{
 "jurisdiction_id": "LV",
 "jurisdiction": "Latvia",
 "url": "https://dataprotection.gi/jurisdictions/latvia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 26,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "GDPR is directly applicable and the national implementing Law plus an active, EDPB-recognised supervisory authority are confirmed; territorial/material scope questions are being actively clarified via CJEU referrals rather than left as gaps.",
   "claims": [
    {
     "statement": "The Data State Inspectorate (DVI), located at Elijas Street 17, Riga, LV-1050, is Latvia's GDPR supervisory authority and EDPB member.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the draft bill on 6 March 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-cabinet-ministers-endorses-draft-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CJEU received a preliminary-ruling request from Latvia's Administratīvā apgabaltiesa (Regional Administrative Court) concerning the material and temporal limits of GDPR obligations applicable to internet-advertising service providers responding to tax-authority information requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A62020CC0175",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core consent rules track GDPR directly, but the special-categories sub-module carries live CJEU interpretive uncertainty and an unconfirmed Article 9(4) national-derogation status.",
   "claims": [
    {
     "statement": "Consent relied on as a lawful basis for processing must be freely given, informed, specific and unambiguous, with data subjects retaining a genuine ability to withdraw it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Latvia's Satversmes tiesa referred to the CJEU the question of how to interpret 'processing of personal data relating to criminal convictions and offences' under Article 10 GDPR in the context of a public register of road-traffic penalty points.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:62019CC0439",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 9(4) permits member states, including Latvia, to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data or health data; whether Latvia has exercised this derogation was not conclusively confirmed in this pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0484",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is confirmed via direct GDPR effect and evidenced through an actual DVI enforcement decision on the erasure right; deadline-specific and portability/restriction sub-modules lack Latvia-specific confirmatory findings.",
   "claims": [
    {
     "statement": "Latvia's data subject rights framework is governed by the GDPR together with the Personal Data Processing Law of 21 June 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/latvia-data-subject-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Chapter III, entitled 'Rights of the data subject', contains Articles 12 to 23, which apply directly in Latvia as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0484",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI imposed a €7,000 fine on an online retailer in 2019 for failing to comply with a data subject's Article 17 erasure request and for non-cooperation with the supervisory authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB (republishing DVI press release)",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/data-state-inspectorate-latvia-imposes-financial-penalty-7000-euros-against_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "DPO-related guidance is mature and consistent, but the DPIA-exemption list underpinning accountability_and_dpia was still in EDPB-reviewed draft form, and breach-notification, ROPA, joint-controller, security and retention sub-modules lack confirmed Latvia-specific findings.",
   "claims": [
    {
     "statement": "The EDPB adopted Opinion 6/2024 on the Latvian supervisory authority's draft list of processing operations exempt from the DPIA requirement under Article 35(5) GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-62024-draft-list-latvian-sa-pro-cessing_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations must notify DVI of a Data Protection Officer's appointment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-publishes-guide-appointing-group-dpo",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI guidance (June 2026) confirms that an international group of companies may appoint a single DPO provided each entity can easily communicate with them, while each entity remains responsible for its own compliance decisions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-publishes-guide-appointing-group-dpo",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI's August 2022 guidance describes the DPO's primary function as leading consultant on personal data protection issues, with duties resembling an internal auditor, while final processing decisions remain with organisational management.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-publishes-guidance-dpos-functions-and-tasks",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Full GDPR Chapter V applies directly via EU membership; no Latvia-specific derogation, additional localisation mandate, or independent adequacy instrument was found, which is the expected baseline for an EU Member State.",
   "claims": [
    {
     "statement": "As an EU Member State and EDPB member, Latvia applies the GDPR Chapter V cross-border transfer regime (adequacy, SCCs, BCRs, derogations) directly, with no confirmed Latvia-specific derogation identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecoms/eprivacy and employment sub-modules are well evidenced via DVI enforcement/guidance; financial, health, credit-scoring and insurance sub-modules carry no confirmed Latvia-specific findings.",
   "claims": [
    {
     "statement": "DVI's preventive check of website cookie practices assessed compliance with both the GDPR and the Law on Information Society Services 2004, as amended, which together regulate the use of cookies on Latvian websites.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-finds-cookie-violations-after-auditing-29",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI has published guidance for employers on processing employee personal data in accordance with GDPR principles, including guidance on appropriate legal bases for such processing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-announces-publication-guidance-employee-data-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI issued clarification in March 2026 on the personal-data rules applicable to the handling of student test papers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-clarifies-personal-data-rules-around",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/tracker enforcement and guidance are well evidenced and show active but imperfect compliance across the merchant sector; dark-patterns, opt-out-signal, clean-room and direct-marketing sub-modules lack confirmed Latvia-specific findings.",
   "claims": [
    {
     "statement": "DVI's 2021-2022 preventive check of cookie practices across 29 websites of 26 e-merchants found that none of the websites tested ensured appropriate consent was obtained, with three traders found in significant violation and 23 others required to remediate non-compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-finds-cookie-violations-after-auditing-29",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI's April 2022 cookie guide clarifies that personalised and analytical cookies require user consent, while technical/functional cookies necessary for website operation do not.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-publishes-cookie-guide",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "The GDPR baseline (Art 9, Art 22, Art 2(2)(d)) applies directly, but no Latvia-specific statutory overlay, DPA guidance, or enforcement action on profiling, ADM transparency, AI risk assessment, biometric regime, genetic data or surveillance carveouts was confirmed.",
   "claims": []
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The GDPR default age-of-consent rule applies by direct effect, but confirmation of any Latvia-specific lower threshold (permitted between 13 and 16) was not found; dependent-adults and minor-profiling-ban sub-modules carry no confirmed findings.",
   "claims": [
    {
     "statement": "GDPR Article 8 sets a default age of 16 for a child's own valid consent to information-society-service processing, below which a holder of parental responsibility must consent; member states may lower this default to a minimum of 13, but confirmation of a Latvia-specific derogation was not found.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/latvia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Multiple concrete enforcement decisions, an active CJEU reference on private compensation rights, and ongoing 2026 regulatory activity together demonstrate a functioning, actively-used enforcement and redress ecosystem.",
   "claims": [
    {
     "statement": "DVI's Director imposed a €7,000 administrative fine in 2019 under GDPR Article 83(5)(b) and (e), exercising Article 58(2) corrective powers against an online retailer for GDPR non-compliance and non-cooperation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB (republishing DVI press release)",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/data-state-inspectorate-latvia-imposes-financial-penalty-7000-euros-against_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI fined HH Invest SIA €15,000 in December 2020 for providing insufficient information to a data subject regarding the processing of their personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-fined-online-store-€15000-inadequately",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DVI fined Lursoft €65,000 in 2021 for unlawful processing of personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-fines-lursoft-65000-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Latvia's Augstākā tiesa (Senāts) referred a preliminary-ruling question to the CJEU (Case C-507/23) concerning Article 82(1) GDPR's right to compensation for non-material damage, including whether an apology can constitute permissible compensation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62023CJ0507",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 3 June 2026, DVI published guidance on the appointment of a single Data Protection Officer for a group of companies, covering accessibility, conflict-of-interest and cross-border-transfer considerations for the DPO role.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/latvia-dvi-publishes-guide-appointing-group-dpo",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new procedures for accessing subscriber data and updating fine structures.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/topics/childrens-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}