
<p><strong>Date:</strong> 12 August 2026 | <strong>Source:</strong> Regulation (EU) 2025/40 (PPWR), European Commission<br />
<i class="fa fa-external-link"></i> <a href="https://environment.ec.europa.eu/news/new-eu-rules-packaging-enter-application-2026-08-11_en" target="_blank" rel="noopener" aria-label="Commission announcement on new EU packaging rules, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>The new Packaging and Packaging Waste Regulation entered general application on 12 August. It affects packaging manufacturers, importers, food businesses, retailers and e-commerce operators.</p>
<p>One requirement applies already in August. Food-contact packaging may not be placed on the market where its content of per- and polyfluoroalkyl substances (PFAS), the group of persistent chemicals used for grease and water resistance, exceeds the applicable limits. Businesses must be able to assess and demonstrate packaging compliance.</p>
<p>According to the Commission’s <a href="https://environment.ec.europa.eu/document/download/3d59ca88-539c-4b6b-a623-0f61068e853e_en?filename=Annex+to+the+Communication+to+the+Commission.pdf" target="_blank" rel="noopener" aria-label="Commission implementation guidance on the Packaging Regulation, PDF, opens in a new tab">implementation guidance</a>, having produced stock before 12 August does not, by itself, allow packaging that fails the PFAS requirements to be placed on the market later. The production date and the first placing on the market must be distinguished. Packaging placed on the market before 12 August may remain there under the guidance and does not have to be recalled solely because of the new PFAS restriction.</p>
<p>The PPWR did not apply all of its objectives at once in August. Harmonized sorting labels and several recyclability, recycled-plastic, empty-space and reuse requirements take effect in later stages, predominantly from 2028 or 2030, subject to the specific deadlines of each provision.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>The restriction applies at the first placing on the market.</p>
<p>Check packaging composition evidence, supplier confirmations and the timing of placing existing stock on the market. Supply agreements should address compliance documents, packaging replacement and cost allocation. A harmonized EU framework may support investment in compliant packaging and circular-economy solutions.</p>
<h3>Recommended actions</h3>
<p>Businesses placing packaged goods on the market should:</p>
<ul>
<li>distinguish production dates from the first placing on the market when managing existing stock</li>
<li>map which later PPWR requirements, predominantly from 2028 and 2030, affect the product range</li>
</ul>
<hr>
<h2 id="electricity-netting">Electricity billing moves to 15-minute netting</h2>
<p><strong>Date:</strong> 1 August 2026 | <strong>Source:</strong> Electricity Market Act amendment, Elektrilevi<br />
<i class="fa fa-external-link"></i> <a href="https://elektrilevi.ee/en/blogi/mida-tahendab-netomootmine" target="_blank" rel="noopener" aria-label="Elektrilevi explanation of the new netting method, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>At consumption points with a bidirectional meter, grid and electricity bills are based on the difference between electricity taken from and fed into the grid during each 15-minute trading period. For example, 4 kWh taken from the grid and 3 kWh fed into it result in net consumption of 1 kWh for that period. This is not monthly or annual netting.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>The effect depends on the timing overlap between generation and consumption, so identical savings cannot be assumed for every producer. For businesses with on-site generation, the new methodology feeds directly into project economics.</p>
<h3>Recommended actions</h3>
<p>Businesses with on-site generation should:</p>
<ul>
<li>check their August billing under the new methodology</li>
<li>update project economics using actual 15-minute data rather than monthly totals</li>
</ul>
<p><strong>Additional sources:</strong> <a href="https://lounaeestlane.ee/elektrit-tootvate-tarbijate-elektriarvestus-muutub-oiglasemaks/" target="_blank" rel="noopener">Lõuna-Eestlane overview</a></p>
<hr>
<h2 id="e-commerce-withdrawal-button">E-commerce withdrawal button required from 1 September</h2>
<p><strong>Date:</strong> 1 September 2026 | <strong>Source:</strong> Consumer Protection and Technical Regulatory Authority (TTJA)<br />
<i class="fa fa-external-link"></i> <a href="https://ttja.ee/ariklient/ettevotlus/tarbijakaitsenouded-tegevusalale/e-kaubandus" target="_blank" rel="noopener" aria-label="TTJA e-commerce requirements for traders, opens in a new tab">Link</a></p>
<h3>What happened?</h3>
<p>From 1 September 2026, an online trader must enable consumers to submit a withdrawal statement through a clearly visible withdrawal button or an equivalent function. The Consumer Protection and Technical Regulatory Authority highlighted the need to prepare for this at the end of August.</p>
<p>The solution must allow the consumer and the contract to be identified, confirm submission of the withdrawal statement, and immediately send an acknowledgement on a durable medium stating the content and time of submission.</p>
<h3>Why does it matter for businesses and investors?</h3>
<p>The requirement covers more than the button itself: identification, confirmation and the durable-medium acknowledgement all have to work end to end.</p>
<h3>Recommended actions</h3>
<p>Online traders should:</p>
<ul>
<li>implement the withdrawal button or an equivalent clearly visible function</li>
<li>ensure the solution identifies the consumer and the contract, confirms submission, and immediately sends an acknowledgement on a durable medium with the content and time of submission</li>
<li>test the entire workflow from button to acknowledgement, on a real order</li>
</ul>
<p><strong>Additional sources:</strong> <a href="https://www.ttja.ee/eraklient/tarbija-oigused/kaubandus/ostmine-e-poest" target="_blank" rel="noopener">TTJA guidance for consumers</a></p>
<hr>
<h2>What international investors should take from August</h2>
<p>The strongest combined effect of the August changes is on industrial and technology investments: a lower support threshold may improve financing, the construction reform may facilitate delivery, and the new electricity methodology may change the economics of on-site generation. The impact must be assessed project by project.</p>
<p>Large-scale investment support does not replace <a href="https://ttja.ee/ariklient/ettevotlus/valisinvesteeringu-hindamine" target="_blank" rel="noopener" aria-label="TTJA foreign investment screening, opens in a new tab">foreign investment clearance</a>. Under the existing framework, an investor from a third country may require clearance for an investment in a designated target undertaking, and a company established in the EU but controlled by a third-country person may also qualify as a foreign investor. The regime covers, among other things, the acquisition of significant participation or control and certain asset transactions. This is an existing framework, not a new August requirement.</p>
<p>Four checks for management:</p>
<ul>
<li><strong>Investment project:</strong> verify eligible costs, salary conditions and the timing of commitments before applying</li>
<li><strong>Real estate:</strong> update the permit schedule and check consistency between the physical building and registry documents</li>
<li><strong>AI and packaging:</strong> assign responsibility, identify applicable requirements and collect supplier evidence</li>
<li><strong>Energy and e-commerce:</strong> verify the new billing method and the actual operation of the withdrawal function</li>
</ul>
<hr>
<h2>How ProventusLaw can help</h2>
<p>ProventusLaw advises businesses and international investors on entering the Estonian market, structuring investments and transactions, including through <a href="https://ecovis.lt/fintech/investment-funds-estonia/">Estonian investment funds</a>, assessing support conditions and clearance requirements, and on corporate, construction, tax and technology law. Cross-border projects can be coordinated across the Baltics and through the ECOVIS network.</p>
<p>If an investment, development or compliance question in Estonia touches your plans, our team can help you assess it before binding commitments are made.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-legal-and-investment-update-in-estonia-september-2026/">RegRally Insights: Legal and Investment Update in Estonia, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Employment &#038; Migration Law Updates, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-employment-migration-law-updates-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 10:01:44 +0000</pubDate>
				<category><![CDATA[Employment & Migration]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=12022</guid>

					<description><![CDATA[<p>Employment law is moving beyond traditional HR compliance. Recent developments show a clear shift towards closer scrutiny of how employers manage disputes, remote and cross-border work, workplace risks, and increasingly technology-driven employment practices.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-employment-migration-law-updates-september-2026/">RegRally Insights: Employment &#038; Migration Law Updates, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>By 31 December 2026, every employer in Lithuania, from a three-person office to the largest group, must have a pay structure that groups positions by objective and gender-neutral criteria. The reporting rules will apply from 2027, with pay data submitted to Sodra monthly, and employees will be able to ask for their category’s numbers.</p>
<p>This edition also covers the State Labour Inspectorate’s reminder that violence and harassment prevention duties adopted three years ago are still not implemented everywhere, and an EU case on dress codes that any employer with a uniform or appearance policy will want to watch.</p>
<p>The September edition of RegRally covers the month’s <a href="https://ecovis.lt/practice-areas/labour-law/" target="_blank" rel="noopener">employment law</a> developments for employers, HR teams and in-house lawyers working in Lithuania.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Pay structure deadline:</strong> by 31 December 2026, all employers, irrespective of size, sector or nature of activities, must approve or review their pay structure (darbo apmokėjimo sistema, DAS) under Article 140(3) of the Labour Code, grouping positions by objective and gender-neutral criteria.</li>
<li><strong>Pay transparency reporting:</strong> Order No A1-433 sets up the Pay Transparency Notification (Form SDUP), submitted to Sodra monthly via EDAS. The first form is due by 28 February 2027 for January 2027, and from 1 March 2027 employees may request their own and their category’s monthly indicators.</li>
<li><strong>Violence and harassment:</strong> a VDI survey of nearly 300 employers found that some have still not implemented obligations that have been mandatory for over three years, from conduct rules and a named contact person to training every three years.</li>
<li><strong>EU case law:</strong> Advocate General Ćapeta considers that a tattoo ban combined with a skirt requirement for women’s ceremonial uniforms amounts to direct sex discrimination. The Court’s judgment will follow.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#pay-structure-deadline-31-december-2026">All employers must have a compliant pay structure by 31 December 2026</a></li>
<li><a href="#order-a1-433-pay-transparency-sdup">Pay transparency reporting takes shape: Form SDUP goes to Sodra monthly from 2027</a></li>
<li><a href="#vdi-violence-harassment-prevention-survey">VDI: some employers still have not implemented mandatory violence and harassment prevention</a></li>
<li><a href="#ag-opinion-tattoo-uniform-sex-discrimination">Advocate General: a tattoo ban plus a skirt requirement can amount to sex discrimination</a></li>
</ul>
</div>
<h2 id="pay-structure-deadline-31-december-2026">All employers must have a compliant pay structure by 31 December 2026</h2>
<p><strong>Source:</strong> Labour Code, Article 140(3) | <strong>Deadline:</strong> 31 December 2026<br /><i class="fa fa-external-link"></i><a href="https://vdi.lrv.lt/lt/skaidrus-darbo-uzmokestis/duk/" target="_blank" rel="noopener"> Link</a> | <a href="https://ecovis.lt/es-darbo-uzmokescio-skaidrumo-direktyvos-igyvendinimas-lietuvoje-planai-ir-kaip-pasiruosti/" target="_blank" rel="noopener">Our overview of the Pay Transparency Directive implementation in Lithuania</a></p>
<h3>What happened?</h3>
<p><strong>31 December 2026</strong> is the deadline for employers to approve, or review and, where necessary, amend the pay structure (darbo apmokėjimo sistema, DAS) under Article 140 of the Labour Code and Article 23(4) of Law No XV-969. By that date, <strong>all employers, irrespective of their size, sector or nature of activities</strong>, must have objective and gender-neutral pay systems ensuring employees’ right to fair remuneration.</p>
<p>The pay structure will be mandatory for all employers and must be made available to all employees. Before approving or amending it, the employer must complete the information and consultation procedures required under the Labour Code.</p>
<p>The pay structure must group positions according to objective and gender-neutral criteria and set out the forms of pay, salary amounts or ranges, rules for additional remuneration, allowances and bonuses, and the criteria and procedure for salary indexation and increases. Employers with fewer than 50 employees are exempt from the obligation to set salary increase criteria and procedure.</p>
<p>Positions involving the same work or work of equal value must be assigned to the same position group, and equal pay must be ensured for men and women performing the same or equal-value work.</p>
<h3>Why does it matter for employers?</h3>
<p>There is no small-company exception. A business with three employees needs a pay structure by the same date as a group with three thousand.</p>
<p>The grouping decisions made now will carry forward. The same position categories will be used for pay transparency reporting from 2027, so inconsistencies in the grouping will carry into the reported data.</p>
<h3>Recommended actions</h3>
<p>Employers should:</p>
<ul>
<li>complete the preparation or review of their pay structure by 31 December 2026 and ensure that all positions are grouped using objective and gender-neutral criteria in line with Article 140(3) of the Labour Code</li>
<li>map all existing roles against the pay structure and assign each employee to the appropriate position group</li>
<li>check whether information and consultation procedures are required before approval or amendment</li>
<li>align the internal categories with the categories that will later be used for pay transparency reporting</li>
</ul>
<hr />
<h2 id="order-a1-433-pay-transparency-sdup">Pay transparency reporting takes shape: Form SDUP goes to Sodra monthly from 2027</h2>
<p><strong>Source:</strong> Ministry of Social Security and Labour (SADM), Order No A1-433 | <strong>Date:</strong> 17 July 2026, in force from 31 July 2026<br /><i class="fa fa-external-link"></i><a href="https://www.e-tar.lt/portal/lt/legalAct/3e5324a481c611f1a2d8bd5283b9c6f3" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>SADM adopted <strong>Order No A1-433</strong> of 17 July 2026 approving the Procedure for the collection and publication of information on employees for the purpose of implementing their right to fair remuneration and for the joint pay assessment. The Order is the implementing measure for the pay transparency amendments to the Labour Code (Law No XV-969 of 21 May 2026, transposing Directive (EU) 2023/970).</p>
<p>The Procedure introduces the <strong>Pay Transparency Notification (Form SDUP)</strong>, submitted monthly to Sodra via EDAS by the last day of the month for the preceding month. It defines the key data concepts: the category of workers (grouped under the objective, gender-neutral criteria of Article 140(3) of the Labour Code and denoted by its number in the pay structure), gross monthly pay, gross complementary pay and paid working time.</p>
<p>The Order sets out the full methodology by which Sodra calculates average hourly pay, pay gaps, medians and quartiles, returns monthly indicators by the 15th day of the month and annual indicators, and lists the additional data required when the form is completed for the first time.</p>
<p>Key dates: the first Form SDUP is due by <strong>28 February 2027</strong> for January 2027. From <strong>1 March 2027</strong>, an employee may request their own and their category’s monthly indicators, earlier than the annual indicators, which apply from 2028 for employers with 150 or more insured employees and from 2031 for those with 100 to 149.</p>
<p>Chapter VIII sets out the <strong>joint pay assessment</strong> procedure, which applies where an unjustified pay gap of <strong>5% or more</strong> within a category of workers is not remedied within six months. Temporary employment agencies do not receive Sodra indicators but must calculate them themselves and submit Form SDUP by 1 March.</p>
<h3>Why does it matter for employers?</h3>
<p>Pay transparency is now a monthly payroll obligation with fixed dates and a defined data format.</p>
<p>From 1 March 2027, employees can request their own and their category’s monthly indicators, well before any annual indicators are published. And a gap of 5% or more within a category that stays unjustified for six months triggers a joint pay assessment.</p>
<h3>Recommended actions</h3>
<p>Employers should:</p>
<ul>
<li>prepare in advance for the new monthly data reporting obligation and the new employee category requirement</li>
<li>review the pay structure, assign all positions to objective and gender-neutral categories, and ensure the internal categories correspond to the data that will have to be submitted in Form SDUP via EDAS</li>
<li>map existing roles against the pay structure and confirm each employee’s category before the first reporting period, so the payroll team can generate consistent monthly data for submission to Sodra</li>
</ul>
<hr />
<h2 id="vdi-violence-harassment-prevention-survey">VDI: some employers still have not implemented mandatory violence and harassment prevention</h2>
<p><strong>Source:</strong> State Labour Inspectorate (VDI) | <strong>Date:</strong> 26 August 2026<br /><i class="fa fa-external-link"></i><a href="https://vdi.lrv.lt/lt/naujienos/vdi-apklausa-atskleide-dalis-darbdaviu-vis-dar-neigyvendino-privalomu-smurto-ir-priekabiavimo-prevencijos-priemoniu-SkL" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>VDI published the results of an anonymous survey of nearly <strong>300 employers</strong> conducted in May 2026. The finding: although employers take violence and harassment prevention seriously, a number have still not implemented obligations that have been <strong>mandatory for over three years</strong>.</p>
<p>All employers, regardless of size, must comply with <strong>Article 30 of the Labour Code</strong> and the Violence and Harassment Prevention Measures Regulation: declare the prohibition of violence and harassment, adopt conduct and ethics rules, designate a responsible contact person, establish complaint reporting and investigation procedures, provide legal and emotional support to affected employees, and organise mandatory training every three years.</p>
<p>Employers with <strong>50 or more employees</strong> must additionally adopt a formal prevention policy covering identification, complaint handling, protective measures and conduct standards. VDI expects employers to move beyond documentation: to carry out psychosocial risk assessments, monitor whether the measures actually work, and handle every complaint seriously and promptly.</p>
<h3>Why does it matter for employers?</h3>
<p>These duties have been mandatory for over three years, and VDI expects more than documentation. Employers should be able to show that the training cycle ran, the risk assessment was done and complaints were actually investigated.</p>
<h3>Recommended actions</h3>
<p>Employers should:</p>
<ul>
<li>verify the Article 30 package is in place and current: prohibition declaration, conduct rules, named contact person, complaint procedure and support arrangements</li>
<li>check the three-year training cycle has not lapsed, and that employers with 50 or more staff have the formal prevention policy adopted</li>
<li>document the psychosocial risk assessment and keep evidence that the measures are monitored, not merely adopted on paper</li>
</ul>
<hr />
<h2 id="ag-opinion-tattoo-uniform-sex-discrimination">Advocate General: a tattoo ban plus a skirt requirement can amount to sex discrimination</h2>
<p><strong>Source:</strong> Advocate General’s Opinion, Case C-320/25 (Lertimene) | <strong>Date:</strong> 3 September 2026<br /><i class="fa fa-external-link"></i><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-09/cp260118en.pdf" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>Advocate General Tamara Ćapeta delivered her Opinion in Case C-320/25 (fictitious name “Lertimene”), concerning a candidate excluded from Italian police recruitment because a small tattoo on her calf would have been visible under the women’s ceremonial uniform, a skirt and court shoes. Male candidates with tattoos in the same location were not excluded, because the men’s ceremonial uniform, trousers, would not reveal it.</p>
<p>The Advocate General took the view that the combined application of the tattoo ban and the requirement for women to wear a skirt at ceremonies amounts to <strong>direct discrimination on grounds of sex</strong> under the Equal Treatment Directive (2006/54/EC): had the candidate been a man, the same tattoo would not have led to exclusion.</p>
<p>She further considered that this could not be justified as a “genuine and determining occupational requirement”, since ceremonial duties make up only a small part of police work, female officers already wear trousers as part of their standard operational uniform, and senior officers could in any event authorise a female officer to wear trousers at a given ceremony. The Opinion is not binding on the Court, which will now deliberate and deliver judgment at a later date.</p>
<h3>Why does it matter for employers?</h3>
<p>A rule that is neutral on paper, here a tattoo ban applied to everyone, can become discriminatory when combined with another rule that in practice affects only one sex. The same logic applies to any dress code, uniform or appearance policy.</p>
<p>Tradition and organisational identity did not carry the justification here, which is worth remembering for any employer defending a differentiated appearance rule.</p>
<h3>Recommended actions</h3>
<p>Employers with dress codes, uniform policies or appearance requirements, including public-sector and uniformed employers, should:</p>
<ul>
<li>review whether any appearance or uniform rule, even if facially neutral, has a different practical effect on men and women, for example a rule that only bites for one gender’s mandated clothing</li>
<li>be cautious about justifying differentiated appearance rules by reference to tradition or organisational identity alone, since the Advocate General found such justifications insufficient where the practical impact falls disproportionately on one sex</li>
<li>watch for the Court’s final judgment, since it will clarify how far “genuine occupational requirement” justifications can stretch to cover appearance and uniform policies EU-wide</li>
</ul>
<hr />
<h2>What should employers take away?</h2>
<p>The pay transparency requirements arrive in sequence: the pay structure by 31 December 2026, the first Form SDUP for January 2027 by 28 February 2027, monthly reporting after that, and employee access to the indicators from 1 March 2027. The reporting will use the categories set in the pay structure, and an unjustified pay gap of 5% or more that is not remedied within six months leads to a joint pay assessment.</p>
<p>On violence and harassment, employers should ensure that the Article 30 package is in place and current, the three-year training cycle has not lapsed, the formal prevention policy is adopted where the company has 50 or more staff, and the psychosocial risk assessment is documented with evidence that the measures are monitored, not merely adopted on paper.</p>
<hr />
<h2>How ECOVIS ProventusLaw can help employers</h2>
<p>Our <a href="https://ecovis.lt/practice-areas/labour-law/" target="_blank" rel="noopener">Employment &#038; Migration team</a> helps employers in Lithuania with:</p>
<ul>
<li>preparing or reviewing the pay structure under Article 140(3) and setting up Form SDUP reporting with payroll and HR</li>
<li>checking employment practices against the Labour Code and identifying compliance gaps</li>
<li>drafting and updating employment contracts, internal policies and other HR documents</li>
<li>internal workplace investigations and disciplinary matters</li>
<li>planning collective redundancies, reorganisations and business transfers</li>
<li>executive contracts, exits and settlement agreements</li>
<li>working time, pay and benefits questions, including the new pay transparency requirements</li>
<li>occupational safety and health duties, including violence and harassment prevention</li>
<li>representing employers in labour disputes and during regulatory investigations and VDI inspections</li>
<li>employee data protection and workplace privacy</li>
</ul>
<p>If you have questions about the 31 December deadline, SDUP reporting, the prevention obligations or any other topic in this edition, our team will be happy to assist.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-employment-migration-law-updates-september-2026/">RegRally Insights: Employment &#038; Migration Law Updates, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Payment Services Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-payment-services-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 15:01:17 +0000</pubDate>
				<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=12015</guid>

					<description><![CDATA[<p>The Bank of Lithuania set the tone. It restricted an electronic money institution over capital and shareholder-lending failures before any final decision, opened a consultation on how fines are calculated and when a breach counts as minor, and a draft law would let newly established financial institutions open their capital accumulation account at a payment or e-money institution instead of a bank.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-payment-services-regulation-september-2026/">RegRally Insights: Payment Services Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The Bank of Lithuania set the tone in August. It restricted an electronic money institution over capital and shareholder-lending failures before any final decision, opened a consultation on how fines are calculated and when a breach counts as minor, and a draft law would let newly established financial institutions open their capital accumulation account at a payment or e-money institution instead of a bank.</p>
<p>At EU level, the new Anti-Money Laundering Authority (AMLA) is reaching <a href="https://ecovis.lt/fintech/payment-institutions/">payment institutions (PIs)</a> and <a href="https://ecovis.lt/fintech/e-money-institutions/">electronic money institutions (EMIs)</a> directly, through the eligibility data collection that will decide who faces direct supervision and a survey on Central Contact Points. The September edition of RegRally covers what this means for PIs, EMIs and fintech groups in the Baltics and across the EU.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Lithuania enforcement:</strong> following an inspection, the Bank of Lithuania ordered EMI Verified Payments to restore capital adequacy by 1 October 2026 and, pending a separate decision, prohibited it from taking on new clients, encumbering assets and lending. The same bulletin licensed crowdfunding provider Finance EU (brand Florrid), Lithuania’s 16th, placing the country fifth in the EU.</li>
<li><strong>Lithuania sanctions methodology:</strong> draft amendments to the fine-calculation procedure and the minor-breach criteria are on public consultation, going directly to the amount of supervisory fines and the threshold for escalation. The industry association filed a joint position in August.</li>
<li><strong>Lithuania draft law:</strong> amendments to the Law on Financial Institutions would extend the shareholder-meeting deadline for approving annual accounts from 3 to 5 months and allow initial share capital to be deposited in an accumulation account at a licensed EMI or PI, not only a credit institution.</li>
<li><strong>AMLA direct supervision:</strong> the European Banking Authority (EBA) published the draft reporting framework for the 2027 eligibility data collection that will determine selection for AMLA direct supervision. PIs and EMIs are within the reporting population, with 31 December 2026 as the reference date.</li>
<li><strong>Passporting:</strong> AMLA surveyed payment service providers and EMIs operating through agents and distributors on Central Contact Points until 15 September 2026, feeding technical standards that will determine when a host state may require a CCP.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#bank-of-lithuania-verified-payments-finance-eu">Bank of Lithuania restricts EMI Verified Payments and licenses crowdfunding provider Finance EU</a></li>
<li><a href="#bank-of-lithuania-fines-minor-breach-consultation">Bank of Lithuania consults on how fines are calculated and when breaches count as minor</a></li>
<li><a href="#draft-law-financial-institutions-articles-27-43">Draft law would ease incorporation and reporting deadlines for financial institutions</a></li>
<li><a href="#eba-amla-eligibility-reporting-pis-emis">AMLA’s 2027 eligibility data collection includes PIs and EMIs</a></li>
<li><a href="#amla-ccp-survey-passporting">AMLA’s Central Contact Point survey goes to the heart of the passported PI and EMI model</a></li>
</ul>
</div>
<h2 id="bank-of-lithuania-verified-payments-finance-eu">Bank of Lithuania restricts EMI Verified Payments and licenses crowdfunding provider Finance EU</h2>
<p><strong>Date:</strong> 5 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania)<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/finansu-rinkos-prieziuros-komiteto-sprendimai-28" target="_blank" rel="noopener" aria-label="Bank of Lithuania decisions bulletin, opens in a new tab"> Link</a></p>
<h3>What happened?</h3>
<p>The Financial Market Supervision Committee decisions bulletin of 5 August contained two decisions: supervisory instructions to an electronic money institution and a new crowdfunding license.</p>
<p>Following an inspection of <strong>Verified Payments, UAB</strong>, the Bank of Lithuania found the institution had failed to comply with the own funds (capital adequacy) requirement for a significant part of the inspected period, and that the breach remains unremedied. The institution had systematically granted significant loans to its shareholder for personal needs without applying effective credit risk management, and the inspection identified circumstances casting reasonable doubt on the sole shareholder’s financial capacity to ensure sound and financially sustainable management.</p>
<p>Without waiting for a final decision, and to protect clients’ interests immediately, the Bank of Lithuania ordered the institution to restore capital adequacy by <strong>1 October 2026</strong>, to prepare and implement a plan acceptable to the supervisor for resolving shareholder-related issues, to report capital adequacy and financial data more frequently, and to notify the Bank of Lithuania in advance of any planned capital-increase actions and not carry them out until it raises no objection. Pending a separate decision, the institution is prohibited from establishing business relationships with new clients, providing them payment services or issuing electronic money, encumbering its financial assets, securing other persons’ obligations and lending its own funds.</p>
<p>In the same bulletin, a <a href="https://ecovis.lt/fintech/crowdfunding/">crowdfunding service provider license</a> was granted to UAB “Finance EU”, which under the brand <strong>Florrid</strong> intends to offer investment in crowdfunding projects secured by real estate. The Bank of Lithuania noted that 16 companies now hold such licenses in Lithuania, placing the country fifth in the European Union by that measure.</p>
<h3>Why it matters for payment institutions and EMIs</h3>
<p>The case shows how much can happen before any final decision. Supervisory doubt about the shareholder alone, combined with an unremedied capital breach, was enough for a new-client ban, asset restrictions and a lending prohibition, all as interim measures.</p>
<p>It also puts related-party lending squarely on the supervisory map. Loans to a shareholder for personal needs, without credit risk management, read as a capital problem and a governance problem at once.</p>
<h3>Recommended actions</h3>
<p>EMIs and payment institutions should:</p>
<ul>
<li>be able to evidence continuous compliance with the own funds requirement between reporting dates, not only at period end</li>
<li>treat related-party (shareholder) lending as a high-risk area governed by credit-risk policy, arm’s-length terms and documented approval, since it was central to this case</li>
<li>ensure the financial capacity and suitability of shareholders can be substantiated, since supervisory doubt on this point alone can trigger a new-client ban and asset restrictions as interim measures</li>
<li>monitor the institution’s communications and consider concentration risk (clients holding balances with a restricted EMI)</li>
<li>note the increasingly competitive Lithuanian licensed population (prospective crowdfunding applicants)</li>
</ul>
<hr />
<h2 id="bank-of-lithuania-fines-minor-breach-consultation">Bank of Lithuania consults on how fines are calculated and when breaches count as minor</h2>
<p><strong>Date:</strong> August 2026 | <strong>Source:</strong> Lietuvos bankas (draft Board resolutions, public consultation)</p>
<h3>What happened?</h3>
<p>The Bank of Lithuania placed on public consultation draft amendments to two enforcement instruments: the Procedure for the Calculation of Fines and the Procedure for Determining When a Breach of a Legal Act Is Considered Minor.</p>
<p>Together these determine how the supervisor sets the amount of a fine and when it may treat a breach as minor and refrain from imposing an enforcement measure. The amendments therefore go directly to the quantum of supervisory sanctions and the threshold for escalation. The consultation attracted sector comments, including a joint position submitted by the industry association in August 2026.</p>
<h3>Why it matters for payment institutions and EMIs</h3>
<p>This is the math behind every future enforcement case. How a fine is calculated, and where the minor-breach line sits, changes both the realistic exposure of any finding and the calculus around self-reporting.</p>
<h3>Recommended actions</h3>
<p>Supervised entities should:</p>
<ul>
<li>review the draft methodology now and model its effect on realistic fine exposure, rather than waiting for the final resolutions</li>
<li>reassess internal breach-classification and self-reporting practice against the revised minor-breach criteria</li>
<li>consider responding to the consultation, individually or through an association, while the calculation methodology is still open</li>
</ul>
<hr />
<h2 id="draft-law-financial-institutions-articles-27-43">Draft law would ease incorporation and reporting deadlines for financial institutions</h2>
<p><strong>Date:</strong> 3 August 2026 | <strong>Source:</strong> Ministry of Finance / Government of the Republic of Lithuania<br /><i class="fa fa-external-link"></i><a href="https://e-seimas.lrs.lt/portal/legalAct/lt/TAP/a6bf7a808efe11f1bf37e5db4f3861c1" target="_blank" rel="noopener" aria-label="Draft law on the Seimas legal acts portal, opens in a new tab"> Link</a></p>
<h3>What happened?</h3>
<p>A draft law amending Articles 27 and 43 of the Law on Financial Institutions (No. IX-1068) was registered on 3 August 2026 (project No. 26-10473), prepared by the Ministry of Finance and submitted to the Seimas by the Government. Consultation with institutions and the public ran from 3 to 17 August 2026.</p>
<p>If adopted, two changes follow. The deadline for the general meeting of shareholders to approve annual financial statements and decide on profit distribution would be extended from <strong>3 to 5 months</strong> after the financial year end, aligning it with the Law on Companies. And newly established financial institutions would be able to deposit initial share capital into an <strong>accumulation account</strong> held not only with a credit institution but also with an electronic money institution or payment institution licensed in Lithuania, again aligning with the Law on Companies and adding flexibility on incorporation.</p>
<h3>Why it matters for payment institutions and EMIs</h3>
<p>The accumulation-account change removes a practical bottleneck: today, setting up a financial institution depends on a bank agreeing to open the capital account. If the amendment passes, licensed EMIs and PIs can be on the other side of that service.</p>
<h3>Recommended actions</h3>
<p>Financial institutions should:</p>
<ul>
<li>note the prospective 5-month approval deadline when planning the 2026 annual accounts and profit-distribution timetable</li>
<li>track adoption when advising on or setting up new financial institutions, since the accumulation-account change removes the practical dependence on a bank at incorporation</li>
<li>assess the commercial opportunity in offering accumulation accounts if the amendment passes (licensed EMIs and PIs)</li>
</ul>
<hr />
<h2 id="eba-amla-eligibility-reporting-pis-emis">AMLA’s 2027 eligibility data collection includes PIs and EMIs</h2>
<p><strong>Date:</strong> 4 August 2026 | <strong>Source:</strong> EBA (European Banking Authority)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/news-media/news-articles/eba-publishes-draft-reporting-framework-2027-eligibility-data-collection_en" target="_blank" rel="noopener" aria-label="EBA reporting framework announcement on the AMLA website, opens in a new tab"> Link</a></p>
<h3>What happened?</h3>
<p>The EBA published, as part of release 4.4 of its reporting framework, a public working draft of the data model and taxonomy that will support the 2027 eligibility data collection underpinning AMLA’s first selection of institutions for direct supervision. Credit and financial institutions fall within the population that must report, including payment institutions and electronic money institutions.</p>
<p>For PIs and EMIs this introduces a concrete reporting exercise. Data gathered in early 2027 will confirm whether provisionally eligible entities still meet the criteria as of <strong>31 December 2026</strong>, with the prospect of EU-level direct supervision from 2028. The consultation on the draft closed on 24 August 2026.</p>
<h3>Why it matters for payment institutions and EMIs</h3>
<p>For PI and EMI reporting teams this is a data exercise with templates, a taxonomy and a fixed reference date. The data reported in early 2027 will reflect a position that is being fixed now, against the 31 December 2026 reference date.</p>
<h3>Recommended actions</h3>
<p>PI and EMI compliance and reporting teams should:</p>
<ul>
<li>scope the reporting obligation and prepare the underlying data against the draft templates</li>
<li>monitor the final eligibility criteria and thresholds</li>
<li>assess governance readiness for potential AMLA direct supervision</li>
</ul>
<hr />
<h2 id="amla-ccp-survey-passporting">AMLA’s Central Contact Point survey goes to the heart of the passported PI and EMI model</h2>
<p><strong>Date:</strong> 6 August 2026 | <strong>Source:</strong> AMLA (Authority for Anti-Money Laundering and Countering the Financing of Terrorism)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/news-media/news-articles/amla-launches-survey-central-contact-points_en" target="_blank" rel="noopener" aria-label="AMLA Central Contact Point survey announcement, opens in a new tab"> Link</a></p>
<h3>What happened?</h3>
<p>AMLA launched a survey on Central Contact Points (CCPs) directed at payment service providers and electronic money institutions that operate in host Member States through agents and distributors, drawing on Article 45(9) of the Anti-Money Laundering Directive (AMLD) and Delegated Regulation (EU) 2018/1108.</p>
<p>The initiative feeds regulatory technical standards (RTS) under Article 41(2) of the AMLD, determining when a host authority may require a CCP and what its functions are. That is a core operating-model question for passported PI and EMI activity, since a CCP obligation affects local representation, governance and AML/CFT accountability in each host market.</p>
<p>The survey closed on <strong>15 September 2026</strong>. Crypto-asset service providers are outside its scope.</p>
<h3>Why it matters for payment institutions and EMIs</h3>
<p>For an institution passporting through agents and distributors, CCP rules decide how much local substance each host market demands. The future RTS will standardize that answer across the EU, and the survey is where the practical input went in.</p>
<h3>Recommended actions</h3>
<p>PIs and EMIs with agent or distributor networks should:</p>
<ul>
<li>map host-state CCP requirements against current agent and distributor arrangements</li>
<li>factor potential CCP obligations into passporting strategy, local-representation and governance arrangements</li>
<li>track the resulting Article 41(2) RTS, which may standardize CCP requirements across the EU</li>
</ul>
<hr />
<h2>Key takeaways for payment institutions and EMIs</h2>
<p>Verified Payments is the case to read closely. Own funds compliance is continuous, shareholder lending is a supervisory topic, and doubt about the shareholder alone can freeze a business through interim measures long before any final decision.</p>
<p>The domestic rulebook is moving too. The fine-calculation methodology and the minor-breach threshold are open for consultation, and the draft law on accumulation accounts would turn EMIs and PIs from bank-dependent applicants into providers of the incorporation service themselves. Both are worth engaging with while they are still drafts.</p>
<p>And AMLA now reaches PIs and EMIs directly. The eligibility reporting exercise fixes positions against 31 December 2026, and the Central Contact Point survey, closed on 15 September, will feed the standards on how much local substance passported models need in each host market.</p>
<hr />
<h2>How ECOVIS ProventusLaw can help payment institutions and EMIs</h2>
<p>Our payments team supports PIs, EMIs and fintech groups across the Baltics with <a href="https://ecovis.lt/fintech/">fintech and financial institution licensing in the EU</a>, including:</p>
<ul>
<li>PI and EMI license applications and authorization strategy</li>
<li>own funds, safeguarding and prudential compliance questions</li>
<li>responding to inspections, supervisory instructions and enforcement</li>
<li>shareholder suitability, qualifying holdings and changes of control</li>
<li>passporting, agent and distributor networks, and Central Contact Point questions</li>
<li>AML/CTF frameworks and AMLA readiness</li>
<li>wind-down planning and regulatory reporting</li>
<li>consultations and dialogue with financial supervisors</li>
</ul>
<p>If a supervisory instruction, a capital question or an AMLA reporting obligation has landed on your desk, we can help you respond with a plan the regulator will accept.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-payment-services-regulation-september-2026/">RegRally Insights: Payment Services Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Crypto &#038; Investments Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-crypto-investments-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 11:44:53 +0000</pubDate>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=12004</guid>

					<description><![CDATA[<p>The September edition of RegRally is for crypto-asset service providers (CASPs), investment firms, fund managers and crowdfunding platforms operating in the Baltics and across the EU. The SEC proposes Regulation Crypto Assets, and the Bank of Lithuania grants new AIFM and brokerage licences. What crypto and investment firms should do now.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-crypto-investments-regulation-september-2026/">RegRally Insights: Crypto &#038; Investments Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>In August the SEC proposed “Regulation Crypto Assets”, a tailored US securities-law framework for certain investment contracts involving crypto assets, which firms authorized under the EU’s <a href="https://ecovis.lt/fintech/crypto-currency-exchange-license/">Markets in Crypto-Assets Regulation (MiCA)</a> will need to read alongside their existing obligations. In Lithuania, the Bank of Lithuania granted new investment licenses and set out how far a crowdfunding platform’s bulletin board can go before it raises a trading-venue question. At EU level, the EBA opened a consultation on the EUR 30 billion threshold at which <a href="https://ecovis.lt/fintech/mifid-license/">investment firms</a> become credit institutions, the ESAs moved to simplify initial margin rules for counterparties below the EUR 8 billion threshold, and weekly commodity derivatives position reporting went live on 3 September.</p>
<p>This September edition of RegRally is for crypto-asset service providers (CASPs), investment firms, fund managers and crowdfunding platforms operating in the Baltics and across the EU.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Lithuania licensing:</strong> Evernord Asset Management was licensed as a management company of alternative collective investment undertakings, covering informed-investor funds, UCITS, real-estate funds and portfolio management. Nasdaq Vilnius rule amendments took effect on 1 September, with the Auction Volume Discovery (AVD) order rolling out across the Baltic markets in stages from 21 September.</li>
<li><strong>Lithuania supervision:</strong> Aria Securities received a Category C brokerage license structured without holding client funds or financial instruments. FinoMark’s crowdfunding license was supplemented with a strictly non-matching bulletin board, and the 2026 inspection plan was adjusted for two payment sector firms.</li>
<li><strong>United States:</strong> the SEC proposed Regulation Crypto Assets, with two registration exemptions (USD 5 million once over four years, and USD 75 million per 12-month period), a conditional safe harbor from the “investment contract” definition, and preemption of state registration requirements. Comments close on 20 October 2026.</li>
<li><strong>Prudential:</strong> the EBA is consulting on three draft technical standards on the EUR 30 billion reclassification threshold, related reporting from EUR 5 billion, and, for the first time, the factors competent authorities must consider when deciding whether to grant a waiver. Registration for the 30 September hearing closes on 25 September; comments close on 25 November 2026.</li>
<li><strong>Derivatives and markets:</strong> the ESAs proposed removing initial margin exchange for counterparties below the EUR 8 billion threshold on both new and existing uncleared OTC contracts, and weekly commodity derivatives position reporting went live on 3 September under XML schema v2.0.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#bank-of-lithuania-evernord-nasdaq-vilnius">Bank of Lithuania licenses Evernord Asset Management and approves Nasdaq Vilnius rule changes</a></li>
<li><a href="#bank-of-lithuania-aria-securities-finomark">Bank of Lithuania licenses Aria Securities and expands FinoMark’s crowdfunding permissions</a></li>
<li><a href="#sec-regulation-crypto-assets-proposal">SEC proposes Regulation Crypto Assets with two registration exemptions and a conditional safe harbor</a></li>
<li><a href="#eba-investment-firm-reclassification-rts">EBA consults on the EUR 30 billion threshold at which investment firms become credit institutions</a></li>
<li><a href="#esas-bilateral-margin-requirements-emir">European Supervisory Authorities propose to simplify initial margin requirements under EMIR</a></li>
<li><a href="#esma-weekly-commodity-position-reporting">ESMA confirms 3 September go-live of weekly commodity derivatives position reporting</a></li>
</ul>
</div>
<h2 id="bank-of-lithuania-evernord-nasdaq-vilnius">Bank of Lithuania licenses Evernord Asset Management and approves Nasdaq Vilnius rule changes</h2>
<p><strong>Date:</strong> 26 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania)<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/finansu-rinkos-prieziuros-komiteto-sprendimai-30" target="_blank" rel="noopener" aria-label="Bank of Lithuania, Financial Market Supervision Committee decisions, 26 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>In its Financial Market Supervision Committee decisions of 26 August, the Bank of Lithuania took two decisions relevant to investment activity.</p>
<p>It licensed <strong>Evernord Asset Management UAB</strong> as a management company of alternative collective investment undertakings. The license permits the company to manage collective investment undertakings intended for informed investors (including those intended for professional investors), to manage undertakings for collective investment in transferable securities (UCITS), to manage real-estate collective investment undertakings, and to manage portfolios of financial instruments belonging to other persons.</p>
<p>It also approved Baltic membership rules amendments at the request of AB Nasdaq Vilnius. Part of the amendments implement the European Commission regulation establishing requirements for the publication of market data on reasonable commercial terms. A new order type, the <strong>Auction Volume Discovery (AVD) order</strong>, is being introduced on the Nasdaq Nordic markets for use in opening and closing auctions, with the aim of increasing auction liquidity without adversely affecting price formation. It will be rolled out across all three Baltic markets in stages from <strong>21 September</strong>. The rule amendments entered into force on <strong>1 September 2026</strong>.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>The Evernord license covers four activities under a single authorization: informed-investor funds, UCITS, real-estate funds and individual portfolio management. For anyone scoping a Lithuanian application, it is a current reference point for how widely a management company authorization can be drawn, and a reminder that individual portfolio management has to be applied for expressly.</p>
<p>For trading members, the AVD order and the market-data requirements come with fixed dates. The rulebook changes applied from 1 September and the AVD rollout begins on 21 September.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>use the scope granted to Evernord as a benchmark when scoping their own license application (managers planning Lithuanian AIFM or UCITS activity), and apply expressly for individual portfolio-management permission where the business model requires it</li>
<li>update rulebook compliance, order-handling and best-execution documentation for the AVD order type (trading members on Nasdaq Vilnius)</li>
<li>review market-data licensing and redistribution arrangements against the reasonable-commercial-terms requirements</li>
</ul>
<hr />
<h2 id="bank-of-lithuania-aria-securities-finomark">Bank of Lithuania licenses Aria Securities and expands FinoMark’s crowdfunding permissions</h2>
<p><strong>Date:</strong> 20 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania)<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/finansu-rinkos-prieziuros-komiteto-sprendimai-29" target="_blank" rel="noopener" aria-label="Bank of Lithuania, Financial Market Supervision Committee decisions, 20 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>The Financial Market Supervision Committee decisions bulletin of 20 August contained four decisions.</p>
<p>A <strong>Category C financial brokerage (investment) firm license</strong> went to UAB Aria Securities, permitting the reception and transmission of orders, management of financial instrument portfolios, provision of investment advice, and placing of financial instruments without a firm commitment basis. Ancillary services were also authorized: advising undertakings on capital structure and business strategy, advice and services on reorganizations and acquisitions, investment research and financial analysis, and other general recommendations relating to transactions in financial instruments. <strong>The firm will not hold client funds or client financial instruments.</strong></p>
<p>The crowdfunding license of UAB “FinoMark” was supplemented with the right to operate a <strong>bulletin board</strong> on which registered and properly identified platform clients may advertise an intention to transfer or acquire claims relating to loans originally offered on the platform. The board will operate only as a technical facility. It will not automatically match buying and selling interests, execute client orders or conclude claim-transfer agreements.</p>
<p>The 2026 inspection plan was adjusted. The planned on-site inspection of electronic money institution UAB B4B PAYMENTS EUROPE will be replaced by off-site (remote) supervision. The inspection window for payment institution RIA Lithuania UAB moves from August–October 2026 to November 2026–January 2027. Senior appointments were approved at UAB SME Bank (head of the internal audit service) and Urbo bankas (board member).</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>Aria Securities will not hold client funds or client financial instruments, which materially narrows its safeguarding and prudential profile. Applicants often treat client asset holding as a given when it is a decision they control at the design stage.</p>
<p>The FinoMark decision shows how a bulletin board can be built to sit inside a crowdfunding license. The board stays passive: no automatic matching of buying and selling interests, no execution of client orders, no conclusion of claim-transfer agreements. That is the boundary that keeps such a facility outside the trading-venue perimeter under the Crowdfunding Regulation (ECSPR). Automated matching would raise a trading venue and MiFID authorization question.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>treat client asset holding as a design decision rather than a default (investment-firm applicants), and scope ancillary services explicitly in the application</li>
<li>keep any bulletin board strictly non-matching and non-executing and document that design (crowdfunding platforms adding secondary-liquidity features), since automated matching of buy and sell interest risks triggering trading venue and MiFID authorization requirements</li>
<li>re-check their slot and re-phase inspection-readiness work (PIs and EMIs named in the published inspection plan), since off-site supervision still produces data requests and remote reviews</li>
</ul>
<hr />
<h2 id="sec-regulation-crypto-assets-proposal">SEC proposes Regulation Crypto Assets with two registration exemptions and a conditional safe harbor</h2>
<p><strong>Date:</strong> 18 August 2026 | <strong>Source:</strong> SEC (U.S. Securities and Exchange Commission)<br /><i class="fa fa-external-link"></i><a href="https://www.sec.gov/newsroom/press-releases/2026-76-sec-proposes-new-regulation-crypto-assets" target="_blank" rel="noopener" aria-label="SEC press release 2026-76, Regulation Crypto Assets, 18 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>The SEC proposed new rules titled <strong>“Regulation Crypto Assets”</strong>, intended to create a clear and fit-for-purpose framework for certain investment contracts involving crypto assets. The proposal builds on the Commission’s March 2026 interpretation of how the federal securities laws apply to crypto assets and transactions involving them.</p>
<p>Two exemptions from the registration requirements of the Securities Act of 1933 are proposed. The first is a one-time exemption permitting offerings of up to <strong>USD 5 million over a four-year period</strong>. The second permits offerings of up to <strong>USD 75 million in each 12-month period</strong>. Issuers under both would make principles-based narrative disclosures available to investors, and issuers relying on the second would also provide financial statements and be subject to ongoing reporting requirements.</p>
<p>The proposal also includes a <strong>conditional safe harbor</strong> from the “investment contract” element of the “security” definitions in the Securities Act of 1933 and the Securities Exchange Act of 1934, available once an issuer has completed or permanently ceased the essential managerial efforts it represented or promised it would undertake. Securities issued under a Regulation Crypto Assets exemption would be exempt from state securities law registration and qualification requirements, as would certain secondary market transactions.</p>
<p>The proposing release (Release Nos. 33-11434 and 34-106150, File No. S7-2026-27) was published in the Federal Register on 21 August 2026. The public comment period closes on <strong>20 October 2026</strong>.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>The two frameworks do different jobs, which is why they have to be mapped rather than compared. MiCA authorizes service providers and regulates offers to the public through <a href="https://ecovis.lt/fintech/solutions-for-blockchain-cryptocurrency-ico/">white papers</a>, disclosure and marketing rules. The SEC proposal is an offering regime built on a different premise: the security is the investment contract surrounding the asset, and the proposed safe harbor turns on whether the issuer has completed or permanently ceased the managerial efforts it promised. An asset that falls outside MiCA’s white-paper obligations can still form part of an investment contract in the US, and an offering structured under a proposed US exemption still needs its EU treatment worked out separately.</p>
<p>For smaller issuers, the caps set the shape of what a US-facing raise can look like: USD 5 million once, or USD 75 million a year with financial statements and ongoing reporting attached.</p>
<h3>Recommended actions</h3>
<p>Crypto-asset firms with US touchpoints should:</p>
<ul>
<li>test planned or completed token offerings against the two proposed exemptions and the conditions of the safe harbor, including the point at which essential managerial efforts are treated as complete</li>
<li>map the interaction with MiCA for any asset offered in both markets, covering classification, white-paper and disclosure content, and marketing rules</li>
<li>submit comments under File No. S7-2026-27 by 20 October 2026 if the proposed conditions would affect a planned offering</li>
<li>review group structures to ensure US-facing activity is ring-fenced or appropriately authorized</li>
</ul>
<hr />
<h2 id="eba-investment-firm-reclassification-rts">EBA consults on the EUR 30 billion threshold at which investment firms become credit institutions</h2>
<p><strong>Date:</strong> 25 August 2026 | <strong>Source:</strong> EBA (European Banking Authority)<br /><i class="fa fa-external-link"></i><a href="https://www.eba.europa.eu/publications-and-media/press-releases/eba-consults-revised-technical-standards-reclassification-investment-firms-credit-institutions" target="_blank" rel="noopener" aria-label="EBA consultation on reclassification of investment firms as credit institutions, 25 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>The EBA launched a consultation on <strong>three draft regulatory technical standards (RTS)</strong> on the reclassification of investment firms as credit institutions. Under the Capital Requirements Directive (CRD), an investment firm whose total assets exceed <strong>EUR 30 billion</strong> must obtain a credit institution authorization rather than operate under a MiFID investment firm authorization.</p>
<p>The first two RTS revise the methodology for calculating total assets against that threshold, at solo and group level, and the related reporting requirements. They reflect the <strong>2024 amendments to the CRD</strong>, which clarified the scope of entities to be included in the calculation. Reporting applies from a lower level than reclassification: under Article 55(5) of the Investment Firms Regulation (IFR), it covers investment firms whose total assets exceed <strong>EUR 5 billion</strong>.</p>
<p>The third RTS is new. For the first time, the EBA is consulting on the factors competent authorities must consider when deciding whether to grant a <strong>waiver</strong> from the requirement to hold a credit institution authorization. Where a waiver is granted, the firm continues to operate under its investment firm authorization.</p>
<p>The legal bases are Articles 8a(6)(b) and 8a(7) CRD and Article 55(5) IFR. The feedback deadline is <strong>25 November 2026</strong>. A virtual public hearing takes place on <strong>30 September 2026 at 10:00 CEST</strong>, with registration required by <strong>25 September 2026 at 16:00 CEST</strong>.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>Crossing the threshold moves a firm out of the IFR/IFD regime and into the full CRR and CRD prudential framework, with a fresh authorization to obtain. For a firm within reach of EUR 30 billion, the calculation methodology determines when the threshold is crossed, and the proposed waiver factors may determine whether the firm can stay under its investment firm authorization. Both are worth reading before they are finalized.</p>
<p>The EUR 5 billion reporting level catches a much wider group. Firms above it will be reporting against the threshold long before they come close to it.</p>
<h3>Recommended actions</h3>
<p>Large investment firms approaching the total-assets threshold should:</p>
<ul>
<li>model total assets under the proposed methodology at both solo and group level and identify the point at which EUR 30 billion would be crossed</li>
<li>assess the proposed waiver factors against the firm’s structure and business model, since a waiver preserves the investment firm authorization</li>
<li>check the proposed reporting templates and instructions where total assets exceed EUR 5 billion</li>
<li>register for the 30 September hearing by 25 September and prepare consultation comments ahead of the 25 November deadline</li>
</ul>
<hr />
<h2 id="esas-bilateral-margin-requirements-emir">European Supervisory Authorities propose to simplify initial margin requirements under EMIR</h2>
<p><strong>Date:</strong> 3 August 2026 | <strong>Source:</strong> EBA / EIOPA / ESMA (Joint Committee of the ESAs)<br /><i class="fa fa-external-link"></i><a href="https://www.eba.europa.eu/publications-and-media/press-releases/eba-eiopa-and-esma-propose-amendments-bilateral-margin-requirements" target="_blank" rel="noopener" aria-label="EBA, EIOPA and ESMA press release on bilateral margin requirements, 3 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>The EBA, EIOPA and ESMA published a <strong>final report on draft regulatory technical standards</strong> proposing to simplify the bilateral margin requirements in Commission Delegated Regulation (EU) 2016/2251 under the European Market Infrastructure Regulation (EMIR).</p>
<p>The proposal concerns <strong>initial margin only</strong>, and targets counterparties below the <strong>EUR 8 billion threshold</strong> for exchanging initial margin. Under the current framework, those counterparties are exempt from exchanging initial margin on new uncleared over-the-counter (OTC) derivative contracts but continue to exchange it on existing ones. The amendments would remove the requirement for new and existing contracts alike, completing the phase-out for this group and moving the EU closer to the treatment applied in other jurisdictions. The ESAs present the change as a response to requests from market participants and part of their simplification and burden reduction work.</p>
<p>The final report has been submitted to the European Commission for endorsement. The RTS will then be subject to scrutiny by the European Parliament and the Council before publication in the Official Journal.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>The proposed change would reduce the initial margin burden for affected counterparties. A counterparty below EUR 8 billion that is still posting and collecting initial margin on legacy uncleared trades would be able to stop, releasing collateral and retiring the associated custody and segregation arrangements.</p>
<p>The timing sits with the Commission and the co-legislators, so nothing changes yet. The consultation stage has passed and comments are closed, which makes this a planning item rather than a lobbying one.</p>
<h3>Recommended actions</h3>
<p>Derivatives counterparties should:</p>
<ul>
<li>confirm whether the firm sits below the EUR 8 billion initial margin threshold, and identify any legacy uncleared OTC contracts on which initial margin is still exchanged</li>
<li>estimate the collateral and custody arrangements that would be released, and plan the operational steps and counterparty communications needed to unwind them</li>
<li>track the endorsement timeline through the Commission, Parliament and Council, since the relief applies only once the amending RTS are published in the Official Journal</li>
</ul>
<hr />
<h2 id="esma-weekly-commodity-position-reporting">ESMA confirms 3 September go-live of weekly commodity derivatives position reporting</h2>
<p><strong>Date:</strong> 14 August 2026 | <strong>Source:</strong> ESMA (European Securities and Markets Authority)<br /><i class="fa fa-external-link"></i><a href="https://www.esma.europa.eu/press-news/esma-news/esma-confirms-go-live-weekly-commodity-derivatives-position-reporting" target="_blank" rel="noopener" aria-label="ESMA news on weekly commodity derivatives position reporting, 14 August 2026"> Link</a></p>
<h3>What happened?</h3>
<p>ESMA confirmed that the new weekly commodity derivatives position reporting framework went live on <strong>3 September 2026</strong>. From that date, market participants submit weekly position reports under the updated requirements, technical specifications and validation rules introduced by <strong>XML schema version 2.0</strong>.</p>
<p>The go-live follows ESMA’s original reporting instructions and a subsequent decision to postpone the rollout, which gave firms additional time for technical and operational preparation. Updated reporting instructions and the XML schema are published on ESMA’s website.</p>
<p>Commodity derivatives position reporting sits within the MiFID II position limits and position management regime, and the shift to a weekly cycle increases the frequency and consistency of the data available to supervisors across trading venues.</p>
<h3>Why it matters for crypto and investment businesses</h3>
<p>The date has already passed. Any firm holding commodity derivative positions should be submitting weekly against schema v2.0, and a validation failure now surfaces every week instead of at a longer interval.</p>
<p>The earlier postponement led some firms to pause their implementation work. Where that work was not restarted in time, the gap will show in rejected or incomplete submissions from the first reporting week onwards.</p>
<h3>Recommended actions</h3>
<p>Firms holding commodity derivatives positions should:</p>
<ul>
<li>confirm that weekly submissions are running against XML schema v2.0 with the updated validation rules implemented, and resolve any rejected or incomplete submissions since 3 September</li>
<li>review position-limit monitoring and ancillary-activity assessments against the more frequent data</li>
</ul>
<hr />
<h2>What crypto and investment businesses should focus on now</h2>
<p>License scope is a design choice. The Evernord authorization shows how widely a Lithuanian management company license can be drawn, and Aria Securities shows what falls away when a firm decides not to hold client assets. The FinoMark bulletin board marks where a crowdfunding license stops and a MiFID trading venue question starts.</p>
<p>On the SEC proposal, the work worth doing now is mapping a token’s treatment under both regimes side by side. Comments under File No. S7-2026-27 close on 20 October 2026, so there is still time to respond on the points that would affect a planned offering.</p>
<p>Three dates are live in the EU. Weekly commodity derivatives position reporting went live on 3 September, so any gap in submissions is already accruing. Registration for the EBA public hearing closes on 25 September, ahead of the hearing on 30 September and the consultation deadline of 25 November. The Nasdaq Vilnius rule amendments took effect on 1 September and the AVD rollout starts on 21 September.</p>
<p>The EMIR initial margin relief runs on a slower track. It has gone to the Commission for endorsement and applies only once the amending RTS reach the Official Journal.</p>
<hr />
<h2>How ECOVIS ProventusLaw can help crypto and investment businesses</h2>
<p>ECOVIS ProventusLaw advises crypto-asset and investment businesses across the Baltics on <a href="https://ecovis.lt/fintech/">fintech and financial institution licensing in the EU</a>, including:</p>
<ul>
<li>MiCA authorization strategy and regulatory perimeter mapping</li>
<li>scoping AIFM, UCITS and investment firm license applications, including ancillary services and client-asset choices</li>
<li>crowdfunding licensing and the design of secondary-liquidity features under ECSPR</li>
<li>structuring cross-border activity across the EU and US regimes</li>
<li>white papers, token offerings and disclosure documents</li>
<li>AML/CTF, Travel Rule and sanctions controls for crypto businesses</li>
<li>DORA and ICT risk readiness</li>
<li>dialogue with financial supervisors, from pre-licensing consultations to inspections</li>
</ul>
<p>If a license application, a perimeter question or a new regulatory proposal touches your plans, we can help you scope it before the regulator asks.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-crypto-investments-regulation-september-2026/">RegRally Insights: Crypto &#038; Investments Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Sanctions Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-sanctions-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 10:10:00 +0000</pubDate>
				<category><![CDATA[RegRally Insights]]></category>
		<category><![CDATA[Sanctions]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11999</guid>

					<description><![CDATA[<p>For EU-based institutions, the month’s common thread is divergence. What becomes permissible under U.S. law can remain prohibited under EU law, and the same names can now be enforced well beyond the Union. The September edition of RegRally covers what this means for financial institutions, exporters and businesses with cross-border exposure.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-sanctions-regulation-september-2026/">RegRally Insights: Sanctions Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>August was a busy month for <a href="https://ecovis.lt/practice-areas/financial-economic-sanctions/" target="_blank" rel="noopener">sanctions</a> compliance. Lithuania’s Financial Crime Investigation Service (FNTT) expanded the national list of companies treated as owned or controlled by sanctioned persons. The EU confirmed that a widening group of third countries is aligning with its restrictive measures. And the U.S. Office of Foreign Assets Control (OFAC) produced a steady stream of designations, de-listings and General License changes, including the removal of Syria’s State Sponsor of Terrorism designation.</p>
<p>For EU-based institutions, what becomes permissible under U.S. law can remain prohibited under EU law, and the same names can now be enforced well beyond the Union. The September edition of RegRally covers what this means for financial institutions, exporters and businesses with cross-border exposure.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Lithuania:</strong> by orders of 5 August, the FNTT added three Lithuanian companies to the national list of entities owned or controlled by sanctioned persons and supplemented the grounds for two existing entries. Asset freezing applies to them despite the absence of a direct EU or UN listing.</li>
<li><strong>EU reach:</strong> two High Representative statements confirmed the alignment of third countries with EU restrictive measures on Ukraine, Belarus, human rights and terrorism, extending the practical effect of EU listings beyond the Union.</li>
<li><strong>United States:</strong> OFAC removed Syria’s State Sponsor of Terrorism designation while issuing fresh Iran-related designations the same day. EU and UK measures on Syria remain fully in force, so U.S. permissibility does not equal EU permissibility.</li>
<li><strong>U.S. enforcement:</strong> a USD 60,764 settlement with Rice Lake Weighing Systems over exports of weighing equipment to Iran through a distributor in the United Arab Emirates shows how indirect routes create liability even at modest amounts.</li>
<li><strong>Rolling U.S. actions:</strong> through August, OFAC issued designations, de-listings and General License changes across the Cuba, Iran, Venezuela, counter-terrorism and Russia programs, and its International Criminal Court (ICC)-related designations raise tension with the EU Blocking Statute.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#fntt-sanctions-list-lithuanian-companies">FNTT adds three Lithuanian companies to the national list of entities controlled by sanctioned persons</a></li>
<li><a href="#eu-alignment-ukraine-restrictive-measures">Third countries align with EU restrictive measures over Ukraine’s territorial integrity</a></li>
<li><a href="#eu-alignment-belarus-human-rights-terrorism">Third countries align with EU sanctions on Belarus, human rights and terrorism</a></li>
<li><a href="#ofac-syria-state-sponsor-terrorism-removal">OFAC removes Syria’s State Sponsor of Terrorism designation while EU measures stay in force</a></li>
<li><a href="#ofac-icc-designations-eu-blocking-statute">OFAC’s ICC-related designations create tension with the EU Blocking Statute</a></li>
<li><a href="#ofac-rice-lake-enforcement-settlement">OFAC settles with Rice Lake Weighing Systems over Iran exports through a UAE distributor</a></li>
<li><a href="#ofac-rolling-august-actions">OFAC’s rolling August actions: designations, de-listings and shifting General Licenses</a></li>
</ul>
</div>
<h2 id="fntt-sanctions-list-lithuanian-companies">FNTT adds three Lithuanian companies to the national list of entities controlled by sanctioned persons</h2>
<p><strong>Date:</strong> 5 August 2026 | <strong>Source:</strong> FNTT (Financial Crime Investigation Service)<br /><i class="fa fa-external-link"></i><a href="https://fntt.lrv.lt/lt/tarptautines-finansines-sankcijos/fntt-isakymai/" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>By orders of 5 August 2026, the Director of the FNTT amended the list of legal persons and other organizations owned or controlled by a sanctioned entity.</p>
<p>Orders No. V-174, V-175 and V-176 added three companies to the list: <strong>UAB “Valientė”</strong> (code 305265888), <strong>UAB “Next Logistic”</strong> (code 305694948) and <strong>UAB “Litproduktai”</strong> (code 305088459).</p>
<p>Orders No. V-172 and V-173 supplemented the grounds for inclusion of two companies already on the list: <strong>AB “Inter Rao Lietuva”</strong> (code 126119913) and <strong>UAB “Vydmantai wind park”</strong> (code 302666616).</p>
<p>Inclusion on the list means the entity is treated as owned or controlled by a person subject to sanctions. Asset freezing and the prohibition on making funds available apply to it even though it is a Lithuanian-registered company.</p>
<h3>Why does it matter for businesses?</h3>
<p>Lithuanian registration is no safe harbour. These are local companies to which freezing measures apply without any direct EU or UN listing, so a screening set-up that only checks EU and UN lists will miss them.</p>
<p>The supplemented grounds matter too. The reasoning behind two existing entries has changed, so decisions taken earlier on those relationships may rest on an outdated basis.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>re-screen the customer and counterparty base against the updated FNTT list and check for indirect exposure through payment chains and ownership links</li>
<li>where a relationship with any listed company exists, freeze and report as required, and not rely on the absence of a direct EU or UN listing</li>
<li>reassess any earlier decision taken on relationships with the two existing entries, since the grounds for their inclusion have changed</li>
</ul>
<hr />
<h2 id="eu-alignment-ukraine-restrictive-measures">Third countries align with EU restrictive measures over Ukraine’s territorial integrity</h2>
<p><strong>Date:</strong> 28 August 2026 | <strong>Source:</strong> Council of the European Union<br /><i class="fa fa-external-link"></i><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/08/28/statement-by-the-high-representative-on-behalf-of-the-eu-on-the-alignment-of-certain-countries-concerning-restrictive-measures-in-respect-of-actions-undermining-or-threatening-the-territorial-integrity-sovereignty-and-independence-of-ukrain/" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The High Representative, on behalf of the EU, declared the alignment of certain third countries with EU restrictive measures concerning actions undermining or threatening Ukraine’s territorial integrity, sovereignty and independence.</p>
<p>Alignment means the aligning states commit to adopt corresponding measures, so the practical reach of EU listings extends beyond the Union. For institutions, this widens the set of jurisdictions in which the same names and prohibitions are effectively enforced.</p>
<h3>Why does it matter for businesses?</h3>
<p>Routing a transaction through an aligned jurisdiction no longer sidesteps the listings. The same names are enforced there, so correspondent and routing assessments should treat aligned states accordingly.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>factor the widening group of aligned jurisdictions into counterparty, routing and correspondent-risk assessments</li>
<li>confirm screening fully reflects the EU restrictive-measures listings under the Russia and Ukraine program</li>
</ul>
<hr />
<h2 id="eu-alignment-belarus-human-rights-terrorism">Third countries align with EU sanctions on Belarus, human rights and terrorism</h2>
<p><strong>Date:</strong> 18 August 2026 | <strong>Source:</strong> Council of the European Union<br /><i class="fa fa-external-link"></i><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/08/18/statement-by-the-high-representative-on-behalf-of-the-eu-on-the-alignment-of-certain-countries-concerning-restrictive-measures-against-serious-human-rights-violations-and-abuses/" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The High Representative, on behalf of the EU, issued statements on the alignment of certain third countries with EU restrictive measures relating to three regimes: the situation in Belarus and its involvement in Russia’s aggression against Ukraine, serious human rights violations and abuses under the EU Global Human Rights Sanctions Regime, and measures to combat terrorism.</p>
<p>The statements confirm the continued extension of these three regimes to aligning partner countries, reinforcing their cross-border effect.</p>
<h3>Why does it matter for businesses?</h3>
<p>The three regimes were extended in parallel. A nexus to an aligned country is a factor to weigh, and screening limited to the Russia program misses the Belarus, human rights and counter-terrorism listings that are being extended in parallel.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>confirm screening covers the Belarus, EU Global Human Rights and counter-terrorism sanctions regimes</li>
<li>treat a nexus to an aligned country as an elevated-risk indicator in onboarding and ongoing monitoring</li>
</ul>
<hr />
<h2 id="ofac-syria-state-sponsor-terrorism-removal">OFAC removes Syria’s State Sponsor of Terrorism designation while EU measures stay in force</h2>
<p><strong>Date:</strong> 24 August 2026 | <strong>Source:</strong> OFAC (U.S. Department of the Treasury)<br /><i class="fa fa-external-link"></i><a href="https://ofac.treasury.gov/recent-actions/20260824" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>OFAC removed Syria’s designation as a <strong>State Sponsor of Terrorism</strong> and published a set of associated Sanctions List updates, marking one of the most significant easings of the U.S. sanctions posture toward Syria in years.</p>
<p>The change re-opens the question of how Syrian counterparties, correspondent flows and trade-finance exposure should be treated. It does not by itself lift all Syria-related prohibitions.</p>
<p>On the same day, OFAC issued fresh Iran-related designations and updated several Iran-related General Licenses. The Syria recalibration runs in parallel with continued pressure on Iran, not a general relaxation.</p>
<p>For EU-based institutions, the key point is that <strong>EU and UK measures on Syria remain fully in force</strong> and are unaffected by the U.S. step. A transaction that becomes permissible under U.S. law may still be prohibited under EU law.</p>
<h3>Why does it matter for businesses?</h3>
<p>Permissibility is a jurisdiction-by-jurisdiction question. A U.S. easing does not make the same transaction lawful for an EU operator.</p>
<p>The analysis also needs a paper trail. When regimes point in different directions, the multi-jurisdictional reasoning behind each decision is what a supervisor will ask to see.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>re-run sanctions screening against the updated OFAC Specially Designated Nationals (SDN) and Sanctions List files and refresh internal watchlists and payment-filter rules</li>
<li>reassess any Syria-related exposure and correspondent relationships against the EU and UK frameworks before treating business as permissible, and document the multi-jurisdictional analysis</li>
<li>where reliance is placed on an Iran-related General License, record its number, scope and expiry and confirm the activity fits squarely within it</li>
</ul>
<hr />
<h2 id="ofac-icc-designations-eu-blocking-statute">OFAC’s ICC-related designations create tension with the EU Blocking Statute</h2>
<p><strong>Date:</strong> 18 August 2026 | <strong>Source:</strong> OFAC (U.S. Department of the Treasury)<br /><i class="fa fa-external-link"></i><a href="https://ofac.treasury.gov/recent-actions/20260818" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>OFAC issued International Criminal Court (ICC)-related designations together with a Venezuela-related designation and an ICC-related General License.</p>
<p>The ICC-related measures are politically sensitive and can create direct tension with EU law. Institutions with an EU nexus should be alert to the <strong>EU Blocking Statute (Regulation (EC) No 2271/96)</strong>, which may prohibit EU operators from complying with certain U.S. measures. The same conduct can be required under one regime and prohibited under another.</p>
<h3>Why does it matter for businesses?</h3>
<p>The same conduct can be required under one regime and prohibited under another. Complying with the U.S. measure, for example by declining or exiting EU-lawful business, can itself breach EU law.</p>
<p>Decisions on affected relationships therefore need legal analysis before action, not after. The Blocking Statute question has to be answered first.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>screen against the new ICC-related and Venezuela-related designations</li>
<li>where an EU nexus exists, take advice on the interaction with the EU Blocking Statute before declining or exiting EU-lawful business solely on the basis of the U.S. measure</li>
<li>document the conflict-of-laws analysis for any affected relationship</li>
</ul>
<hr />
<h2 id="ofac-rice-lake-enforcement-settlement">OFAC settles with Rice Lake Weighing Systems over Iran exports through a UAE distributor</h2>
<p><strong>Date:</strong> 12 August 2026 | <strong>Source:</strong> OFAC (U.S. Department of the Treasury)<br /><i class="fa fa-external-link"></i><a href="https://ofac.treasury.gov/recent-actions/20260812" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>OFAC announced a settlement of <strong>USD 60,764</strong> with Rice Lake Weighing Systems, Inc., resolving apparent violations of U.S. sanctions arising from the export of weighing equipment to Iran via a distributor in the United Arab Emirates (UAE) between July 2019 and November 2021.</p>
<p>Although the amount is modest, the case is a useful enforcement benchmark. It underlines OFAC’s expectations on distributor and re-export due diligence, geographic red flags, and the mitigating value of remediation and voluntary self-disclosure.</p>
<h3>Why does it matter for businesses?</h3>
<p>The case sets out OFAC’s expectations on distributor and re-export due diligence and on geographic red flags. Exposure through distributors and intermediaries is judged by where the goods end up, not where the invoice goes.</p>
<p>It also shows the mitigating value of remediation and voluntary self-disclosure.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>review the enforcement findings as a benchmark for their own sanctions controls, especially indirect exposure through distributors and intermediaries</li>
<li>confirm procedures for voluntary self-disclosure, escalation and remediation where a potential breach is identified</li>
<li>test end-user and re-export screening for goods and services that can reach sanctioned jurisdictions through third countries</li>
</ul>
<hr />
<h2 id="ofac-rolling-august-actions">OFAC’s rolling August actions: designations, de-listings and shifting General Licenses</h2>
<p><strong>Date:</strong> 6 to 27 August 2026 | <strong>Source:</strong> OFAC (U.S. Department of the Treasury)<br /><i class="fa fa-external-link"></i><a href="https://ofac.treasury.gov/recent-actions" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>OFAC made list changes throughout August. On 6 August it issued Cuba-related designations with a clarifying FAQ on the treatment of the newly listed parties. On 7 August it combined Counter Terrorism and Iran-related designations with same-day removals of certain Counter Narcotics designations and an amended Iran-related FAQ. On 20 August a broad multi-program round spanned the Counter Narcotics, Counter Terrorism, Cuba-related and Iran-related programs, accompanied by a new Russia-related General License and associated FAQs.</p>
<p>Venezuela-related General Licenses issued on 21 August were amended again on <strong>27 August</strong>. Further Counter Terrorism designations on 26 August came with a Counter Terrorism General License and an amended Russia-related General License, which is particularly relevant to institutions still managing legacy exposure, as it can change the permitted scope or timing of otherwise restricted dealings.</p>
<h3>Why does it matter for businesses?</h3>
<p>Additions and removals both change screening outcomes. Stale watchlists produce missed hits and unnecessary rejects, so list maintenance has to be continuous rather than periodic.</p>
<p>The General License churn carries its own risk. When authorizations are amended within a week, reliance on any single version is a timing exposure.</p>
<h3>Recommended actions</h3>
<p>Businesses should:</p>
<ul>
<li>refresh watchlists to capture both the new designations and the de-listings, and re-screen recently rejected or blocked transactions that may be affected by the removals</li>
<li>map exposure against the scope and expiry of the current General Licenses, diarize the amendments, conditions and any wind-down periods, and re-verify the applicable license version before executing payments</li>
<li>review the accompanying FAQs for interpretation points relevant to the firm’s book of business</li>
</ul>
<hr />
<h2>What businesses should take from this month’s developments</h2>
<p>The FNTT orders are the local reminder. A company registered in Lithuania can be subject to asset freezing without ever appearing on an EU or UN list, and the grounds behind an existing entry can change, so past decisions do not stay decided.</p>
<p>Across borders, the pictures are moving in opposite directions. The EU’s reach is widening as more third countries align with its restrictive measures, while the U.S. is recalibrating: easing on Syria, pressing on Iran, and adjusting General Licenses week by week. The same transaction can be permissible under one regime and prohibited under another, so permissibility has to be assessed and documented jurisdiction by jurisdiction.</p>
<p>Screening lists need continuous maintenance covering both additions and de-listings, and any reliance on a General License needs its version, scope and expiry on record.</p>
<hr />
<h2>How ECOVIS ProventusLaw can help with sanctions compliance</h2>
<p>Our <a href="https://ecovis.lt/practice-areas/financial-economic-sanctions/" target="_blank" rel="noopener">sanctions team</a> works with businesses across the Baltics on EU, U.S. and national sanctions questions, including:</p>
<ul>
<li>building and stress-testing sanctions compliance programs and risk assessments</li>
<li>screening set-up, watchlist management and internal controls</li>
<li>ownership and control analysis of counterparties</li>
<li>exposure reviews covering Russia, Belarus and other sanctioned jurisdictions</li>
<li>circumvention and third-country intermediary risk</li>
<li>crypto-asset sanctions exposure and blockchain analytics findings</li>
<li>export controls and trade restrictions</li>
<li>handling asset freezes, investigations and supervisory enquiries</li>
<li>internal policies, procedures and staff training</li>
</ul>
<p>If an FNTT listing, an OFAC action or a divergence between EU and U.S. rules touches your business, we can help you work out what is prohibited, what is permitted and what to document.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-sanctions-regulation-september-2026/">RegRally Insights: Sanctions Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: Consumer Protection Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-consumer-protection-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 10:40:24 +0000</pubDate>
				<category><![CDATA[Consumer protection]]></category>
		<category><![CDATA[Fintech]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11990</guid>

					<description><![CDATA[<p>The FCA warns on risky mini-bonds and clone-firm scams. The September edition of RegRally looks at what this means for investment firms, distributors and platforms serving retail clients in the Baltics and across the EU.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-consumer-protection-regulation-september-2026/">RegRally Insights: Consumer Protection Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Consumer protection attention in August turned to how retail investors are approached and misled. The UK Financial Conduct Authority (FCA) issued two warnings in quick succession: one on risky mini-bonds and loan notes marketed with high fixed returns, and one on clone firms impersonating authorised companies. Both risks travel well beyond the UK, because Baltic retail investors reach the same products and the same scams through online platforms.</p>
<p>The September edition of RegRally looks at what these developments mean for <a href="https://ecovis.lt/fintech/mifid-license/" target="_blank" rel="noopener">investment firms</a>, distributors and platforms serving retail clients in the Baltics and across the EU.</p>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#fca-mini-bonds-loan-notes-warning">FCA warns consumers about risky mini-bonds and loan notes</a></li>
<li><a href="#fca-clone-firm-warnings">FCA flags clone firms as impersonation fraud continues</a></li>
</ul>
</div>
<h2 id="fca-mini-bonds-loan-notes-warning">FCA warns consumers about risky mini-bonds and loan notes</h2>
<p><strong>Date:</strong> 20 August 2026 | <strong>Source:</strong> FCA (Financial Conduct Authority, UK)<br /><i class="fa fa-external-link"></i><a href="https://www.fca.org.uk/news/press-releases/consumers-warned-beware-risky-mini-bonds-and-loan-notes" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The FCA issued a consumer warning urging people to beware of risky <strong>mini-bonds and loan notes</strong>. These are high-risk and frequently illiquid investments. In many cases they are not protected by the Financial Services Compensation Scheme (FSCS) and can result in the loss of the entire amount invested.</p>
<p>The warning responds to continued marketing of speculative debt securities to retail investors, often promising high fixed returns. It reiterates that such products may sit outside key regulatory protections and the Financial Ombudsman Service.</p>
<p>While issued by a UK regulator, the theme is directly relevant to Baltic retail investors who access such products cross-border through online platforms.</p>
<h3>Why does it matter for businesses?</h3>
<p>The warning signals continued supervisory attention to how high-risk retail products are promoted. Firms marketing these products are expected to meet financial promotion standards in full, from risk warnings to appropriateness checks.</p>
<p>For Baltic distributors and platforms, the cross-border point is the practical one. The same products reach local retail investors online, so the same promotion and target market discipline applies regardless of where the issuer sits.</p>
<h3>Recommended actions</h3>
<p>Firms promoting mini-bonds or loan notes should:</p>
<ul>
<li>ensure their financial promotions are fair, clear and not misleading and comply with the high-risk investment marketing rules, including risk warnings and appropriateness checks</li>
<li>verify the target market assessment and the prominence of risk warnings before distribution (retail distributors)</li>
</ul>
<p>Consumers should confirm a firm&rsquo;s status on the FCA Register (or the relevant national register) and check FSCS or compensation coverage before investing.</p>
<hr />
<h2 id="fca-clone-firm-warnings">FCA flags clone firms as impersonation fraud continues</h2>
<p><strong>Date:</strong> 28 August 2026 | <strong>Source:</strong> FCA (Financial Conduct Authority, UK)<br /><i class="fa fa-external-link"></i><a href="https://www.fca.org.uk/consumers/unauthorised-firms-individuals" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The FCA published a warning that <strong>reclaim-experts.com</strong> is a clone of an FCA-authorised firm targeting people in the UK. It is one of a continued wave of unauthorised-firm and clone warnings issued throughout late August 2026, including multiple entries on 27 August.</p>
<p><strong>Clone firms</strong> impersonate the name, registration details and sometimes the address of a genuinely authorised firm to defraud consumers, frequently in connection with investment or reclaim and refund scams.</p>
<p>The persistence of these warnings underlines that impersonation fraud remains a high-volume consumer risk.</p>
<h3>Why does it matter for businesses?</h3>
<p>Authorised firms are targets here too. A clone trades on a real firm&rsquo;s name and registration details, and every defrauded customer associates the loss with that name.</p>
<p>For distributors and platforms, onboarding and payment authorisation are the points where a clone can still be caught before money moves.</p>
<h3>Recommended actions</h3>
<p>To reduce clone-firm risk:</p>
<ul>
<li>consumers should verify any firm against the FCA Register and use only the contact details published there, never those supplied by the firm making the approach</li>
<li>authorised firms should monitor for cloning of their identity, proactively warn customers and report clones to the regulator</li>
<li>distributors and platforms should build clone-firm checks into onboarding and payment-authorisation flows</li>
</ul>
<hr />
<h2>What businesses should take from this month&rsquo;s developments</h2>
<p>Both warnings point at the retail interface. Supervisors are watching how high-risk products are promoted and how easily consumers can be misled about who they are dealing with.</p>
<p>For firms, that translates into two checks. Promotions for high-risk retail products need current risk warnings, appropriateness checks and a documented target market assessment. And clone-firm monitoring, both of your own identity and within onboarding and payment flows, is becoming standard hygiene.</p>
<p>The warnings are UK-issued, but the products and the scams are cross-border by nature. Baltic firms serving retail clients online should treat them as directly applicable.</p>
<hr />
<h2>Need assistance?</h2>
<p>Our financial services and regulatory specialists advise consumer credit providers, investment firms, distributors and platforms serving retail clients on:</p>
<ul>
<li>Consumer credit regulatory compliance</li>
<li>Creditworthiness assessment and responsible lending</li>
<li>Consumer credit agreements and documentation</li>
<li>Consumer credit advertising and marketing compliance</li>
<li>P2P lending regulation</li>
<li>Licensing and regulatory authorisations</li>
<li>Regulatory reporting and supervisory requirements</li>
<li>Consumer protection and unfair commercial practices</li>
<li>Regulatory inspections and remediation</li>
<li>Legal advice on financial services regulation in Lithuania, Latvia and Estonia</li>
</ul>
<p>If you would like to review how your financial promotions, risk warnings or anti-impersonation controls stand up to the issues covered in this edition, our team will be happy to assist.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-consumer-protection-regulation-september-2026/">RegRally Insights: Consumer Protection Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RegRally Insights: AML/CTF Regulation, September 2026</title>
		<link>https://ecovis.lt/regrally-insights-aml-ctf-regulation-september-2026/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 10:14:39 +0000</pubDate>
				<category><![CDATA[AML & CTF Regulation]]></category>
		<category><![CDATA[RegRally Insights]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11984</guid>

					<description><![CDATA[<p>The countdown to direct EU-level anti-money laundering and counter-terrorist financing (AML/CTF) supervision has started. The European Banking Authority (EBA) and the new Anti-Money Laundering Authority (AMLA) are preparing the data collection that will decide which institutions AMLA supervises directly from 2028. At national level, the Bank of Lithuania is asking a simpler question: does the AML framework work in practice, from geographic risk to suspicious transaction reporting and sanctions screening.</p>
<p>The post <a href="https://ecovis.lt/regrally-insights-aml-ctf-regulation-september-2026/">RegRally Insights: AML/CTF Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The countdown to direct EU-level <a href="https://ecovis.lt/aml/" target="_blank" rel="noopener">anti-money laundering</a> and counter-terrorist financing (AML/CTF) supervision has started. The European Banking Authority (EBA) and the new Anti-Money Laundering Authority (AMLA) are preparing the data collection that will decide which institutions AMLA supervises directly from 2028. At national level, the Bank of Lithuania had an active August: a letter on money laundering and terrorist financing risks, an interim restriction on an electronic money institution under inspection, and the first results of the Verification of Payee service.</p>
<p>The September edition of RegRally covers what matters most to financial institutions, payment and electronic money institutions, crypto-asset service providers (CASPs) and other obliged entities in Lithuania and across the EU.</p>
<p><strong>This month at a glance</strong></p>
<ul>
<li><strong>Lithuania:</strong> the Bank of Lithuania&rsquo;s letter, based on 2025 supervisory data and 10 AML/CTF inspections, flags formally assessed geographic risk, the need to verify authorisation under the Markets in Crypto-Assets Regulation (MiCAR), weak enhanced due diligence, disproportionately low suspicious transaction reporting and incomplete sanctions screening. The Council of Europe&rsquo;s MONEYVAL 6th evaluation round starts in October 2026, and the EU AML package applies in full from 10 July 2027.</li>
<li><strong>Lithuania enforcement:</strong> the Bank of Lithuania temporarily prohibited the electronic money institution Lux International Payment System from providing financial services to new and existing customers while an inspection is ongoing, citing suspected serious deficiencies and possible AML/CTF breaches. The restriction was authorised by the Regional Administrative Court.</li>
<li><strong>Payment fraud:</strong> the Bank of Lithuania published the first results of the Verification of Payee (VoP) service, based on a survey of seven banks, two central credit unions and five electronic money institutions. VoP is seen as a useful additional measure against payment fraud, and monitoring continues.</li>
<li><strong>AMLA direct supervision:</strong> the EBA published a draft data model and taxonomy for the 2027 eligibility data collection, the basis for AMLA&rsquo;s first selection of institutions for direct supervision. The reference date is 31 December 2026. Payment institutions and electronic money institutions fall within the reporting population.</li>
<li><strong>Cross-border payments:</strong> AMLA is surveying electronic money institutions (EMIs) and payment service providers (PSPs) on Central Contact Points until 15 September 2026, feeding future technical standards under Article 41(2) of the Anti-Money Laundering Directive (AMLD). Crypto-asset service providers are not in scope.</li>
<li><strong>Isle of Man:</strong> the Isle of Man Financial Services Authority (FSA) published a year-one progress report on its two-year supervisory engagement programme covering AML, countering the financing of terrorism and countering proliferation financing (AML/CFT/CPF), and set out its priorities for 2026/27. Legislative reviews touch virtual asset service providers (VASPs) and the Travel Rule, and a questionnaire on foreign politically exposed persons (PEPs) is coming.</li>
</ul>
<div style="background-color: #f8f9fa; padding: 20px 20px 20px 20px; width: 100%;">
<p><span style="font-size: 20px; display: block; margin: 0 0 12px 0; line-height: 1.3;"><i class="fa fa-list-ul"></i> Quick Navigation</span></p>
<ul>
<li><a href="#bank-of-lithuania-ml-tf-risk-letter">Bank of Lithuania warns financial market participants about ML/TF deficiencies</a></li>
<li><a href="#bank-of-lithuania-lux-international-payment-system">Bank of Lithuania temporarily prohibits EMI Lux International Payment System from providing services during inspection</a></li>
<li><a href="#bank-of-lithuania-verification-of-payee-results">Bank of Lithuania publishes first results of the Verification of Payee service</a></li>
<li><a href="#eba-amla-2027-eligibility-data-collection">EBA publishes draft reporting framework for AMLA&rsquo;s 2027 eligibility data collection</a></li>
<li><a href="#amla-ccp-survey-emis-psps">AMLA surveys EMIs and payment service providers on Central Contact Points</a></li>
<li><a href="#isle-of-man-fsa-supervisory-priorities">Isle of Man FSA publishes year-one progress report on AML/CFT supervisory priorities</a></li>
</ul>
</div>
<h2 id="bank-of-lithuania-ml-tf-risk-letter">Bank of Lithuania warns financial market participants about ML/TF deficiencies</h2>
<p><strong>Date:</strong> 20 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania), Financial Market Supervision Department<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/uploads/documents/files/Rastas%20atkreipiantis%20FRD%20vadovu%20demesi%20i%20PPTF%20rizikas%202026-08-20.pdf" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The Bank of Lithuania sent a letter to the heads of financial market participants on money laundering and terrorist financing (ML/TF) risks and prevention requirements. It is based on 2025 supervisory data and 10 AML/CTF inspections.</p>
<p><strong>The letter flags several risk areas:</strong></p>
<ul>
<li>geographic risk assessed too formally, based on declared residence only rather than actual activity and payment flows</li>
<li>higher-risk activities (crypto-assets, gambling, remittance), where licences must be verified in official registers, including MiCAR authorisation now that the transitional period ended on <strong>1 July 2026</strong></li>
<li>agents and distributors, where responsibility remains with the financial market participant</li>
<li>cash operations, virtual IBANs (vIBANs) and Travel Rule compliance</li>
</ul>
<p><strong>Deficiencies found during inspections:</strong></p>
<ul>
<li>business-wide risk assessments that do not match the actual risk profile</li>
<li>weak enhanced due diligence</li>
<li>transaction monitoring not tailored to the business</li>
<li>incomplete sanctions screening, with no sanctions risk assessment</li>
</ul>
<p>Suspicious transaction report (STR) numbers remain disproportionately low or nil in most sectors. The Bank of Lithuania also reminded firms of the cash reporting duty: linked cash operations reaching <strong>EUR 15,000</strong> must be reported to the Financial Crime Investigation Service (FNTT) within <strong>7 business days</strong>.</p>
<p>On sanctions, circumvention continues via the Commonwealth of Independent States (CIS) and third countries, and EU packages now reach third-country banks and crypto platforms. Not being established in Russia or Belarus is no evidence of low risk. The Council of Europe&rsquo;s MONEYVAL 6th evaluation round runs from <strong>October 2026 to May 2028</strong>, and the EU AML package applies in full from <strong>10 July 2027</strong>.</p>
<h3>Why does it matter for businesses?</h3>
<p>The letter is effectively an inspection roadmap. The flagged areas are where 2025 inspections actually found breaches, and the same areas will get attention in the run-up to the MONEYVAL evaluation starting in October 2026.</p>
<p>Two compliance triggers already apply. The MiCAR transitional period ended on 1 July 2026, so servicing crypto clients without MiCAR authorisation is now a live exposure. And the EUR 15,000 cash reporting duty carries a hard 7-business-day deadline.</p>
<p>Low or nil STR volumes are treated as a warning sign in themselves. Firms should be able to justify their reporting levels against their scale and risk profile.</p>
<h3>Recommended actions</h3>
<p>Lithuanian financial market participants should:</p>
<ul>
<li>re-do geographic risk assessments based on actual activity and payment flows</li>
<li>screen the crypto client book for clients without MiCAR authorisation</li>
<li>review STR volumes against the firm&rsquo;s scale and risk profile and be able to justify them</li>
<li>complete the sanctions risk assessment and extend screening to ownership and the intermediary chain</li>
<li>remediate known deficiencies before expanding activities</li>
<li>start the EU AML package gap analysis against the 10 July 2027 application date</li>
</ul>
<hr />
<h2 id="bank-of-lithuania-lux-international-payment-system">Bank of Lithuania temporarily prohibits EMI Lux International Payment System from providing services during inspection</h2>
<p><strong>Date:</strong> 4 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania)<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/kalbos-interviu-pristatymai/ipareigojimai-lux-international-payment-system" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The Bank of Lithuania temporarily prohibited the electronic money institution UAB &ldquo;Lux International Payment System&rdquo; from providing financial services to both new and existing customers while an inspection is ongoing.</p>
<p>The measure was imposed because the Bank of Lithuania had grounds to suspect serious deficiencies and possible breaches of AML/CTF and other regulatory requirements. The restriction was authorised by the Regional Administrative Court.</p>
<h3>Why does it matter for businesses?</h3>
<p>The case shows that the supervisor does not need a completed inspection to act. Where suspected deficiencies are serious, the supervisor can impose an interim restriction before the inspection is completed, with court authorisation.</p>
<p>For other institutions, the practical lesson is about known weaknesses. Deficiencies that are identified but left unremediated are exactly what turns an inspection into an interim restriction.</p>
<h3>Recommended actions</h3>
<p>Financial institutions should:</p>
<ul>
<li>treat the case as a supervisory benchmark demonstrating the Bank of Lithuania&rsquo;s willingness to impose interim restrictions before completion of an inspection where serious deficiencies are suspected</li>
<li>ensure material AML/CTF weaknesses are escalated and remediated promptly</li>
<li>ensure management can demonstrate effective control over identified regulatory deficiencies</li>
</ul>
<hr />
<h2 id="bank-of-lithuania-verification-of-payee-results">Bank of Lithuania publishes first results of the Verification of Payee service</h2>
<p><strong>Date:</strong> 13 August 2026 | <strong>Source:</strong> Lietuvos bankas (Bank of Lithuania)<br /><i class="fa fa-external-link"></i><a href="https://www.lb.lt/lt/naujienos/gavejo-tikrinimo-paslauga-pirmieji-rezultatai-nuteikia-optimistiskai" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The Bank of Lithuania published the first assessment of the implementation of the Verification of Payee (VoP) service, based on a survey covering seven banks, two central credit unions and five electronic money institutions.</p>
<p>The initial results indicate that VoP is considered a useful additional measure for reducing payment fraud, particularly by alerting customers to discrepancies between the beneficiary name and account details before a payment is executed.</p>
<p>The Bank of Lithuania nevertheless emphasised that further data and experience are required to assess its effectiveness. It intends to continue monitoring both financial institutions&rsquo; and consumers&rsquo; experience with the service.</p>
<h3>Why does it matter for businesses?</h3>
<p>VoP has moved from go-live to supervisory review. Expectations will now be shaped by implementation data, so how a firm handles match results today is what gets benchmarked tomorrow.</p>
<p>The integration point matters most. A VoP check that only displays a warning, without feeding the firm&rsquo;s fraud prevention and monitoring, adds little.</p>
<h3>Recommended actions</h3>
<p>Payment service providers should:</p>
<ul>
<li>review VoP implementation, including the handling of match, no-match and close-match results and customer warnings</li>
<li>assess whether VoP outcomes are appropriately integrated into the firm&rsquo;s fraud prevention and monitoring framework</li>
<li>monitor further Bank of Lithuania communications as supervisory expectations develop based on implementation experience</li>
</ul>
<hr />
<h2 id="eba-amla-2027-eligibility-data-collection">EBA publishes draft reporting framework for AMLA&rsquo;s 2027 eligibility data collection</h2>
<p><strong>Date:</strong> 4 August 2026 | <strong>Source:</strong> European Banking Authority (EBA)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/news-media/news-articles/eba-publishes-draft-reporting-framework-2027-eligibility-data-collection_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The EBA published, as part of release 4.4 of its reporting framework, a public working draft of the data model and taxonomy that will support the 2027 eligibility data collection underpinning AMLA&rsquo;s first selection of financial institutions for direct supervision.</p>
<p>The data will be gathered in early 2027 from all obliged entities provisionally identified as eligible in 2026, to confirm whether they still meet the criteria as of the <strong>31 December 2026</strong> reference date.</p>
<p>Credit and financial institutions fall within the population that must report, including payment institutions and electronic money institutions. Feedback on the draft could be submitted through the EBA feedback form until 24 August 2026, and the draft should be read alongside the templates AMLA published for the 2026 eligibility-criteria data collection.</p>
<h3>Why does it matter for businesses?</h3>
<p>Selection for direct AMLA supervision from 2028 will be based on this data. The 31 December 2026 reference date means the position that determines eligibility is being fixed now, not when the data is collected in 2027.</p>
<p>Payment institutions and electronic money institutions are explicitly within the reporting population. Firms that have not mapped their internal data against the draft model may only discover gaps once the collection exercise is already under way.</p>
<h3>Recommended actions</h3>
<p>Firms should:</p>
<ul>
<li>assess whether they are within scope of the eligibility data collection and begin mapping the required data against the draft model and taxonomy</li>
<li>review the draft reporting templates alongside the templates AMLA published for the 2026 eligibility-criteria data collection</li>
<li>plan governance and resourcing for possible selection for AMLA direct supervision from 2028, using 31 December 2026 as the reference date</li>
</ul>
<hr />
<h2 id="amla-ccp-survey-emis-psps">AMLA surveys EMIs and payment service providers on Central Contact Points</h2>
<p><strong>Date:</strong> 6 August 2026 | <strong>Source:</strong> Anti-Money Laundering Authority (AMLA)<br /><i class="fa fa-external-link"></i><a href="https://www.amla.europa.eu/news-media/news-articles/amla-launches-survey-central-contact-points_en" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>AMLA launched a survey on Central Contact Points (CCPs), inviting electronic money institutions and payment service providers to share their experience of the current CCP framework under Article 45(9) of the AMLD and Delegated Regulation (EU) 2018/1108.</p>
<p>The survey supports AMLA&rsquo;s preparatory work on forthcoming regulatory technical standards (RTS) under Article 41(2) of the AMLD. The standards will address when a host Member State may require the appointment of a CCP and what functions the CCP should perform.</p>
<p>AMLA is running a parallel survey for national competent authorities. It also confirms that crypto-asset service providers are not in scope, as the previous CCP framework did not apply to them. The survey remains open until <strong>15 September 2026</strong>, after which AMLA will publish a report on the main findings.</p>
<h3>Why does it matter for businesses?</h3>
<p>For EMIs and payment service providers operating cross-border through agents or distributors, CCP requirements shape host-Member-State compliance obligations. The future technical standards will harmonise when a host state may require a CCP and what functions it performs.</p>
<p>The survey is the practical way to shape those standards. Problems reported now will likely influence how the harmonised rules are drafted.</p>
<h3>Recommended actions</h3>
<p>EMIs and PSPs operating cross-border through agents or distributors should:</p>
<ul>
<li>review their host-Member-State CCP arrangements and respond to the survey before 15 September 2026</li>
<li>capture practical implementation challenges now, as they are likely to shape the future harmonised RTS</li>
<li>monitor the follow-up report and the eventual Article 41(2) technical standards</li>
</ul>
<hr />
<h2 id="isle-of-man-fsa-supervisory-priorities">Isle of Man FSA publishes year-one progress report on AML/CFT supervisory priorities</h2>
<p><strong>Date:</strong> 19 August 2026 | <strong>Source:</strong> Isle of Man Financial Services Authority (FSA)<br /><i class="fa fa-external-link"></i><a href="https://www.iomfsa.im/fsa-news/2026/aug/authority-publishes-amlcft-supervisory-priorities-progress-report/" target="_blank" rel="noopener"> Link</a></p>
<h3>What happened?</h3>
<p>The Isle of Man FSA published a year-one progress report on its two-year AML/CFT/CPF supervisory engagement programme. It sets out the risk-based work delivered during 2025/26 and the priorities for 2026/27.</p>
<p>The report covers topical thematic reviews (sanctions, terrorist financing, proliferation financing, business risk assessments, reporting and registers), sectoral reviews (estate agents, moneylenders) and legislative reviews touching Virtual Asset Service Providers (VASPs) and the Travel Rule.</p>
<p>Findings feed into the AML/CFT Handbook, sectoral guidance, the Island&rsquo;s National Risk Assessment and preparations for the MONEYVAL mutual evaluation. The Authority also signalled a forthcoming questionnaire on foreign PEPs.</p>
<h3>Why does it matter for businesses?</h3>
<p>For firms within scope, the stated priorities show where the FSA&rsquo;s thematic and sectoral reviews will land during 2026/27. The legislative reviews confirm continued attention to VASPs and the Travel Rule.</p>
<h3>Recommended actions</h3>
<p>Firms within scope should:</p>
<ul>
<li>review the FSA&rsquo;s stated supervisory priorities and benchmark their AML/CFT/CPF frameworks against the thematic and sectoral focus areas</li>
<li>confirm Travel Rule readiness ahead of continued legislative attention (VASPs and firms handling transfers)</li>
<li>anticipate thematic reviews and the PEP questionnaire, and evidence remediation of known gaps</li>
</ul>
<hr />
<h2>What businesses should take from this month&rsquo;s developments</h2>
<p>The Bank of Lithuania&rsquo;s letter makes the expectation explicit: risk assessments, due diligence, monitoring, reporting and sanctions screening must reflect how the business actually operates, not just how it is documented.</p>
<p>The Lux International Payment System case shows the other side of the same expectation. Where serious deficiencies are suspected, the supervisor is prepared to stop business before the inspection ends.</p>
<p>At EU level, the AMLA era is arriving on two tracks. The 2027 eligibility data collection, with 31 December 2026 as the reference date, will determine which institutions face direct AMLA supervision from 2028. The Central Contact Point survey shows AMLA building the technical rules for cross-border payment and e-money business.</p>
<p>With MONEYVAL starting in October 2026 and the EU AML package applying in full from 10 July 2027, the remediation window is now clearly defined.</p>
<hr />
<h2>Need assistance?</h2>
<p>ECOVIS ProventusLaw advises financial institutions, fintechs, CASPs and other obliged entities on AML/CTF compliance, including:</p>
<ul>
<li>AML/CTF regulatory assessments and gap analysis;</li>
<li>business-wide ML/TF risk assessments;</li>
<li>AML policies, internal controls and procedures;</li>
<li>customer due diligence and enhanced due diligence frameworks;</li>
<li>transaction monitoring and suspicious transaction reporting;</li>
<li>AML governance, MLRO responsibilities and employee training;</li>
<li>CASP and virtual asset AML/CTF requirements;</li>
<li>regulatory inspections and remediation of identified deficiencies.</li>
</ul>
<p>If your organisation is preparing for increased AMLA or national supervisory scrutiny, our team can help assess whether your AML framework is not only documented but operationally effective and ready for regulatory review.</p>


<p>The post <a href="https://ecovis.lt/regrally-insights-aml-ctf-regulation-september-2026/">RegRally Insights: AML/CTF Regulation, September 2026</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IBA Annual Conference 2026 in Copenhagen, 4–9 October</title>
		<link>https://ecovis.lt/iba-annual-conference-2026-in-copenhagen/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 09:01:16 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11783</guid>

					<description><![CDATA[<p>Bella Center, Copenhagen. Meet ECOVIS ProventusLaw at IBA 2026. Our partners Inga Karulaitytė and Loreta Andziulytė will attend the IBA Annual Conference 2026 in Copenhagen.</p>
<p>The post <a href="https://ecovis.lt/iba-annual-conference-2026-in-copenhagen/">IBA Annual Conference 2026 in Copenhagen, 4–9 October</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Bella Center, Copenhagen</p>
<h2 style="line-height: 1.2;">Meet ECOVIS ProventusLaw at IBA 2026</h2>
<p>Our partners Inga Karulaitytė and Loreta Andziulytė will attend the <a href="https://www.ibanet.org/conference-details/CONF2635" target="_blank" rel="noopener">IBA Annual Conference 2026</a> in Copenhagen.</p>
<p>If your clients are entering the Baltics, investing in the region or navigating financial services and FinTech regulation across Lithuania, Latvia and Estonia, let&rsquo;s meet in Copenhagen.</p>
<p><a href="https://ecovis.lt/team/inga-karulaityte-en/" style="color:#c6093b;text-decoration:none;">Meet Inga &rarr;</a><br />
<a href="https://ecovis.lt/team/loreta-andziulyte-en/" style="color:#c6093b;text-decoration:none;">Meet Loreta &rarr;</a></p>

	<section class="section" id="section_1317822381">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_1317822381 {
  padding-top: 20px;
  padding-bottom: 20px;
}
</style>
	</section>
	

	<section class="section" id="section_13361157">
		<div class="section-bg fill" >
									<div class="section-bg-overlay absolute fill"></div>
			

		</div>

		

		<div class="section-content relative">
			

<div class="row row-large align-middle"  id="row-141490466">


	<div id="col-1714054408" class="col medium-6 small-12 large-6"  >
				<div class="col-inner"  >
			
			

	<div class="img has-hover x md-x lg-x y md-y lg-y" id="image_547756209">
								<div class="img-inner dark" >
			<img fetchpriority="high" decoding="async" width="803" height="803" src="https://ecovis.lt/wp-content/uploads/2026/06/Inga_Karulaityte.webp" class="attachment-large size-large" alt="" srcset="https://ecovis.lt/wp-content/uploads/2026/06/Inga_Karulaityte.webp 803w, https://ecovis.lt/wp-content/uploads/2026/06/Inga_Karulaityte-300x300.webp 300w, https://ecovis.lt/wp-content/uploads/2026/06/Inga_Karulaityte-150x150.webp 150w, https://ecovis.lt/wp-content/uploads/2026/06/Inga_Karulaityte-768x768.webp 768w" sizes="(max-width: 803px) 100vw, 803px" />						
					</div>
								
<style>
#image_547756209 {
  width: 100%;
}
</style>
	</div>
	


		</div>
					</div>

	

	<div id="col-2059442071" class="col medium-6 small-12 large-6"  >
				<div class="col-inner text-left"  >
			
			

<h2>Inga Karulaitytė</h2>
<p>Partner, Attorney-at-law, Financial Services, FinTech &amp; Regulatory, CAMS</p>
<a href="https://ecovis.lt/team/inga-karulaityte-en/" class="button primary" >
		<span>Learn more →</span>
	</a>



		</div>
					</div>

	

</div>
<div class="row"  id="row-2041101584">


	<div id="col-1016848873" class="col small-12 large-12"  >
				<div class="col-inner"  >
			
			

<div class="row"  id="row-1961833991">


	<div id="col-332101320" class="col small-12 large-12"  >
				<div class="col-inner"  >
			
			

<p>Inga is a leading adviser on financial services regulation, FinTech, payments, crypto-assets, AML/CTF, sanctions and technology-driven regulatory matters. She is rated and recognised by prestigious legal directories such as Chambers and Partners, Legal 500, and IFLR1000.</p>
<p>She leads ECOVIS ProventusLaw&#8217;s FinTech, Banking &amp; Finance practice and helps innovative and regulated businesses turn complex legal requirements into clear, practical strategies for entering markets, launching products and scaling across the Baltics and EU.</p>
<p>Her experience includes advising businesses navigating fast-changing regulatory frameworks, managing licensing and compliance challenges, and developing solutions that support growth while meeting the highest regulatory standards.</p>
<p>Languages: English, Lithuanian, Russian</p>
<p><a href="mailto:Inga.karulaityte@ecovis.lt" style="color:#c6093b;text-decoration:none;">Inga.karulaityte@ecovis.lt</a></p>
<p><a href="https://ecovis.lt/team/inga-karulaityte-en/" style="color:#c6093b;text-decoration:none;">Profile →</a></p>
<p><a href="https://www.linkedin.com/in/inga-karulaityte-42350721/" style="color:#c6093b;text-decoration:none;">LinkedIn →</a></p>

		</div>
					</div>

	

</div>

		</div>
					</div>

	

</div>

		</div>

		
<style>
#section_13361157 {
  padding-top: 20px;
  padding-bottom: 20px;
  background-color: rgb(193, 193, 193);
}
#section_13361157 .section-bg-overlay {
  background-color: rgba(255, 255, 255, 0.85);
}
</style>
	</section>
	

	<section class="section" id="section_11883562">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_11883562 {
  padding-top: 20px;
  padding-bottom: 20px;
}
</style>
	</section>
	

	<section class="section" id="section_626405421">
		<div class="section-bg fill" >
									<div class="section-bg-overlay absolute fill"></div>
			

		</div>

		

		<div class="section-content relative">
			

<div class="row row-large align-middle"  id="row-841932548">


	<div id="col-1257170871" class="col medium-6 small-12 large-6"  >
				<div class="col-inner"  >
			
			

	<div class="img has-hover x md-x lg-x y md-y lg-y" id="image_561798419">
								<div class="img-inner dark" >
			<img decoding="async" width="803" height="803" src="https://ecovis.lt/wp-content/uploads/2026/06/Loreta_Andziulyte.webp" class="attachment-large size-large" alt="" srcset="https://ecovis.lt/wp-content/uploads/2026/06/Loreta_Andziulyte.webp 803w, https://ecovis.lt/wp-content/uploads/2026/06/Loreta_Andziulyte-300x300.webp 300w, https://ecovis.lt/wp-content/uploads/2026/06/Loreta_Andziulyte-150x150.webp 150w, https://ecovis.lt/wp-content/uploads/2026/06/Loreta_Andziulyte-768x768.webp 768w" sizes="(max-width: 803px) 100vw, 803px" />						
					</div>
								
<style>
#image_561798419 {
  width: 100%;
}
</style>
	</div>
	


		</div>
					</div>

	

	<div id="col-1947286049" class="col medium-6 small-12 large-6"  >
				<div class="col-inner text-left"  >
			
			

<h2>Loreta Andziulytė</h2>
<p>Partner, Attorney-at-law, Corporate, M&#038;A, Technology &#038; Data Protection, Employment, CIPP/E </p>
<a href="https://ecovis.lt/team/loreta-andziulyte-en/" class="button primary" >
		<span>Learn more →</span>
	</a>



		</div>
					</div>

	

</div>
<div class="row"  id="row-129388108">


	<div id="col-1980477916" class="col small-12 large-12"  >
				<div class="col-inner"  >
			
			

<div class="row"  id="row-472712879">


	<div id="col-108542879" class="col small-12 large-12"  >
				<div class="col-inner"  >
			
			

<p>Loreta Andziulytė is a highly experienced adviser on employment, FinTech, corporate and M&amp;A matters, technology, data protection and regulatory issues. She advises businesses and international counsel on complex, cross-border matters throughout the business lifecycle — from market entry, establishment and investment to transactions, workforce management, restructuring and ongoing operations.</p>
<p>Her practice combines strong commercial and regulatory insight with a practical understanding of the challenges faced by technology-driven financial services and other regulated businesses. Loreta regularly supports clients on employment strategy and disputes, corporate governance, transactions, technology arrangements, data protection and compliance matters.</p>
<p>Loreta is recognised in Chambers Europe for Employment and is also rated by FinTech Legal for her work in the FinTech sector.</p>
<p>Languages: English, Lithuanian, Russian</p>
<p><a href="mailto:Loreta.andziulyte@ecovis.lt" style="color:#c6093b;text-decoration:none;">Loreta.andziulyte@ecovis.lt</a></p>
<p><a href="https://ecovis.lt/team/loreta-andziulyte-en/" style="color:#c6093b;text-decoration:none;">Profile →</a></p>
<p><a href="https://www.linkedin.com/in/loreta-andziulyte-4b7b9510/" style="color:#c6093b;text-decoration:none;">LinkedIn →</a></p>

		</div>
					</div>

	

</div>

		</div>
					</div>

	

</div>

		</div>

		
<style>
#section_626405421 {
  padding-top: 20px;
  padding-bottom: 20px;
  background-color: rgb(193, 193, 193);
}
#section_626405421 .section-bg-overlay {
  background-color: rgba(255, 255, 255, 0.85);
}
</style>
	</section>
	

	<section class="section" id="section_1307350970">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_1307350970 {
  padding-top: 20px;
  padding-bottom: 20px;
}
</style>
	</section>
	
<h2 style="line-height: 1.2;">From Copenhagen to the Baltics</h2>
<p>Legal expertise across Lithuania, Latvia and Estonia.</p>
<p>ECOVIS ProventusLaw supports international businesses and law firms with cross-border matters throughout the Baltic region.</p>

	<section class="section" id="section_1732575333">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_1732575333 {
  padding-top: 10px;
  padding-bottom: 10px;
}
</style>
	</section>
	

	<section class="section" id="section_2092071030">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<h2 style="line-height: 1.2;">Connected to the wider ECOVIS network</h2>
<p>Denmark · Baltics · International</p>
<p>ECOVIS ProventusLaw is part of ECOVIS International, connecting local professional expertise across jurisdictions. It has over 16,000 people operating in more than 90 countries. Its consulting focus and core competencies lie in tax consultation, accounting, auditing, and legal advice.</p>
<p>For matters extending beyond the Baltics, the wider ECOVIS network can provide additional local connections and multidisciplinary support.</p>
<p><a href="https://global.ecovis.com/" rel="nofollow" style="color:#c6093b;text-decoration:none;">Explore ECOVIS International →</a></p>
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_2092071030 {
  padding-top: 0px;
  padding-bottom: 0px;
}
</style>
	</section>
	

	<section class="section" id="section_934027134">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<h2>One Baltic region. Three local markets.</h2>
<p>Lithuania · Latvia · Estonia</p>
<p>The Baltic states are closely connected markets, but each has its own legal, regulatory and business environment.</p>
<p>Our Baltic presence allows us to combine local jurisdiction-specific expertise with a broader regional perspective — supporting matters in one market or coordinating legal needs across all three.</p>
<p>For international counsel, this means one point of contact for Baltic legal matters, with access to local expertise where it matters.</p>
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_934027134 {
  padding-top: 10px;
  padding-bottom: 10px;
}
</style>
	</section>
	

	<section class="section" id="section_1382033310">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<h2>Supporting business across the Baltics</h2>
<p>Investing and doing business in the Baltics</p>
<p>M&amp;A · Investments · Corporate · Commercial</p>
<p>We advise international businesses and counsel on acquisitions, investments, corporate matters, commercial arrangements and other transactions involving Baltic businesses and operations.</p>
<style>ul li::marker { color: #c6093b; }</style>
<h3>Entering or expanding across the region</h3>
<ul>
<li>Market entry</li>
<li>Establishment</li>
<li>Licensing</li>
<li>Regulatory requirements</li>
</ul>
<p>We support businesses entering the Baltic markets, establishing local operations and navigating the legal requirements that come with expansion.</p>
<h3>Financial services &amp; FinTech</h3>
<ul>
<li>Payments</li>
<li>Financial services</li>
<li>MiCA</li>
<li>AML/CTF</li>
<li>Sanctions</li>
<li>DORA</li>
</ul>
<p>Our team has particular experience advising financial services and technology-driven businesses on licensing, regulatory compliance and rapidly evolving European regulatory frameworks.</p>
<h3>Technology &amp; data</h3>
<ul>
<li>Data protection</li>
<li>IT</li>
<li>TMT</li>
<li>Digital business</li>
<li>Technology regulation</li>
</ul>
<p>We advise technology businesses and companies operating in digital markets on data protection, technology arrangements, telecommunications and regulatory requirements.</p>
<h3>Employment &amp; business operations</h3>
<ul>
<li>Employment</li>
<li>Commercial matters</li>
<li>Compliance</li>
</ul>
<p>From establishing a local team to managing ongoing operations, we provide practical legal support throughout the business lifecycle.</p>
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>


		</div>

		
<style>
#section_1382033310 {
  padding-top: 10px;
  padding-bottom: 10px;
}
</style>
	</section>
	

	<section class="section" id="section_1007621109">
		<div class="section-bg fill" >
									
			

		</div>

		

		<div class="section-content relative">
			

<h2>Working with international counsel</h2>
<p>A Baltic legal partner for cross-border matters</p>
<p>When a transaction or business expansion reaches the Baltics, international counsel needs local expertise that understands both the jurisdiction and the wider commercial context.</p>
<p>We work with international law firms, advisers and businesses as local counsel and referral partners.</p>
<p>Local expertise. Regional perspective. We can support you with:</p>
<h3>Local legal advice</h3>
<p>Practical advice on the legal and regulatory environment in Estonia, Latvia and Lithuania.</p>
<h3>Cross-border transactions</h3>
<p>Local support for international M&amp;A, investments and other transactions involving Baltic businesses.</p>
<h3>Market entry and expansion</h3>
<p>Legal support when clients establish or expand operations in one or more Baltic markets.</p>
<h3>Regulated sectors</h3>
<p>Specialist advice for financial services, FinTech, payments, crypto-assets and other regulated businesses.</p>
<h3>Ongoing cooperation</h3>
<p>A local legal partner your firm can work with on Baltic matters as they arise.</p>

		</div>

		
<style>
#section_1007621109 {
  padding-top: 10px;
  padding-bottom: 10px;
}
</style>
	</section>
	
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>

	<div id="gap-152286921" class="gap-element clearfix" style="display:block; height:auto;">
		
<style>
#gap-152286921 {
  padding-top: 30px;
}
</style>
	</div>
	

<h2>Explore our CEE resources</h2>
<p>Doing Business in Central and Eastern Europe</p>
<p>Our CEE Guide provides practical information for businesses and advisers considering investment, expansion and business operations across Central and Eastern Europe.</p>
<p><a href="https://www.ecovis.com/cee/cee-guide/" rel="nofollow" style="color:#c6093b;text-decoration:none;">Explore the CEE Guide →</a></p>
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>

	<div id="gap-1999165505" class="gap-element clearfix" style="display:block; height:auto;">
		
<style>
#gap-1999165505 {
  padding-top: 30px;
}
</style>
	</div>
	

<h2>RegRally Insights</h2>
<p>Regulatory developments that matter to businesses</p>
<p>Our RegRally Insights provide practical updates on regulatory developments affecting businesses, including: Payments · Crypto &amp; Investments · AML/CTF · Sanctions · Data &amp; ICT · Consumer Protection · Employment</p>
<p><a href="https://www.linkedin.com/pulse/regrally-insights-regulatory-compliance-updates-ecovisproventuslaw-i5ylf/" style="color:#c6093b;text-decoration:none;">Explore RegRally Insights →</a></p>
<div class="is-divider divider clearfix" style="margin-top:0px;margin-bottom:0px;max-width:70px;height:2px;background-color:rgb(198, 9, 59);"></div>

	<div id="gap-409026939" class="gap-element clearfix" style="display:block; height:auto;">
		
<style>
#gap-409026939 {
  padding-top: 30px;
}
</style>
	</div>
	

<h2>Will you be in Copenhagen?</h2>
<p>If you are attending the IBA Annual Conference 2026 and would like to discuss a matter involving Lithuania, Latvia or Estonia, we would be pleased to meet.</p>
<p>Whether you are looking for local counsel, a Baltic referral partner or simply want to exchange views on opportunities in the region, get in touch.</p>
<h3>Inga Karulaitytė</h3>
<p><a href="mailto:Inga.karulaityte@ecovis.lt" style="color:#c6093b;text-decoration:none;">Inga.karulaityte@ecovis.lt</a></p>
<p><a href="https://www.linkedin.com/in/inga-karulaityte-42350721/" style="color:#c6093b;text-decoration:none;">LinkedIn →</a></p>
<h3>Loreta Andziulytė</h3>
<p><a href="mailto:Loreta.andziulyte@ecovis.lt" style="color:#c6093b;text-decoration:none;">Loreta.andziulyte@ecovis.lt</a></p>
<p><a href="https://www.linkedin.com/in/loreta-andziulyte-4b7b9510/" style="color:#c6093b;text-decoration:none;">LinkedIn →</a></p>

<p>The post <a href="https://ecovis.lt/iba-annual-conference-2026-in-copenhagen/">IBA Annual Conference 2026 in Copenhagen, 4–9 October</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</title>
		<link>https://ecovis.lt/ai-act-transparency-guidelines/</link>
		
		<dc:creator><![CDATA[jkwer892]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 12:30:10 +0000</pubDate>
				<category><![CDATA[Data protection & ICT]]></category>
		<category><![CDATA[Insight]]></category>
		<guid isPermaLink="false">https://ecovis.lt/?p=11631</guid>

					<description><![CDATA[<p>The European Commission’s Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (20 July 2026), and the accompanying Code of Practice on Transparency of AI-generated Content – what they mean in practice, and when AI-generated content must be marked and labelled</p>
<p>The post <a href="https://ecovis.lt/ai-act-transparency-guidelines/">AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1>AI made it? Say so. What the Commission&rsquo;s new AI Act transparency Guidelines require</h1>
<p>The European Commission&rsquo;s Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (20 July 2026), and the accompanying Code of Practice on Transparency of AI-generated Content &ndash; what they mean in practice, and when AI-generated content must be marked and labeled.</p>
<h2>Summary</h2>
<ul>
<li><em><strong>Four duties, two owners.</strong> Providers must design interactive systems to disclose themselves (Article 50(1)) and embed an invisible, machine-readable mark in synthetic output (Article 50(2)); deployers must notify people exposed to emotion-recognition and biometric categorization systems (Article 50(3)) and add a visible label on deep fakes and on public-interest text (Article 50(4)). The duties are cumulative, none discharges another, and the same organization frequently owes several.</em></li>
<li><em><strong>Not every AI output has to be marked.</strong> Standard editing and minor alterations, AI translation, formatting, source code, single words and captions, machine-to-machine data, and genuine closed-loop internal B2B material all fall outside the scope of duty. That is where most of the practical relief lies.</em></li>
<li><em><strong>AI-generated or manipulated public-interest text deserves particular attention.</strong> AI-touched investor and sustainability reports on a company website need a visible label unless genuine human review and editorial responsibility are both documented &ndash; and that exception collapses the moment AI edits the text after editorial sign-off.</em></li>
<li><em><strong>Article 50 does not stop at the EU border.</strong> A provider or deployer established outside the EU owes the same duties where the output of its system is foreseeably used in the Union &ndash; so a third-country group entity generating content targeted at EU audiences is in scope.</em></li>
<li><em><strong>A label is not a license.</strong> Marking and labeling answer the question &ldquo;is this AI?&rdquo;, not &ldquo;is this allowed?&rdquo;. A properly labeled deep fake can still be unlawful on other grounds, and a 50(3) notice does not legitimize a deployment prohibited under Article 5 or unlawful under data protection law.</em></li>
<li><em><strong>One deadline has passed, one is coming</strong> &ndash; and the fines are real. Chatbot and voice-assistant disclosure under Article 50(1) has been required since 2 August 2026, with no grandfathering; providers of generative systems already on the market have until 2 December 2026 to bring Article 50(2) marking into conformity. Non-compliance amounts to EUR 15 000 000 or 3% of the total worldwide annual turnover, whichever is higher, with RRT supervising in Lithuania.</em></li>
</ul>
<p>Since 2 August 2026, a new layer of Regulation (EU) 2024/1689 (the &ldquo;AI Act&rdquo;) applies to almost every business that lets customers talk to a chatbot, generates images or text with artificial intelligence (AI), or edits media with AI tools.</p>
<p>Article 50 of the AI Act imposes a set of <strong>transparency obligations</strong>: people must be told when they are dealing with AI, and AI-generated or manipulated content must be marked and, in defined cases, visibly labeled. On 20 July 2026, the European Commission (the &ldquo;Commission&rdquo;) adopted detailed Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (the &ldquo;Guidelines&rdquo;), complemented by the Code of Practice on Transparency of AI-generated Content (the &ldquo;Code of Practice&rdquo;).</p>
<p>The Guidelines are non-binding &ndash; only the Court of Justice can give an authoritative interpretation of the AI Act &ndash; but they are the clearest practical map of what is in scope, what is out of scope, and who has to do what.</p>
<p>This article walks through the four obligations, with the emphasis on the question clients actually ask: <strong>what has to be marked or labeled as AI, and by whom?</strong> It pays particular attention to the financial market and its participants &ndash; banks, payment and electronic money institutions, investment firms, crypto-asset service providers, insurers and listed issuers &ndash; for whom AI-touched investor communications, corporate and sustainability reports, client-facing chatbots, marketing content and biometric onboarding tools sit squarely inside Article 50, on top of the disclosure and conduct duties they already owe under financial services regulation.</p>
<h2>The four obligations at a glance</h2>
<p>Article 50 contains four distinct transparency duties, each attaching to a different type of AI system or output, and each falling on either the <strong>provider</strong> (the entity that develops the system and places it on the market under its own name) or the <strong>deployer</strong> (the entity that uses the system under its own authority, unless the use is purely personal and non-professional). The distinction matters because the same organization can be both at once &ndash; for example, a firm that builds an in-house generative tool and then uses it to produce deep fakes wears both hats. The deployer side reaches wider than most clients assume: businesses, public-sector bodies, media outlets, advertising and marketing agencies, and any other legal or natural person using AI content in a professional or economic activity &ndash; including influencers monetizing social media. Purely personal, non-professional use is outside Article 50 altogether.</p>
<ul>
<li><strong>Article 50(1) &ndash; interactive AI.</strong> The provider must design the system so that a person is informed that they are interacting with an AI. Think chatbots, voice assistants, and AI agents.</li>
<li><strong>Article 50(2) &ndash; marking of synthetic content.</strong> The provider must ensure that AI-generated or manipulated audio, images, videos, or text are marked in a machine-readable format and detectable as artificial.</li>
<li><strong>Article 50(3) &ndash; emotion recognition and biometric categorization.</strong> The deployer must inform people exposed to such a system that it is operating.</li>
<li><strong>Article 50(4) &ndash; deepfakes and certain text.</strong> The deployer must clearly and visibly label deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest.</li>
</ul>
<p>A single system can trigger several of these at once. An image generator embedded in a chatbot engages 50(1) and 50(2) for the provider; if the deployer uses it to create a deep fake, 50(4) applies on top. The obligations are cumulative, not alternative.</p>
<p><strong>Article 50 does not stop at the EU border.</strong> A provider or deployer established outside the EU is caught where the output of its AI system is used in the Union &ndash; so a third-country group entity generating content that is disseminated to, or targeted at, EU audiences owes the same duties as an EU actor. The trigger is foreseeable use of the output in the Union: a deployer who directs or authorizes EU distribution, including by posting deep fakes on the open internet, is in scope, whereas purely incidental or unforeseeable downstream use that reaches the Union through channels outside the actor&rsquo;s control is not.</p>
<h2>Two kinds of &ldquo;marking&rdquo; &ndash; and why the difference matters</h2>
<p>The word &ldquo;marking&rdquo; serves two very different functions in Article 50, and conflating them is the most common source of confusion. It is worth pinning down the distinction before going further.</p>
<p><strong>Machine-readable marking (Article 50(2))</strong> is invisible plumbing. It is a technical signal &ndash; a watermark, metadata, a cryptographic provenance tag, a fingerprint &ndash; embedded in the content so that software can later identify it as AI-generated. It is the <strong>provider&rsquo;s</strong> job, and it applies to essentially all synthetic audio, image, video and text output of the system.</p>
<p><strong>Visible labeling (Article 50(4))</strong> is a disclosure a person can see or hear &ndash; a caption, a banner, a spoken statement &ndash; telling the audience that a deep fake or a public-interest text is artificial. It is the <strong>deployer&rsquo;s</strong> job, and it applies to a much narrower set of content.</p>
<p>The Guidelines are explicit that these do not substitute for one another. A deployer cannot discharge the 50(4) labeling duty by pointing to the provider&rsquo;s machine-readable mark, because that mark is not perceptible to the ordinary viewer without special tools. Conversely, a visible label does not relieve the provider of the duty to provide a machine-readable marking under 50(2).</p>
<h2>What must be marked under Article 50(2)</h2>
<p>This is the obligation with the widest reach, and the one clients most often ask about. It applies where all of the following are true: the system is an AI system; it generates or manipulates synthetic content; the content is <strong>audio, image, video or text</strong> (an exhaustive list, but one that includes multimodal, 3-D, and virtual and augmented reality (VR/AR) output); and none of the exceptions applies.</p>
<p>Crucially, content does not have to be wholly AI-generated to count. Content mixed with human-created material still qualifies as synthetic if the AI-generated or manipulated part falls within one of the four modalities. &ldquo;Generation&rdquo; means creating new material (an AI-drawn image, a synthesized song); &ldquo;manipulation&rdquo; means altering existing content beyond standard editing (a face swap, a voice clone).</p>
<p><strong>Marking is only half of it.</strong> Article 50(2) imposes two cumulative duties: the provider must mark the output in a machine-readable format and ensure a means of detection is available to the people exposed to it, one that returns a human-readable result indicating whether the content is AI-generated or manipulated. A mark that no one can read back is not compliance. Where the provider relies on another actor for detection, it remains responsible for ensuring that the solution works and that the result is clearly shown at first exposure.</p>
<h3>In scope &ndash; must be marked</h3>
<ul>
<li>AI-generated summaries of text, or paraphrasing/rewriting that changes style, structure or meaning.</li>
<li>Removal, replacement or insertion of objects or persons in images and videos that change the substance; face replacement or substantial facial modification.</li>
<li>Synthesis of a specific person&rsquo;s voice, or a realistic video of events that did not occur; altering a person&rsquo;s body shape or skin color.</li>
<li>Composite images or clips that modify the depiction of persons, objects, events or facts.</li>
<li>AI agent output that is perceptible to a person as audio, image, video or text.</li>
</ul>
<h3>Out of scope &ndash; no marking required</h3>
<p>The Guidelines carve out a long list of things that do <strong>not</strong> have to be marked, which is just as useful to know:</p>
<ul>
<li><strong>Standard editing and minor alterations &ndash;</strong> grammar and spell-checking, minor stylistic polishing, AI-generated translations, formatting and format conversion, noise reduction, minor cropping or color correction, red-eye removal, background blurring, video stabilization, and converting black-and-white to color.</li>
<li><strong>Non-substantial changes &ndash;</strong> anything that does not significantly alter the input data or its meaning, style or intent.</li>
<li><strong>Source code &ndash;</strong> code in any programming, scripting, markup, query or configuration language (including SDKs, SQL, YAML, JSON, APIs), and integral comments.</li>
<li><strong>Very short outputs &ndash;</strong> single words, image captions, alt-text, UI labels, icon-scale graphics.</li>
<li><strong>Machine-to-machine output</strong> processed automatically and never perceived by a person; internal analytical extraction and structuring of data; mere reproduction, ranking or arrangement of existing content (playlists, recommender systems).</li>
<li><strong>Closed-loop and industrial output &ndash;</strong> strictly technical, business-to-business (B2B) output, perceived only by a limited pre-defined set of professionals inside the organization, not shared externally, with appropriate safeguards. Real-time ephemeral content (e.g. in games or VR) consumed immediately and not stored may also be exempt where marking is not technically feasible, and an in-experience notice is provided.</li>
<li><strong>Law enforcement use</strong> authorized by law to detect, prevent, investigate or prosecute criminal offences.</li>
</ul>
<p>The technical solution must be <strong>effective, interoperable, robust and reliable</strong>, as far as technically feasible and in line with the state of the art. Providers may rely on an adequate Code of Practice to demonstrate compliance; those who do not adhere to one must provide equivalent alternative measures and should expect closer scrutiny and more information requests.</p>
<h2>What must be labeled under Article 50(4)</h2>
<p>This obligation sits on <strong>deployers</strong> and concerns visible, perceivable disclosure. It has two limbs.</p>
<h3>Deepfakes</h3>
<p>A &ldquo;deepfake&rdquo; is AI-generated or manipulated image, audio or video content that (i) appreciably resembles (ii) an existing (iii) person, object, place, entity or event, and (iv) would falsely appear to a person to be authentic or truthful. &ldquo;Existing&rdquo; is read broadly: something that exists, plausibly could exist, or could have plausibly existed. Content that defies physics or biology &ndash; a dragon, an elephant driving a car &ndash; is not a deepfake, because it cannot mislead.</p>
<p>Minor or cosmetic AI manipulation of existing content does not make it a deepfake in the first place, where the change has too little effect on how a viewer perceives the content&rsquo;s authenticity or truthfulness &ndash; for example, editing out a background passer-by, adjusting lighting or color, noise reduction, re-scaling or file compression. This is a threshold question, not an exemption: such content is simply not a deep fake, so no labelling duty arises. Whether a given edit stays on this side of the line is context-dependent: the Guidelines contrast these cosmetic operations with substantial AI editing of journalistic images, where the expectation of authenticity is high enough that a similar change may affect perceived authenticity and cross into deep fake territory.</p>
<p>The fourth criterion is assessed <strong>objectively</strong> and in context; the deployer&rsquo;s intention to deceive is not required. Where the foreseeable audience does not expect the content to be authentic &ndash; for instance, standard special effects in a movie &ndash; the content may not &ldquo;falsely appear&rdquo; authentic and so falls outside the definition. But fully AI-generated actors, digital replicas of real or deceased actors, de-aging, or non-authentic depictions in documentaries generally will be deepfakes.</p>
<p><strong>Deepfakes must be clearly and distinctly labeled.</strong> A lighter regime applies to content that is <strong>evidently</strong> artistic, creative, satirical, fictional or analogous: the disclosure need only be made in a manner that does not hamper enjoyment of the work, but disclosure is still required, and the &ldquo;evidently&rdquo; threshold is read strictly. <strong>Two limits keep this regime narrow.</strong> Where content mixes an informative and a creative character, the informative character prevails labeling, and full labeling applies; and the lighter regime is, in any event, subject to appropriate safeguards for third-party rights, so it is no justification for disregarding data-protection or intellectual-property obligations.</p>
<h3>Public-interest text</h3>
<p>AI-generated or manipulated <strong>text published to inform the public on matters of public interest</strong> must also be labeled. &ldquo;Published&rdquo; means accessible to an indeterminate, fairly large group; &ldquo;public interest&rdquo; covers politics, public administration, justice, fundamental rights, public health and safety, the environment, consumer safety, and economic, financial, scientific or cultural developments meriting public debate.</p>
<p>There is an important <strong>exception</strong>: text that has undergone genuine <strong>human review or editorial control</strong> and for which a natural or legal person holds <strong>editorial responsibility</strong> need not be labeled. Both conditions are cumulative. A superficial spell-check, an automated review, or a mere editorial policy will not do &ndash; the review must engage with the substance, and fact-checking is the minimum. If AI makes any substantive change after editorial sign-off, the exception falls away.</p>
<p>For a regulated financial entity, note the concrete examples the Guidelines give as <strong>in scope</strong>: AI-manipulated corporate reports containing investor information on a listed company&rsquo;s website, and AI-generated sustainability reports &ndash; both of which need labeling unless the human-review/editorial-responsibility exception is satisfied. Conversely, an AI-manipulated advice text prepared by a consultant for a single client on regulatory compliance is <strong>not</strong> &ldquo;published&rdquo; and falls outside 50(4).</p>
<h2>How to label in practice</h2>
<p>Article 50 does not dictate wording. The Code of Practice does the practical work: the AI Office has published three EU icons &ndash; AI involved, fully AI-generated, and human content modified by AI &ndash; free to use, and testing showed that an icon on its own is not enough. The icon plus a few plain words are what people actually understand. &ldquo;AI&rdquo; is the only abbreviation to use.</p>
<p>What that looks like in practice. An icon and &ldquo;Image created with AI&rdquo; in the caption of a social media post &ndash; not in the small print. A spoken line in the first seconds of a podcast produced with a synthetic voice. A badge at the top of an AI-drafted news summary, not in the website footer. A mark that stays in the corner of the screen while an AI presenter is speaking. Give the icon alt text so a screen reader conveys it, leave a temporary label up long enough to be read, and use the same icon and the same words everywhere.</p>
<p><strong>A label is not a license.</strong> The Guidelines are emphatic that complying with Article 50 does not make the content or its use lawful. A properly labeled deep fake can still be unlawful on other grounds &ndash; child sexual abuse material, non-consensual intimate imagery, trademark or copyright infringement, misleading advertising &ndash; and a 50(3) notice does not legitimize an emotion-recognition deployment that is prohibited under Article 5 or unlawful under data protection law.</p>
<p>Marking and labeling answer the question <strong>&ldquo;is this AI?&rdquo;,</strong> not <strong>&ldquo;is this allowed?&rdquo;</strong> The two assessments are separate.</p>
<h2>The other two obligations, briefly</h2>
<h3>When must a chatbot tell users that they are interacting with AI?</h3>
<p>Providers of systems that interact <strong>directly</strong> with people &ndash; chatbots, voice assistants, AI companions, AI agents &ndash; must design them so the person is told they are dealing with AI, at the latest at the first interaction. The disclosure must be clear and in context: a first-turn message, a spoken statement, a persistent badge. Burying it in terms and conditions, or relying on a vague reference to an &ldquo;assistant&rdquo; or &ldquo;this system uses LLMs&rdquo;, is not enough.</p>
<p>There is an <strong>obviousness</strong> exception &ndash; no disclosure is needed where it would be obvious to a reasonably well-informed, observant and circumspect person that they are dealing with AI. But the Guidelines read this narrowly: general awareness that chatbots exist does not mean people recognize them in a given interaction, and the exception is unavailable where vulnerable groups (children, the elderly, the less digitally literate) may be exposed. A professional-only internal helpdesk assistant may qualify; a public-facing helpdesk chatbot generally will not.</p>
<p><strong>AI agents carry an extra layer.</strong> An agent must disclose not only its artificial nature but also the person on whose behalf it acts, reflecting the need for transparency regarding both its origin and delegated authority. Where the provider cannot know in advance whether an agent will meet a natural person, it must be designed to disclose itself in every situation where interaction with a person is reasonably likely, including in multi-agent chains where another agent is the one facing the person. Agents should also re-disclose to the person instructing them at key steps such as authorization, reporting and validation, and at every new interaction.</p>
<h3>Emotion recognition and biometric categorization &ndash; Article 50(3)</h3>
<p>Deployers of these systems must inform the people exposed to them that the system is operating &ndash; for example, a notice at the entrance to a space where facial images are captured to infer age, or a pop-up before a game that reads the player&rsquo;s emotions. This applies whether the system runs in real time or after the fact, and to any biometric categorization system (unless outright prohibited under Article 5).</p>
<h2>Timing, accessibility and penalties</h2>
<p>Whatever the obligation, Article 50(5) requires the information to be given <strong>clearly and distinguishably, at the latest at the first interaction or exposure</strong>, and in an accessible format. &ldquo;First exposure&rdquo; means the start of a video featuring a deepfake, the start of a public-interest text, or the moment a person scrolling through social media encounters the content. Where children are foreseeably in the audience, the disclosure must be child-friendly and age-appropriate.</p>
<p>Non-compliance is not trivial. Fines can reach <strong>EUR 15 000 000 or 3% of total worldwide annual turnover</strong>, whichever is higher (EU institutions face up to EUR 750 000; small and medium-sized enterprises (SMEs) and start-ups face the lower of the two figures). Enforcement sits with national market surveillance authorities, the AI Office for systems based on general-purpose AI (GPAI) models, and the European Data Protection Supervisor (EDPS) for EU institutions.</p>
<p>In Lithuania, the Communications Regulatory Authority (RRT) has already issued public guidance of its own on when AI-generated content must be marked and when it need not be &ndash; an early signal that the national supervisor intends to engage with these obligations actively rather than wait for complaints.</p>
<p><strong>On timing of application:</strong> Article 50 has applied since 2 August 2026 to all in-scope systems on the market on that date, regardless of when they were placed. A targeted grandfathering rule under the AI Omnibus gives providers of existing generative systems until 2 December 2026 to bring the 50(2) marking into conformity &ndash; but the 50(1) interaction disclosure had to be in place by 2 August 2026. Content generated before 2 August 2026 need not be marked or labeled retroactively, but pre-existing text published on or after that date does need labeling.</p>
<h2>What should businesses pay attention to?</h2>
<p>Four practical points to act on:</p>
<ul>
<li><strong>Separate the two &ldquo;markings&rdquo;.</strong> Providers owe invisible, machine-readable markings on synthetic output (50(2)); deployers owe visible labels on deepfakes and public-interest text (50(4)). One does not cover the other.</li>
<li><strong>Get the label right &ndash; and know what needs none.</strong> The EU icon, plus a short, plain-language line (&ldquo;AI&rdquo; is the only abbreviation to use), placed where the content is consumed, with alt text and an audio disclaimer when there is nothing to see. Standard editing, translation, formatting, source code, short labels and genuine internal B2B output fall outside the marking duty entirely &ndash; that is where much of the practical relief lies.</li>
<li><strong>Watch the text limb closely.</strong> AI-touched investor and sustainability reports on a company website count as text published on matters of public interest, so they are squarely in scope unless the human-review and editorial-responsibility exception is properly documented &ndash; and that exception collapses if AI edits the text after sign-off.</li>
<li><strong>Consider the Code of Practice.</strong> Adhering to the adequate Code of Practice is the most predictable way to demonstrate compliance with the 50(2) and 50(4) content obligations; non-signatories should run a gap analysis against it and keep evidence of equivalent measures.</li>
</ul>
<p><strong>Businesses introducing AI systems should assess Article 50 alongside their wider AI governance, data protection and intellectual property obligations. ECOVIS ProventusLaw can assist with this assessment and the implementation of appropriate compliance measures.</strong></p>
<p>This article reflects ECOVIS ProventusLaw&#8217;s interpretation of the Commission&#8217;s non-binding Guidelines and Code of Practice and is provided for general information purposes only. It does not constitute legal advice; specific advice should be obtained before acting on any part of it.</p>
<div class="article-authors">
<h2 class="article-authors__title">About the Author</h2>
<div id="text-2347073171" class="text"><strong>Augustinas Gečas</strong> is a Junior Associate in the FinTech group at ECOVIS ProventusLaw, where he focuses on FinTech regulation and the legal aspects of artificial intelligence, supporting clients navigating the evolving Baltic and EU regulatory landscape.</div>
</div>


<p>The post <a href="https://ecovis.lt/ai-act-transparency-guidelines/">AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require</a> appeared first on <a href="https://ecovis.lt">ECOVIS ProventusLaw</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
