Other Developments
Workplace recording guidance issued by the DVI in 2026 permits employees to record workplace meetings on a legitimate-interest basis, provided clear internal procedures are followed. This is an uncertain-confidence finding drawn from a single trade source, but it represents a notable shift in how the legitimate-interest basis is being applied to an employee-facing recording scenario, an area that had previously sat in some ambiguity under Latvian guidance.
Cross-border enforcement procedure is set to change at the EU level: Regulation (EU) 2025/2518, which lays down additional procedural rules for enforcement of the GDPR in cross-border cases, will apply from April 2027. This is a probable-confidence, forward-looking development that has not yet taken effect, and Latvian controllers involved in cross-border processing should treat it as a horizon item rather than a current operative requirement.
Cross-Monitor Connections
The Tet enforcement outcome, involving disclosure of customer data to debt-recovery services, touches on themes relevant to the financial-integrity monitor's interest in data-sharing practices among regulated entities, though this brief does not re-analyse that domain and links out to financial-integrity for any further exploration of debt-recovery-sector data practices. The 2026 workplace-recording guidance may also be of interest to employers assessing surveillance and monitoring practices tracked separately under other monitors' remits.
Outlook
With the Tet judgment now final, the near-term item to watch is whether the volume of DVI in-depth review proceedings (266 this reporting period) translates into a further wave of administrative-offence decisions in the next cycle. The exact date range covered by that 266-proceeding figure was not confirmable from the source reached this cycle and should be clarified in a future cycle. Separately, the April 2027 application date for Regulation (EU) 2025/2518 is a fixed horizon marker that will eventually require attention as it approaches, though it remains more than a year away and carries no immediate compliance implication.
1 earlier update not shown here.
Standing brief · as of 5 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Latvia receives its first full ten-module structured-claims baseline this cycle, and a challenger-fold review has corrected two stale case-law characterisations while surfacing a confirmed national variance on children's consent age. The Court of Justice of the European Union's Case C-439/19, concerning Latvia's public register of road-traffic penalty points, was decided by the Grand Chamber on 2021-06-22: the Court ruled that GDPR precludes the Latvian legislation permitting public disclosure and re-use of that data under Article 10 GDPR. A second referral, Case C-175/20, concerning a Latvian tax authority's request that an internet-advertising service provider supply taxpayer data, is understood to have been decided on 2022-02-24, with the Court finding that GDPR does not in principle preclude such a request, subject to Article 5(1) GDPR necessity, proportionality and time-limitation safeguards. The same review indicates that Latvia's Personal Data Processing Law is understood to set the child-consent age for information-society services at 13 years, exercising the GDPR Article 8(1) member-state option to lower the default age of 16.
Other Developments
Latvia's Data State Inspectorate (DVI) is Latvia's Article 51 GDPR supervisory authority and an EDPB member, headquartered in Riga. The Personal Data Processing Law, endorsed by the Cabinet of Ministers on 2018-03-06, implements GDPR into Latvian national law and has been in force since 2018-07-05. GDPR Article 7 requires consent as a lawful basis to be freely given, informed, specific and unambiguous, with genuine withdrawal ability, and Latvia's data subject rights framework is governed by GDPR together with the Personal Data Processing Law of 21 June 2018, with GDPR Chapter III applying directly in Latvia as an EU Member State. DVI's enforcement record has escalated over successive years: the authority imposed a €7,000 administrative fine on an online retailer in 2019 under GDPR Article 83(5)(b) and (e) for failing to comply with an Article 17 erasure request and for non-cooperation with the regulator; it fined HH Invest SIA €15,000 in December 2020 for providing insufficient information to a data subject; and it fined Lursoft €65,000 in 2021 for unlawful processing of personal data. Latvia's Augstākā tiesa (Senāts) has referred a preliminary-ruling question, Case C-507/23, to the CJEU concerning Article 82(1) GDPR compensation for non-material damage, including whether an apology can constitute compensation. On the accountability side, the EDPB has adopted Opinion 6/2024 on DVI's draft list of processing operations exempt from the Article 35(5) GDPR DPIA requirement, and DVI published guidance on 3 June 2026 confirming that an international group of companies may appoint a single Data Protection Officer provided each entity can easily communicate with them, while each entity remains responsible for its own compliance decisions. Organisations in Latvia are understood to be required to notify DVI of a Data Protection Officer's appointment. Reports suggest no Latvia-specific derogation from the standard GDPR Chapter V cross-border transfer regime has been confirmed, with adequacy, SCCs, BCRs and derogations applying directly. In the adtech space, a DVI preventive audit found that none of 29 websites operated by 26 large e-merchants ensured appropriate cookie consent was obtained, with three traders found in significant violation and 23 required to remediate; DVI's cookie guide of April 2022 clarifies that personalised and analytical cookies require consent while technical and functional cookies necessary for website operation do not. DVI also assessed compliance with both GDPR and the Law on Information Society Services 2004 in a preventive check of e-merchant cookie practices, has published guidance for employers on processing employee personal data, and is understood to have issued clarification in March 2026 on the personal-data rules applicable to handling student test papers. Reports suggest the Latvian Parliament may have adopted amendments to the Law on Administrative Liability introducing new procedures for accessing subscriber data and updating fine structures, though the amendments' commencement date has not been confirmed.
Cross-Monitor Connections
Latvia's algorithmic, biometric and surveillance-governance module intersects with EU AI Act implementation; this cycle's research routes that intersection to the artificial-intelligence monitor for AI-Act-first analysis rather than duplicating it here.
Outlook
Whether Latvia has exercised the GDPR Article 9(4) option to impose further conditions on genetic, biometric or health data processing remains unconfirmed. The finalisation status of DVI's Article 35(5) DPIA-exemption list following the EDPB's opinion has not been established. The substantive terms and commencement date of the Law on Administrative Liability amendments remain to be verified.