EnglishLV
Latvia flag

Latvia

Latvia Data Privacy Laws: GDPR, DVI Enforcement & Compliance Guide (2026)

By Recording Law Editorial TeamReviewed September 9, 202624 min read
Latvia Data Privacy Laws: GDPR, DVI Enforcement & Compliance Guide (2026)

Frequently Asked Questions

What is the main data protection law in Latvia?

Latvia's data protection framework consists of two primary instruments. The EU General Data Protection Regulation (GDPR, Regulation 2016/679) applies directly as EU law and governs most personal data processing activities. The Personal Data Processing Law (Fizisko personu datu apstrādes likums, DPL), in force since 5 July 2018, supplements the GDPR by exercising the national opening clauses the regulation leaves to member states. These include the age of digital consent (set at 13 in Latvia), qualifications for data protection officers, DVI appointment and powers, and criminal penalty provisions. Privacy also has constitutional protection under Article 96 of Latvia's Satversme.

Who enforces data protection law in Latvia?

The Data State Inspectorate (Datu valsts inspekcija, DVI), established in 2001, is Latvia's independent supervisory authority. It has full investigative, corrective, and advisory powers under GDPR Article 58, including the power to audit processing activities, issue reprimands and warnings, order compliance, impose temporary or permanent bans on processing, and levy administrative fines up to EUR 20 million or 4% of global annual turnover. Since October 2025, the DVI also serves as a market surveillance authority for prohibited AI practices and high-risk AI systems under the EU AI Act.

What is the largest GDPR fine the DVI has imposed?

The largest GDPR fine in Latvian enforcement history is EUR 1,200,000, imposed on SIA Tet (a telecommunications and internet service company) for violations of GDPR Articles 5(1) and 6(1). The violations involved transferring unverified customer data including a minor's personal data to debt recovery services without a valid legal basis. The DVI originally imposed EUR 3,200,000; mitigating factors including cooperation and remedial measures led to reduction to EUR 1,200,000. In June 2024, the Riga Regional Court upheld the fine; the decision is final and not subject to further appeal.

What happened in the ZZ Dats data breach case?

Between 29 October and 2 November 2024, a technical vulnerability in ZZ Dats' Unified Municipal Information System allowed unauthorized access to personal data held for 42 Latvian municipalities. Names, surnames, personal identification numbers, and addresses of residents and municipal employees were exposed. In October 2025, the DVI fined SIA ZZ Dats EUR 300,000 under GDPR Article 32 for failing to implement security measures appropriate to the risk of its processing activities. ZZ Dats has appealed the decision to Riga City Court. The municipalities received reprimands in their capacity as data controllers.

How quickly must a data breach be reported to the DVI?

Controllers must notify the DVI within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is delayed beyond 72 hours, the controller must provide a reasoned explanation. Notifications are submitted through the DVI's online portal at pazinojums.dvi.gov.lv. Data processors must notify the controller without undue delay after becoming aware of a breach, regardless of assessed risk level. The controller then determines whether to notify the DVI and affected individuals.

Can individuals face criminal penalties for data protection violations in Latvia?

Yes. Section 145 of the Latvian Criminal Law establishes three tiers of criminal liability for illegal activities involving personal data. First-tier violations causing substantial harm carry up to two years' imprisonment. Second-tier violations where a controller or processor processes data illegally for vengeance, property gain, or blackmail carry up to four years. Third-tier violations where someone uses violence, threats, or deception to compel illegal data processing carry up to five years. These criminal penalties apply alongside, not instead of, administrative fines.

What is the minimum age for digital consent in Latvia?

Latvia has set the minimum age for valid consent to information society services at 13 years, exercising the option under GDPR Article 8 to lower the default threshold of 16. This makes Latvia one of the EU member states with the lowest digital consent age. For children under 13, consent must be given or authorized by a parent or legal guardian. Organizations offering digital services to children must make reasonable efforts to verify parental responsibility, taking into account available technology.

What role does the DVI play under the EU AI Act?

Following Latvia's Law on Digital Operational Resilience and the Use of Artificial Intelligence in the Financial Market entering into force on 1 October 2025, the DVI was designated as a market surveillance authority for prohibited AI practices and high-risk AI systems under the EU AI Act. This means the DVI can investigate and take enforcement action against AI systems that deploy prohibited practices (such as social scoring by public authorities or real-time biometric identification in public spaces) and against high-risk AI systems that fail to meet the AI Act's conformity requirements. For AI systems used by financial market participants, Latvijas Banka holds market surveillance authority.

Do I need DVI approval to transfer personal data outside the EU from Latvia?

It depends on the transfer mechanism. Transfers to countries with European Commission adequacy decisions require no additional steps. Transfers using Standard Contractual Clauses (SCCs) also do not require DVI prior approval. However, Binding Corporate Rules (BCRs) require DVI approval before they can be relied upon. Transfers under the GDPR Article 49(1) legitimate interests derogation must be notified to the DVI. Where Latvia-based operations are involved in a transfer subject to supervisory authority cooperation under the GDPR's one-stop-shop mechanism, the DVI participates as a concerned supervisory authority.

Updates

AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Full refresh: added ZZ Dats EUR 300,000 fine (Oct 2025), Tet court ruling (June 2024), EU AI Act overlay, DVI market surveillance role, Satversme Constitutional Court cases, expanded legal bases, data subject rights restrictions, and DORA interaction.

Initial publication: [GDPR](/world-laws/world-data-privacy-laws) framework, DVI overview, TET fine, breach notification, DPO requirements, children's consent, and criminal penalties.

Sources and References

  1. Personal Data Processing Law (likumi.lv)(likumi.lv).gov
  2. Datu valsts inspekcija (DVI)(dvi.gov.lv).gov
  3. EDPB Latvia(edpb.europa.eu).gov
  4. GDPRhub DVI Latvia(gdprhub.eu)
  5. GDPRhub DVI SIA TET(gdprhub.eu)
  6. ZZ Dats EUR 300,000 fine LSM.lv(eng.lsm.lv)
  7. Tet EUR 1.2M fine court ruling LSM.lv(eng.lsm.lv)
  8. DVI EUR 7,000 online retailer fine(edpb.europa.eu).gov
  9. Latvia AI Act implementation plan VARAM(varam.gov.lv).gov
  10. Latvia DORA AI Act law DataGuidance(dataguidance.com)
  11. GDPR Official Text EUR-Lex(eur-lex.europa.eu).gov
  12. White & Case GDPR Latvia(whitecase.com)
  13. DLA Piper Latvia Data Protection(dlapiperdataprotection.com)
  14. Linklaters Data Protected Latvia(linklaters.com)
  15. CJEU Latvia Data Protection Ruling 2021(curia.europa.eu).gov
  16. Latvia Constitutional Court Demerit Points Article 96(satv.tiesa.gov.lv).gov
  17. Latvian Parliament Personal Data Processing(saeima.lv).gov
  18. EU AI Act Official Text(eur-lex.europa.eu).gov
  19. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
Share: