🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LV v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-05

Latvia

LV schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 26 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
10Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 4 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Latvia's data-protection enforcement environment shows a clear escalation this cycle. The Riga Regional Court has upheld the Data State Inspectorate's (DVI) EUR 1.2 million fine against Tet for unlawfully disclosing unverified customer personal data to debt-recovery services, and the judgment is now final and not subject to further appeal. Alongside this confirmed outcome, the DVI's own reporting shows substantial enforcement activity in its latest period: 266 in-depth review proceedings initiated, 143 violations identified, corrective measures applied in 62 cases, and seven administrative-offence decisions adopted, five of them fines for GDPR violations and two for failure to provide information to the DVI. Taken together, these figures point to a regulator operating at meaningful volume rather than through isolated high-profile cases alone.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

GDPR is directly applicable and the national implementing Law plus an active, EDPB-recognised supervisory authority are confirmed; territorial/material scope questions are being actively clarified via CJEU referrals rather than left as gaps.

Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by the Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenGDPR is directly applicable and the national implementing Law plus an active, EDPB-recognised supervisory authority are confirmed; territorial/material scope questions are being actively clarified via CJEU referrals rather than left as gaps.

Sub-modules (5)

Regulator And AuthorityGreen

DVI is confirmed as Latvia's Article 51 GDPR supervisory authority, listed on the EDPB member register with its Riga headquarters and its representative to the Board.

Claims (1):

  • The Data State Inspectorate (DVI), located at Elijas Street 17, Riga, LV-1050, is Latvia's GDPR supervisory authority and EDPB member.

Act And InstrumentsGreen

The Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the implementing bill on 6 March 2018.

Claims (1):

  • The Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the draft bill on 6 March 2018.

Material ScopeGreen

Material scope questions (e.g., obligations of internet-advertising service providers vis-à-vis tax-authority information requests) have reached the CJEU via a Latvian court referral, clarifying GDPR's material/temporal limits in a Latvian administrative-law context.

Claims (1):

  • The CJEU received a preliminary-ruling request from Latvia's Administratīvā apgabaltiesa (Regional Administrative Court) concerning the material and temporal limits of GDPR obligations applicable to internet-advertising service providers responding to tax-authority information requests.

Territorial ScopeAmber

No Latvia-specific territorial-scope derogation or extension beyond GDPR Article 3 was identified in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Regulator Registration And FilingAmber

No general processing-notification/filing regime was identified beyond GDPR's own framework; DPO-appointment notification to DVI is addressed under controller_processor_duties.dpo_requirements rather than here.

Absence provenance: unavailable. Searched: unavailable.

Category narrative101 words

Latvia's data-protection regime is anchored on the GDPR as directly-applicable EU law, implemented and supplemented domestically by the Personal Data Processing Law of 21 June 2018 (Fizisko personu datu apstrādes likums). The Data State Inspectorate (Datu valsts inspekcija, DVI), headquartered at Elijas Street 17, Riga LV-1050, is the Article 51 GDPR supervisory authority and sits as Latvia's representative on the EDPB. Material and territorial scope questions have been the subject of CJEU preliminary rulings originating from Latvian courts, including a referral from the Regional Administrative Court on the scope of GDPR obligations for internet-advertising service providers responding to tax-authority information requests.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedEDPB — The Data State Inspectorate (DVI), located at Elijas Street 17, Riga, LV-1050, is Latvia's GDPR supervisory authority and EDPB member.observed
  2. ConfirmedOneTrust DataGuidance — The Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the draft bill on 6 March 2018.observed
  3. ProbableEUR-Lex — The CJEU received a preliminary-ruling request from Latvia's Administratīvā apgabaltiesa (Regional Administrative Court) concerning the material and temporal limits of GDPR obligations applicable to internet-advertising service providers responding to tax-authority information requests.observed

#

Core consent rules track GDPR directly, but the special-categories sub-module carries live CJEU interpretive uncertainty and an unconfirmed Article 9(4) national-derogation status.

Primary frameworkGDPR Articles 6, 7 and 9; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — AmberCore consent rules track GDPR directly, but the special-categories sub-module carries live CJEU interpretive uncertainty and an unconfirmed Article 9(4) national-derogation status.

Sub-modules (4)

Lawful BasesAmber

No Latvia-specific supplement to the GDPR Article 6 lawful-basis enumeration was identified.

Absence provenance: unavailable. Searched: unavailable.

Special CategoriesAmber

A CJEU reference from Latvia's Constitutional Court tested the interpretation of Article 10 GDPR (criminal-offence data) in the context of a public traffic-penalty-points register, and GDPR Article 9(4) allows member states to impose further conditions on genetic/biometric/health data.

Claims (2):

  • Latvia's Satversmes tiesa referred to the CJEU the question of how to interpret 'processing of personal data relating to criminal convictions and offences' under Article 10 GDPR in the context of a public register of road-traffic penalty points.
  • GDPR Article 9(4) permits member states, including Latvia, to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data or health data; whether Latvia has exercised this derogation was not conclusively confirmed in this pass.

Pseudonymisation And AnonymisationAmber

No Latvia-specific pseudonymisation/anonymisation safe-harbour or definition beyond the GDPR baseline was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative74 words

Lawful bases and consent standards follow GDPR Articles 6 and 7 directly, with no confirmed Latvia-specific derogation identified for general lawful bases. Special-category processing has been the subject of a CJEU reference from Latvia's Satversmes tiesa (Constitutional Court) concerning Article 10 GDPR's treatment of criminal-offence/penalty-point data, and GDPR Article 9(4) permits member states to add further conditions on genetic, biometric and health data — whether Latvia has exercised this option was not conclusively confirmed.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedEDPB — Consent relied on as a lawful basis for processing must be freely given, informed, specific and unambiguous, with data subjects retaining a genuine ability to withdraw it.observed
  2. ProbableEUR-Lex — Latvia's Satversmes tiesa referred to the CJEU the question of how to interpret 'processing of personal data relating to criminal convictions and offences' under Article 10 GDPR in the context of a public register of road-traffic penalty points.observed
  3. UncertainEUR-Lex — GDPR Article 9(4) permits member states, including Latvia, to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data or health data; whether Latvia has exercised this derogation was not conclusively confirmed in this pass.observed

#

Rights framework is confirmed via direct GDPR effect and evidenced through an actual DVI enforcement decision on the erasure right; deadline-specific and portability/restriction sub-modules lack Latvia-specific confirmatory findings.

Primary frameworkGDPR Chapter III (Articles 12-23); Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenRights framework is confirmed via direct GDPR effect and evidenced through an actual DVI enforcement decision on the erasure right; deadline-specific and portability/restriction sub-modules lack Latvia-specific confirmatory findings.

Sub-modules (5)

Access RightGreen

Access and other data-subject rights are governed by GDPR Chapter III together with the Personal Data Processing Law of 21 June 2018.

Claims (2):

  • Latvia's data subject rights framework is governed by the GDPR together with the Personal Data Processing Law of 21 June 2018.
  • GDPR Chapter III, entitled 'Rights of the data subject', contains Articles 12 to 23, which apply directly in Latvia as an EU Member State.

Rectification And ErasureGreen

DVI has actively enforced the Article 17 erasure right, fining an online retailer for failing to execute an erasure request and for non-cooperation with the authority.

Claims (1):

  • DVI imposed a €7,000 fine on an online retailer in 2019 for failing to comply with a data subject's Article 17 erasure request and for non-cooperation with the supervisory authority.

Restriction And ObjectionAmber

No Latvia-specific restriction/objection finding was identified beyond the general GDPR framework.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityAmber

No Latvia-specific portability finding was identified beyond the general GDPR framework.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsAmber

No Latvia-specific variance from the GDPR's statutory response deadlines (Article 12(3)) was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative62 words

Data subject rights in Latvia derive directly from GDPR Chapter III (Articles 12-23), supplemented by the Personal Data Processing Law. DVI's 2019 enforcement action against an online retailer for failure to execute an Article 17 erasure request and for non-cooperation under Article 58(2)(c) and (g) and Article 23 of the Personal Data Processing Law demonstrates the rights framework is operative and enforced.

Periodic update · new data 2026-08-25

Data Subject Rights

The Data State Inspectorate's enforcement action against SIA "Tet" is this cycle's principal data-subject-rights finding for Latvia. DVI imposed a EUR 1,200,000 fine against the internet-service-provider for disclosing unverified personal data, including data belonging to a minor, to debt-recovery services without first verifying the data subject's identity, in violation of GDPR Article 5(1)'s accuracy and lawfulness principles. This is rectification-and-erasure-adjacent in character: had the disclosed data been properly verified before disclosure, the inaccuracy, and the affected individual's status as a minor, would plausibly have been identified before the data reached a third party.

The case is significant for several reasons beyond its size. First, it demonstrates that DVI treats pre-disclosure identity verification as a component of the lawfulness and accuracy obligations under GDPR Article 5(1), rather than as a separate, lower-stakes administrative step; the fine's basis was the disclosure of unverified data, not merely an unauthorised disclosure of accurate data. Second, the involvement of a minor's data elevates the case's severity within DVI's assessment. Third, debt-recovery disclosure is a specific, recurring risk vector for data-subject-rights violations: personal data transferred to third-party debt-recovery services is a common commercial practice across sectors, and Tet's failure to verify data before such a transfer is a cautionary pattern relevant to any controller engaging in similar third-party disclosures for debt-recovery or similar purposes.

At EUR 1.2 million, the Tet fine sits well below the GDPR's statutory maximum of EUR 20,000,000 or 4 percent of worldwide annual turnover, whichever is higher, indicating that even DVI's most significant known case to date has been calibrated substantially under the available ceiling. It is worth situating this case within the broader taxonomy of data-subject-rights risk. The right to accuracy and the associated obligation on controllers to take reasonable steps to ensure data is not inaccurate before further processing or disclosure sits alongside, but is analytically distinct from, the right to erasure and the right to rectification proper; the Tet case's core failure was upstream of any data-subject request for rectification or erasure. This distinction matters for compliance purposes: a controller cannot rely solely on a functioning rectification-request process to discharge its Article 5(1) accuracy obligations, since that obligation applies proactively to the controller's own data-handling practices, independent of whether any data subject has exercised a formal rights request.

The absence of any further data-subject-rights-specific finding for Latvia this cycle, beyond the Tet case, should be read against the backdrop of DVI's broader enforcement volume: 266 in-depth review proceedings and 143 identified violations across DVI's full docket in a recent reporting period represent a much larger population of matters than data-subject-rights cases specifically, and this cycle's evidence base isolates Tet as the identifiable data-subject-rights-specific case within that broader volume rather than indicating that no other data-subject-rights matters exist within DVI's docket.

Outlook

The clearest forward-looking test for this domain is whether DVI issues any further data-subject-rights enforcement action addressing pre-disclosure verification failures, particularly in debt-recovery or other third-party-disclosure contexts, which would establish the Tet case as the first instance of a now-settled enforcement pattern rather than a singular event. A secondary item to track is whether Tet or any similarly situated controller in Latvia updates its third-party-disclosure verification practices in response to this case, and whether any private civil claim follows from the affected data subjects independent of DVI's administrative fine; no such follow-on private action was evidenced this cycle.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — Latvia's data subject rights framework is governed by the GDPR together with the Personal Data Processing Law of 21 June 2018.observed
  2. ConfirmedEUR-Lex — GDPR Chapter III, entitled 'Rights of the data subject', contains Articles 12 to 23, which apply directly in Latvia as an EU Member State.observed
  3. ConfirmedEDPB (republishing DVI press release) — DVI imposed a €7,000 fine on an online retailer in 2019 for failing to comply with a data subject's Article 17 erasure request and for non-cooperation with the supervisory authority.observed

#

DPO-related guidance is mature and consistent, but the DPIA-exemption list underpinning accountability_and_dpia was still in EDPB-reviewed draft form, and breach-notification, ROPA, joint-controller, security and retention sub-modules lack confirmed Latvia-specific findings.

Primary frameworkGDPR Articles 24-39; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — AmberDPO-related guidance is mature and consistent, but the DPIA-exemption list underpinning accountability_and_dpia was still in EDPB-reviewed draft form, and breach-notification, ROPA, joint-controller, security and retention sub-modules lack confirmed Latvia-specific findings.

Sub-modules (7)

Accountability And DpiaAmber

DVI's draft list of DPIA-exempt processing operations under Article 35(5) GDPR was the subject of EDPB Opinion 6/2024, indicating the list was in a consultative/draft stage as of that opinion.

Claims (1):

  • The EDPB adopted Opinion 6/2024 on the Latvian supervisory authority's draft list of processing operations exempt from the DPIA requirement under Article 35(5) GDPR.

Dpo RequirementsGreen

DVI guidance requires notification of DPO appointments and permits a single DPO for a group of companies provided accessibility and independence criteria are met; DVI frames the DPO's role as an independent, auditor-like consultant to management.

Claims (3):

  • Organisations must notify DVI of a Data Protection Officer's appointment.
  • DVI guidance (June 2026) confirms that an international group of companies may appoint a single DPO provided each entity can easily communicate with them, while each entity remains responsible for its own compliance decisions.
  • DVI's August 2022 guidance describes the DPO's primary function as leading consultant on personal data protection issues, with duties resembling an internal auditor, while final processing decisions remain with organisational management.

Ropa RequirementsAmber

No Latvia-specific ROPA finding beyond the general GDPR Article 30 requirement was identified.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsAmber

No Latvia-specific joint-controller finding was identified beyond the general GDPR Article 26 framework.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

No Latvia-specific security-of-processing finding beyond the general GDPR Article 32 framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Breach NotificationAmber

No Latvia-specific breach-notification variance beyond the general GDPR Articles 33-34 framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Retention And DisposalAmber

No Latvia-specific retention/disposal finding beyond the general GDPR storage-limitation principle was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative65 words

Controller/processor accountability obligations follow GDPR Articles 24-39. DVI's draft list of processing operations exempt from the DPIA requirement (Article 35(5)) was reviewed by the EDPB in Opinion 6/2024, indicating the list remains subject to finalisation. DVI has also issued repeated guidance clarifying DPO functions, including a June 2026 note on appointing a single DPO for corporate groups and requiring notification of DPO appointments to DVI.

Periodic update · new data 2026-09-28

Controller/Processor Duties

In 2026 the DVI issued updated guidance permitting employees to record workplace meetings on a legitimate-interest basis, provided clear internal procedures are followed. This is an uncertain-confidence finding, drawn from a single Tier-3 source, and represents a shift in how the legitimate-interest lawful basis is being applied to an employee-initiated recording scenario rather than a controller-initiated one. Employers operating in Latvia should note that this guidance addresses recording by employees rather than by the employer itself, and the requirement for clear internal procedures suggests the DVI expects documented governance around the practice rather than an unconditional permission.

Separately, the DVI retains its established statutory power to visit and inspect controllers' premises, including production facilities, warehouses, and other commercial or non-residential premises, in order to check compliance with Latvian data-protection law. This inspection power is a probable-confidence, standing feature of the DVI's regulatory toolkit rather than a new development this cycle, but it forms part of the same controller-facing compliance architecture that the 2026 workplace-recording guidance sits within.

Outlook

The item to watch is whether further DVI guidance clarifies the internal-procedure standard referenced in the 2026 workplace-recording guidance, and whether any enforcement action tests the legitimate-interest basis in this specific employee-recording context.

1 earlier distinct update(s)
Periodic update · new data 2026-08-25

Controller/Processor Duties

Latvia's controller and processor duties saw two incremental clarifications from the Data State Inspectorate this cycle, both addressing recurring practical-compliance ambiguities rather than introducing new statutory obligations. First, 2026 DVI guidance clarifies that employees may record workplace meetings on a legitimate-interest basis, subject to internal policy safeguards. This resolves a common employment-context question by confirming legitimate interest as an available basis, conditioned on the employer having internal policy safeguards in place. This is the most recent identified controller-processor-duties development for Latvia, dated to 2026.

Second, DVI's data-minimisation guidance for CCTV and video-surveillance systems establishes a practical retention norm: footage is generally expected to be limited to approximately 30 days absent strong, documented justification for longer retention. This is a guidance-level norm rather than a binding statutory retention period, and is accordingly assessed rather than confirmed in confidence, reflecting its status as regulatory expectation rather than codified law. Separately, but related, Latvia's CCTV regime does not require mandatory DVI registration of surveillance systems, but does require clear signage stating the surveillance purpose and providing controller contact information, a binding requirement.

Read together, these two developments describe DVI's approach to controller-processor duties as one of targeted, sector- or context-specific guidance issued incrementally, rather than a single comprehensive controller-processor-duties framework document. The workplace-recording guidance addresses an employment-relations context; the CCTV guidance addresses a physical-security and surveillance context; both narrow practical uncertainty for controllers operating in those specific contexts without altering Latvia's underlying GDPR-based statutory obligations.

The accountability dimension of both pieces of guidance is also worth noting: the workplace-recording guidance is explicitly conditioned on internal policy safeguards, which implies an accountability expectation that employers relying on employee legitimate-interest recording maintain a documented internal policy, even though the guidance does not appear to specify the precise content such a policy must contain. Similarly, the CCTV signage requirement functions as a transparency-and-accountability control, giving data subjects notice of surveillance and a contact point for further inquiry or rights exercise, even in the absence of a formal registration obligation. It is also useful to distinguish these two 2026 guidance items from the security-measures and retention-and-disposal sub-modules they respectively sit under: the CCTV signage requirement is a security-and-transparency measure, while the 30-day retention norm is a data-minimisation and retention-and-disposal matter, and controllers should treat compliance with one as distinct from, though related to, compliance with the other.

Outlook

The main open question for this domain is whether either piece of 2026 guidance is tested against an actual DVI enforcement action — for instance, an employer relying on the workplace-recording legitimate-interest basis without adequate internal policy safeguards, or a CCTV operator retaining footage well beyond the 30-day norm without documented justification. No such enforcement test was evidenced this cycle, and until one occurs, both pieces of guidance remain untested compliance expectations rather than confirmed enforcement standards. A further item worth monitoring is whether DVI extends the workplace-recording legitimate-interest logic to analogous contexts beyond meetings specifically, since the 2026 guidance as evidenced this cycle is specific to meetings and does not itself address those adjacent scenarios.

Sources and claims (4)
  1. ConfirmedEDPB — The EDPB adopted Opinion 6/2024 on the Latvian supervisory authority's draft list of processing operations exempt from the DPIA requirement under Article 35(5) GDPR.observed
  2. ProbableOneTrust DataGuidance — Organisations must notify DVI of a Data Protection Officer's appointment.observed
  3. ConfirmedOneTrust DataGuidance — DVI guidance (June 2026) confirms that an international group of companies may appoint a single DPO provided each entity can easily communicate with them, while each entity remains responsible for its own compliance decisions.observed
  4. ConfirmedOneTrust DataGuidance — DVI's August 2022 guidance describes the DPO's primary function as leading consultant on personal data protection issues, with duties resembling an internal auditor, while final processing decisions remain with organisational management.observed

#

Full GDPR Chapter V applies directly via EU membership; no Latvia-specific derogation, additional localisation mandate, or independent adequacy instrument was found, which is the expected baseline for an EU Member State.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — GreenFull GDPR Chapter V applies directly via EU membership; no Latvia-specific derogation, additional localisation mandate, or independent adequacy instrument was found, which is the expected baseline for an EU Member State.

Sub-modules (6)

Transfer MechanismsGreen

Latvia relies on the standard GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) as an EU Member State; DVI's EDPB membership confirms full participation in the harmonised EU transfer regime.

Claims (1):

  • As an EU Member State and EDPB member, Latvia applies the GDPR Chapter V cross-border transfer regime (adequacy, SCCs, BCRs, derogations) directly, with no confirmed Latvia-specific derogation identified.

Adequacy ReceivedGreen

Adequacy decisions are an EU Commission competence exercised at Union level, not a Latvia-specific instrument; no Latvia-specific 'adequacy received' determination is applicable.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedGreen

Latvia does not independently grant adequacy; this is an EU Commission competence exercised on behalf of the Union.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsAmber

No Latvia-specific SCC/BCR uptake data or supplementary national form was identified.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentAmber

No Latvia-specific TIA guidance beyond the general EDPB/Schrems II framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationGreen

No Latvia-specific data-localisation mandate was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative44 words

As an EU Member State, Latvia's cross-border transfer regime is governed entirely by GDPR Chapter V (Articles 44-49): adequacy decisions are an EU Commission competence (not a Latvia-specific instrument), and SCCs/BCRs apply directly without a confirmed Latvia-specific overlay. No Latvia-specific data-localisation mandate was identified.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Regulation (EU) 2025/2518, which lays down additional procedural rules for the enforcement of the GDPR in cross-border cases, will apply from April 2027. This is a probable-confidence, forward-looking regulatory-horizon item rather than a currently operative rule, and it sits at the supranational EU level rather than being a Latvia-specific instrument. Its eventual application will affect how cross-border GDPR enforcement cases involving Latvian controllers or the DVI as lead or concerned supervisory authority are procedurally handled, though the specific mechanics of that change are not yet detailed in the evidence reaching this cycle.

No Latvia-specific cross-border transfer or adequacy development beyond this EU-level procedural regulation was identified this cycle.

Outlook

The April 2027 application date is the fixed marker to track. As that date approaches, future cycles should watch for implementing guidance from the European Data Protection Board or the DVI clarifying how the new procedural rules will be applied in cross-border cases involving Latvia.

Sources and claims (1)
  1. UncertainEDPB — As an EU Member State and EDPB member, Latvia applies the GDPR Chapter V cross-border transfer regime (adequacy, SCCs, BCRs, derogations) directly, with no confirmed Latvia-specific derogation identified.observed

#

Telecoms/eprivacy and employment sub-modules are well evidenced via DVI enforcement/guidance; financial, health, credit-scoring and insurance sub-modules carry no confirmed Latvia-specific findings.

Primary frameworkGDPR plus sector-specific instruments (Law on Information Society Services 2004, as amended)
Traffic-light rationale — AmberTelecoms/eprivacy and employment sub-modules are well evidenced via DVI enforcement/guidance; financial, health, credit-scoring and insurance sub-modules carry no confirmed Latvia-specific findings.

Sub-modules (7)

Financial Sector OverlayRed

No Latvia-specific financial-sector data-protection overlay was identified in this pass.

Absence provenance: unavailable. Searched: unavailable.

Health Sector OverlayRed

No Latvia-specific health-sector data-protection overlay was identified in this pass.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyAmber

DVI applies both the GDPR and the Law on Information Society Services 2004, as amended, to regulate cookie and tracker practices, as evidenced by its 2021-2022 preventive audit of e-merchant websites.

Claims (1):

  • DVI's preventive check of website cookie practices assessed compliance with both the GDPR and the Law on Information Society Services 2004, as amended, which together regulate the use of cookies on Latvian websites.

Employment DataGreen

DVI has published dedicated guidance for employers on processing employee personal data consistent with GDPR principles, including appropriate legal bases.

Claims (1):

  • DVI has published guidance for employers on processing employee personal data in accordance with GDPR principles, including guidance on appropriate legal bases for such processing.

Credit And ScoringRed

No Latvia-specific credit-scoring overlay was identified in this pass.

Absence provenance: unavailable. Searched: unavailable.

EducationAmber

DVI clarified personal-data rules applicable to student test papers in March 2026, addressing an education-sector processing scenario.

Claims (1):

  • DVI issued clarification in March 2026 on the personal-data rules applicable to the handling of student test papers.

InsuranceRed

No Latvia-specific insurance-sector overlay was identified in this pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative50 words

Sectoral overlays confirmed for Latvia are concentrated in telecoms/eprivacy (Law on Information Society Services 2004, as amended, applied alongside GDPR to cookie practices) and employment data (DVI employer guidance). Financial-sector, health-sector, credit-scoring and insurance overlays were not confirmed in this research pass; an education-sector clarification (student test papers) was identified.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — DVI's preventive check of website cookie practices assessed compliance with both the GDPR and the Law on Information Society Services 2004, as amended, which together regulate the use of cookies on Latvian websites.observed
  2. ConfirmedOneTrust DataGuidance — DVI has published guidance for employers on processing employee personal data in accordance with GDPR principles, including guidance on appropriate legal bases for such processing.observed
  3. ProbableOneTrust DataGuidance — DVI issued clarification in March 2026 on the personal-data rules applicable to the handling of student test papers.observed

#

Cookie/tracker enforcement and guidance are well evidenced and show active but imperfect compliance across the merchant sector; dark-patterns, opt-out-signal, clean-room and direct-marketing sub-modules lack confirmed Latvia-specific findings.

Primary frameworkGDPR plus Law on Information Society Services 2004, as amended (ePrivacy transposition)
Traffic-light rationale — AmberCookie/tracker enforcement and guidance are well evidenced and show active but imperfect compliance across the merchant sector; dark-patterns, opt-out-signal, clean-room and direct-marketing sub-modules lack confirmed Latvia-specific findings.

Sub-modules (6)

Cookies And TrackersAmber

DVI's 2021-2022 preventive audit found widespread cookie-consent non-compliance among e-merchants, and its April 2022 cookie guide clarifies which cookie categories require consent.

Claims (2):

  • DVI's 2021-2022 preventive check of cookie practices across 29 websites of 26 e-merchants found that none of the websites tested ensured appropriate consent was obtained, with three traders found in significant violation and 23 others required to remediate non-compliance.
  • DVI's April 2022 cookie guide clarifies that personalised and analytical cookies require user consent, while technical/functional cookies necessary for website operation do not.

Dark PatternsAmber

No Latvia-specific dark-patterns finding was identified beyond the general EDPB guidance framework.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsAmber

No Latvia-specific Global Privacy Control/DAA opt-out-signal finding was identified.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrAmber

No Latvia-specific data clean-room/collaboration-room finding was identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingAmber

No Latvia-specific cross-context advertising finding beyond general GDPR profiling rules was identified.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingAmber

No Latvia-specific direct-marketing consent/suppression finding beyond the general GDPR/ePrivacy framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative49 words

DVI has actively enforced cookie-consent standards, conducting a 2021-2022 preventive audit of 29 websites belonging to 26 large e-merchants that found none obtained appropriate consent, with three traders found in significant violation. DVI subsequently published a cookie guide (1 April 2022) distinguishing consent-requiring personalised/analytical cookies from consent-exempt technical/functional cookies.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance — DVI's 2021-2022 preventive check of cookie practices across 29 websites of 26 e-merchants found that none of the websites tested ensured appropriate consent was obtained, with three traders found in significant violation and 23 others required to remediate non-compliance.observed
  2. ConfirmedOneTrust DataGuidance — DVI's April 2022 cookie guide clarifies that personalised and analytical cookies require user consent, while technical/functional cookies necessary for website operation do not.observed

#

The GDPR baseline (Art 9, Art 22, Art 2(2)(d)) applies directly, but no Latvia-specific statutory overlay, DPA guidance, or enforcement action on profiling, ADM transparency, AI risk assessment, biometric regime, genetic data or surveillance carveouts was confirmed.

Primary frameworkGDPR Articles 9, 22 and 2(2)(d) (no confirmed Latvia-specific overlay)
Traffic-light rationale — AmberThe GDPR baseline (Art 9, Art 22, Art 2(2)(d)) applies directly, but no Latvia-specific statutory overlay, DPA guidance, or enforcement action on profiling, ADM transparency, AI risk assessment, biometric regime, genetic data or surveillance carveouts was confirmed.

Sub-modules (6)

Profiling RestrictionsAmber

No Latvia-specific profiling-restriction finding beyond general GDPR Article 22 was identified.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyAmber

No Latvia-specific ADM-transparency finding was identified.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

No Latvia-specific AI-risk-assessment or EU AI Act interface finding was identified in this pass.

Absence provenance: unavailable. Searched: unavailable.

Biometric RegimeAmber

No Latvia-specific biometric-data regime beyond the general GDPR Article 9 special-category framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataAmber

No Latvia-specific genetic-data regime beyond the general GDPR Article 9 special-category framework was identified.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

No Latvia-specific state-surveillance carveout beyond the general GDPR Article 2(2)(d) law-enforcement exclusion was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative43 words

GDPR Article 9(4) permits Latvia to add further conditions on genetic, biometric and health data, but no confirmed Latvia-specific biometric, genetic, ADM-transparency or AI-risk-assessment overlay was located in this pass. No Latvia-specific state-surveillance carveout beyond the general GDPR Article 2(2)(d)/national-security exclusions was identified.

#

The GDPR default age-of-consent rule applies by direct effect, but confirmation of any Latvia-specific lower threshold (permitted between 13 and 16) was not found; dependent-adults and minor-profiling-ban sub-modules carry no confirmed findings.

Primary frameworkGDPR Article 8 (default age 16, absent confirmed national derogation)
Traffic-light rationale — AmberThe GDPR default age-of-consent rule applies by direct effect, but confirmation of any Latvia-specific lower threshold (permitted between 13 and 16) was not found; dependent-adults and minor-profiling-ban sub-modules carry no confirmed findings.

Sub-modules (5)

Age VerificationAmber

No Latvia-specific age-verification mandate or DVI guidance was identified.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansAmber

No Latvia-specific minor-profiling-ban finding was identified.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsAmber

DVI's March 2026 clarification on student test papers addresses an education-sector processing scenario involving minors' data; this finding is homed under sectoral_watch.education (see CLM-LV-9b0c72d3) and is cross-referenced here for completeness.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsAmber

No Latvia-specific dependent-adults (elderly/incapacitated) data-protection finding was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative69 words

GDPR Article 8 sets a default age of 16 for a child's own consent to information-society-service processing, with member states permitted to lower this to a minimum of 13; this research could not confirm whether Latvia has enacted a specific national derogation from the 16-year default. DVI's March 2026 clarification on student test papers touches an education setting involving minors' data but does not itself establish an age-of-consent rule.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainEDPB — GDPR Article 8 sets a default age of 16 for a child's own valid consent to information-society-service processing, below which a holder of parental responsibility must consent; member states may lower this default to a minimum of 13, but confirmation of a Latvia-specific derogation was not found.observed

#

Multiple concrete enforcement decisions, an active CJEU reference on private compensation rights, and ongoing 2026 regulatory activity together demonstrate a functioning, actively-used enforcement and redress ecosystem.

Primary frameworkGDPR Articles 58, 77-84; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenMultiple concrete enforcement decisions, an active CJEU reference on private compensation rights, and ongoing 2026 regulatory activity together demonstrate a functioning, actively-used enforcement and redress ecosystem.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

DVI exercises GDPR Article 58(2) investigative/corrective powers and Article 83 fining powers, as demonstrated by its 2019 decision against an online retailer, calculated with reference to Article 83(5)(b) and (e).

Claims (1):

  • DVI's Director imposed a €7,000 administrative fine in 2019 under GDPR Article 83(5)(b) and (e), exercising Article 58(2) corrective powers against an online retailer for GDPR non-compliance and non-cooperation.

Enforcement Activity IndexGreen

DVI's enforcement record includes fines against an online retailer (€7,000, 2019), HH Invest SIA (€15,000, 2020) and Lursoft (€65,000, 2021), indicating sustained enforcement activity over multiple years.

Claims (2):

  • DVI fined Lursoft €65,000 in 2021 for unlawful processing of personal data.
  • DVI fined HH Invest SIA €15,000 in December 2020 for providing insufficient information to a data subject regarding the processing of their personal data.

Regulator Funding And CapacityAmber

No specific DVI funding/headcount data was identified in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsAmber

No Latvia-specific collective-redress or class-action mechanism for data-protection claims was identified.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionGreen

Latvia's Supreme Court referred a preliminary question to the CJEU (C-507/23) on Article 82(1) GDPR compensation for non-material damage, confirming Latvian courts recognise direct data-subject compensation claims.

Claims (1):

  • Latvia's Augstākā tiesa (Senāts) referred a preliminary-ruling question to the CJEU (Case C-507/23) concerning Article 82(1) GDPR's right to compensation for non-material damage, including whether an apology can constitute permissible compensation.

Recent Developments 180DAmber

Within the recent-developments window, DVI published June 2026 guidance on group DPO appointment, and the Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new subscriber-data access procedures and updated fine structures.

Claims (2):

  • On 3 June 2026, DVI published guidance on the appointment of a single Data Protection Officer for a group of companies, covering accessibility, conflict-of-interest and cross-border-transfer considerations for the DPO role.
  • The Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new procedures for accessing subscriber data and updating fine structures.
Category narrative106 words

DVI exercises GDPR Article 58 investigative and corrective powers and Article 83 fining powers, evidenced by a 2019 €7,000 fine (erasure/non-cooperation), a December 2020 €15,000 fine against HH Invest SIA (inadequate information to a data subject), and a 2021 €65,000 fine against Lursoft for unlawful processing. Latvia's Supreme Court (Augstākā tiesa, Senāts) referred a preliminary question to the CJEU (C-507/23) on Article 82(1) GDPR compensation for non-material damage, confirming an operative private right of action before Latvian courts. Recent developments include June 2026 DVI guidance on group DPO appointments and Latvian parliamentary amendments to the Law on Administrative Liability affecting subscriber-data access procedures and fine structures.

Periodic update · new data 2026-09-28

Enforcement & Redress

Latvia's enforcement environment shows material escalation this cycle. The Riga Regional Court has upheld the Data State Inspectorate's EUR 1.2 million fine against Tet, a significant Latvian telecommunications provider, for unlawfully disclosing unverified customer personal data to debt-recovery services. This judgment is now final and not subject to appeal, converting what was previously a contested fine into a settled, confirmed enforcement outcome. The finality of this decision is a confirmed-confidence finding drawn from Latvian public broadcasting reporting.

Beyond this individual case, the DVI's own activity statistics for its latest reporting period show sustained enforcement volume: 266 in-depth review proceedings were initiated, 143 violations were identified within those reviews, and corrective measures were applied in 62 cases. The DVI also adopted seven administrative-offence decisions, five of which were fines for GDPR violations and two of which were penalties for failure to provide information to the DVI itself. These figures are probable-confidence findings drawn from a single Tier-3 source (Linklaters), and the exact date range of the reporting period they cover was not confirmable from the source excerpt reached this cycle, a gap that should be closed in a future cycle before the figures are treated as fully settled. The DVI additionally retains a statutory power to visit and inspect controllers' premises, including production facilities, warehouses and other commercial or non-residential premises, to check compliance with Latvian data-protection law.

Outlook

The item to watch is whether the volume of in-depth review proceedings this reporting period (266) converts into further administrative-offence decisions in the coming cycle, and whether a future source can confirm the exact reporting-period date range for these figures. The Tet judgment's finality removes any near-term appeal uncertainty from that specific case.

1 earlier distinct update(s)
Periodic update · new data 2026-08-25

Enforcement & Redress

The Data State Inspectorate's enforcement and redress activity in Latvia shows a materially active, above-baseline enforcement programme this cycle, anchored by one headline case. DVI opened 266 in-depth review proceedings, identified 143 violations, applied corrective measures in 62 cases, and issued 7 administrative-offence decisions in a recent reporting period, of which 5 were GDPR fines and 2 concerned cooperation failures with DVI itself rather than substantive GDPR breaches.

The headline case within this activity remains the SIA "Tet" fine of EUR 1,200,000, imposed for disclosing unverified personal data, including a minor's data, to debt-recovery services without prior identity verification, in violation of GDPR Article 5(1). This fine sits well below the GDPR's statutory maximum penalty of EUR 20,000,000 or 4 percent of worldwide annual turnover, whichever is higher. The gap between Tet's actual fine and the statutory ceiling is instructive: DVI's largest identified fine to date represents a small fraction of the maximum available penalty, suggesting a calibrated, proportionality-conscious fining practice even in its most significant known case.

The proportion of DVI's enforcement outcomes is also analytically significant. Of 143 identified violations, corrective measures were applied in 62 cases, while only 7 proceeded to formal administrative-offence decisions. This indicates that DVI's default enforcement posture favours remediation over formal fining, reserving administrative-offence decisions, and by extension monetary fines, for a comparatively small subset of matters. This pattern suggests DVI's enforcement capacity is being deployed primarily toward correction and compliance-improvement rather than punitive deterrence, with fines functioning as an exception rather than the default response to an identified violation.

DVI's decisions carry a defined judicial-review pathway: administrative-offence decisions are appealable first to the DVI Director and subsequently to the District (City) Court under the Administrative Violations Code. This establishes that DVI's enforcement decisions, including the Tet fine, are not administratively final but subject to a defined internal-then-judicial appeal route. No indication of whether Tet or any other sanctioned party has exercised this appeal route was available this cycle.

It is also worth situating DVI's enforcement volume in context to the extent this cycle's evidence permits: 266 in-depth review proceedings in a single reporting period is a substantial docket, and the resulting 143-violation identification rate suggests DVI's review process is reasonably effective at surfacing genuine violations rather than functioning as a largely pro forma review exercise. No comparative figure from another jurisdiction is available within this cycle's evidence base, so this observation should be read as a description of Latvia's own docket composition rather than a comparative ranking. Finally, the 2-of-7 administrative-offence decisions concerning cooperation failures rather than substantive GDPR breaches is itself a distinct and separately notable finding: it indicates that DVI is willing to formally sanction non-cooperation with its own supervisory process as a distinct category of offence, independent of whatever substantive GDPR violation, if any, prompted the underlying inquiry.

Outlook

The most consequential open item for this domain is whether DVI's active 2026-2030 strategic emphasis on strengthened supervision translates into a materially higher rate of administrative-offence decisions relative to the 7-of-143 ratio observed in the most recent reporting period, which would signal a shift away from the remediation-favouring posture described above. A second item to track is whether the Tet decision, or any other DVI administrative-offence decision from this reporting period, is appealed to the District Court, which would be the first test of Latvia's GDPR judicial-redress pathway under this cycle's evidence base.

Sources and claims (6)
  1. ConfirmedEDPB (republishing DVI press release) — DVI's Director imposed a €7,000 administrative fine in 2019 under GDPR Article 83(5)(b) and (e), exercising Article 58(2) corrective powers against an online retailer for GDPR non-compliance and non-cooperation.observed
  2. ConfirmedOneTrust DataGuidance — DVI fined HH Invest SIA €15,000 in December 2020 for providing insufficient information to a data subject regarding the processing of their personal data.observed
  3. ConfirmedOneTrust DataGuidance — DVI fined Lursoft €65,000 in 2021 for unlawful processing of personal data.observed
  4. ConfirmedEUR-Lex — Latvia's Augstākā tiesa (Senāts) referred a preliminary-ruling question to the CJEU (Case C-507/23) concerning Article 82(1) GDPR's right to compensation for non-material damage, including whether an apology can constitute permissible compensation.observed
  5. ConfirmedOneTrust DataGuidance — On 3 June 2026, DVI published guidance on the appointment of a single Data Protection Officer for a group of companies, covering accessibility, conflict-of-interest and cross-border-transfer considerations for the DPO role.observed
  6. UncertainOneTrust DataGuidance — The Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new procedures for accessing subscriber data and updating fine structures.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct44.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Latvia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s) (26 category placement(s)), 28 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressprivate right of action
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated with at least T1/T2 sourcing for regulator_and_framework, data_subject_rights, controller_processor_duties (DPO strand), adtech_and_commercial_privacy (cookies), and enforcement_and_redress, drawing on DVI/EDPB primary sources (T1) supplemented by DataGuidance secondary reporting (T2) and CJEU case law (T1) originating from Latvian courts. sectoral_watch and children_and_vulnerable_groups relied on partial T2/T3 coverage with several sub-modules (financial, health, credit, insurance) carrying no confirmed Latvia-specific findings. algorithmic_biometric_and_surveillance_governance and several controller_processor_duties sub-modules (ROPA, joint-controller, security, breach, retention) rely entirely on the GDPR baseline with absent_field_provenance, as no Latvia-specific overlay was located.

Unresolved questions (5):

  • Has Latvia enacted a national derogation lowering the GDPR Article 8 default child-consent age below 16 (to a minimum of 13)?
  • Has Latvia exercised the GDPR Article 9(4) option to impose further conditions on genetic, biometric or health data processing, and if so, what is the specific statutory text?
  • What is the finalised (post-EDPB-Opinion-6/2024) status of DVI's DPIA-exemption list under Article 35(5) GDPR?
  • What are the substantive terms and commencement date of the Latvian Parliament's amendments to the Law on Administrative Liability concerning subscriber-data access procedures?
  • Does Latvia maintain any sector-specific data-protection overlays for financial services, health, credit-scoring or insurance beyond the general GDPR framework?

Escalate to primary-source review: yes