🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LV · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 19 sources retrieved model claude-sonnet-5 ·

Latvia

LV schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 26 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

Latvia receives its first full ten-module structured-claims baseline this cycle, and a challenger-fold review has corrected two stale case-law characterisations while surfacing a confirmed national variance on children's consent age. The Court of Justice of the European Union's Case C-439/19, concerning Latvia's public register of road-traffic penalty points, was decided by the Grand Chamber on 2021-06-22: the Court ruled that GDPR precludes the Latvian legislation permitting public disclosure and re-use of that data under Article 10 GDPR. A second referral, Case C-175/20, concerning a Latvian tax authority's request that an internet-advertising service provider supply taxpayer data, is understood to have been decided on 2022-02-24, with the Court finding that GDPR does not in principle preclude such a request, subject to Article 5(1) GDPR necessity, proportionality and time-limitation safeguards. The same review indicates that Latvia's Personal Data Processing Law is understood to set the child-consent age for information-society services at 13 years, exercising the GDPR Article 8(1) member-state option to lower the default age of 16.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

GDPR is directly applicable and the national implementing Law plus an active, EDPB-recognised supervisory authority are confirmed; territorial/material scope questions are being actively clarified via CJEU referrals rather than left as gaps.

Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by the Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenGDPR is directly applicable and the national implementing Law plus an active, EDPB-recognised supervisory authority are confirmed; territorial/material scope questions are being actively clarified via CJEU referrals rather than left as gaps.

Sub-modules (5)

Regulator And AuthorityGreen

DVI is confirmed as Latvia's Article 51 GDPR supervisory authority, listed on the EDPB member register with its Riga headquarters and its representative to the Board.

Claims: CLM-LV-4a1f9c02

Act And InstrumentsGreen

The Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the implementing bill on 6 March 2018.

Claims: CLM-LV-7b3e88d1

Material ScopeGreen

Material scope questions (e.g., obligations of internet-advertising service providers vis-à-vis tax-authority information requests) have reached the CJEU via a Latvian court referral, clarifying GDPR's material/temporal limits in a Latvian administrative-law context.

Claims: CLM-LV-140dfb87

Territorial ScopeAmber

No Latvia-specific territorial-scope derogation or extension beyond GDPR Article 3 was identified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Regulator Registration And FilingAmber

No general processing-notification/filing regime was identified beyond GDPR's own framework; DPO-appointment notification to DVI is addressed under controller_processor_duties.dpo_requirements rather than here.

Absence provenance: not recorded. Searched: not recorded.

Category narrative101 words

Latvia's data-protection regime is anchored on the GDPR as directly-applicable EU law, implemented and supplemented domestically by the Personal Data Processing Law of 21 June 2018 (Fizisko personu datu apstrādes likums). The Data State Inspectorate (Datu valsts inspekcija, DVI), headquartered at Elijas Street 17, Riga LV-1050, is the Article 51 GDPR supervisory authority and sits as Latvia's representative on the EDPB. Material and territorial scope questions have been the subject of CJEU preliminary rulings originating from Latvian courts, including a referral from the Regional Administrative Court on the scope of GDPR obligations for internet-advertising service providers responding to tax-authority information requests.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEDPBThe Data State Inspectorate (DVI), located at Elijas Street 17, Riga, LV-1050, is Latvia's GDPR supervisory authority and EDPB member.
  2. ConfirmedOneTrust DataGuidanceThe Personal Data Processing Law of 21 June 2018 implements the GDPR into Latvian national law, following Cabinet of Ministers endorsement of the draft bill on 6 March 2018.
  3. ProbableEUR-LexThe CJEU received a preliminary-ruling request from Latvia's Administratīvā apgabaltiesa (Regional Administrative Court) concerning the material and temporal limits of GDPR obligations applicable to internet-advertising service providers responding to tax-authority information requests.

#

Core consent rules track GDPR directly, but the special-categories sub-module carries live CJEU interpretive uncertainty and an unconfirmed Article 9(4) national-derogation status.

Primary frameworkGDPR Articles 6, 7 and 9; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — AmberCore consent rules track GDPR directly, but the special-categories sub-module carries live CJEU interpretive uncertainty and an unconfirmed Article 9(4) national-derogation status.

Sub-modules (4)

Lawful BasesAmber

No Latvia-specific supplement to the GDPR Article 6 lawful-basis enumeration was identified.

Absence provenance: not recorded. Searched: not recorded.

Special CategoriesAmber

A CJEU reference from Latvia's Constitutional Court tested the interpretation of Article 10 GDPR (criminal-offence data) in the context of a public traffic-penalty-points register, and GDPR Article 9(4) allows member states to impose further conditions on genetic/biometric/health data.

Claims: CLM-LV-6c9a03f8, CLM-LV-fd83a710

Pseudonymisation And AnonymisationAmber

No Latvia-specific pseudonymisation/anonymisation safe-harbour or definition beyond the GDPR baseline was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative74 words

Lawful bases and consent standards follow GDPR Articles 6 and 7 directly, with no confirmed Latvia-specific derogation identified for general lawful bases. Special-category processing has been the subject of a CJEU reference from Latvia's Satversmes tiesa (Constitutional Court) concerning Article 10 GDPR's treatment of criminal-offence/penalty-point data, and GDPR Article 9(4) permits member states to add further conditions on genetic, biometric and health data — whether Latvia has exercised this option was not conclusively confirmed.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEDPBConsent relied on as a lawful basis for processing must be freely given, informed, specific and unambiguous, with data subjects retaining a genuine ability to withdraw it.
  2. ProbableEUR-LexLatvia's Satversmes tiesa referred to the CJEU the question of how to interpret 'processing of personal data relating to criminal convictions and offences' under Article 10 GDPR in the context of a public register of road-traffic penalty points.
  3. UncertainEUR-LexGDPR Article 9(4) permits member states, including Latvia, to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data or health data; whether Latvia has exercised this derogation was not conclusively confirmed in this pass.

#

Rights framework is confirmed via direct GDPR effect and evidenced through an actual DVI enforcement decision on the erasure right; deadline-specific and portability/restriction sub-modules lack Latvia-specific confirmatory findings.

Primary frameworkGDPR Chapter III (Articles 12-23); Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenRights framework is confirmed via direct GDPR effect and evidenced through an actual DVI enforcement decision on the erasure right; deadline-specific and portability/restriction sub-modules lack Latvia-specific confirmatory findings.

Sub-modules (5)

Access RightGreen

Access and other data-subject rights are governed by GDPR Chapter III together with the Personal Data Processing Law of 21 June 2018.

Claims: CLM-LV-2b7e0a91, CLM-LV-88f3d0c4

Rectification And ErasureGreen

DVI has actively enforced the Article 17 erasure right, fining an online retailer for failing to execute an erasure request and for non-cooperation with the authority.

Claims: CLM-LV-2e77b1a9

Restriction And ObjectionAmber

No Latvia-specific restriction/objection finding was identified beyond the general GDPR framework.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityAmber

No Latvia-specific portability finding was identified beyond the general GDPR framework.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsAmber

No Latvia-specific variance from the GDPR's statutory response deadlines (Article 12(3)) was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative62 words

Data subject rights in Latvia derive directly from GDPR Chapter III (Articles 12-23), supplemented by the Personal Data Processing Law. DVI's 2019 enforcement action against an online retailer for failure to execute an Article 17 erasure request and for non-cooperation under Article 58(2)(c) and (g) and Article 23 of the Personal Data Processing Law demonstrates the rights framework is operative and enforced.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceLatvia's data subject rights framework is governed by the GDPR together with the Personal Data Processing Law of 21 June 2018.
  2. ConfirmedEUR-LexGDPR Chapter III, entitled 'Rights of the data subject', contains Articles 12 to 23, which apply directly in Latvia as an EU Member State.
  3. ConfirmedEDPB (republishing DVI press release)DVI imposed a €7,000 fine on an online retailer in 2019 for failing to comply with a data subject's Article 17 erasure request and for non-cooperation with the supervisory authority.

#

DPO-related guidance is mature and consistent, but the DPIA-exemption list underpinning accountability_and_dpia was still in EDPB-reviewed draft form, and breach-notification, ROPA, joint-controller, security and retention sub-modules lack confirmed Latvia-specific findings.

Primary frameworkGDPR Articles 24-39; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — AmberDPO-related guidance is mature and consistent, but the DPIA-exemption list underpinning accountability_and_dpia was still in EDPB-reviewed draft form, and breach-notification, ROPA, joint-controller, security and retention sub-modules lack confirmed Latvia-specific findings.

Sub-modules (7)

Accountability And DpiaAmber

DVI's draft list of DPIA-exempt processing operations under Article 35(5) GDPR was the subject of EDPB Opinion 6/2024, indicating the list was in a consultative/draft stage as of that opinion.

Claims: CLM-LV-3b5a9e12

Dpo RequirementsGreen

DVI guidance requires notification of DPO appointments and permits a single DPO for a group of companies provided accessibility and independence criteria are met; DVI frames the DPO's role as an independent, auditor-like consultant to management.

Claims: CLM-LV-9f02c7a3, CLM-LV-af02d871, CLM-LV-c419e0aa

Ropa RequirementsAmber

No Latvia-specific ROPA finding beyond the general GDPR Article 30 requirement was identified.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsAmber

No Latvia-specific joint-controller finding was identified beyond the general GDPR Article 26 framework.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresAmber

No Latvia-specific security-of-processing finding beyond the general GDPR Article 32 framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Breach NotificationAmber

No Latvia-specific breach-notification variance beyond the general GDPR Articles 33-34 framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Retention And DisposalAmber

No Latvia-specific retention/disposal finding beyond the general GDPR storage-limitation principle was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative65 words

Controller/processor accountability obligations follow GDPR Articles 24-39. DVI's draft list of processing operations exempt from the DPIA requirement (Article 35(5)) was reviewed by the EDPB in Opinion 6/2024, indicating the list remains subject to finalisation. DVI has also issued repeated guidance clarifying DPO functions, including a June 2026 note on appointing a single DPO for corporate groups and requiring notification of DPO appointments to DVI.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEDPBThe EDPB adopted Opinion 6/2024 on the Latvian supervisory authority's draft list of processing operations exempt from the DPIA requirement under Article 35(5) GDPR.
  2. ProbableOneTrust DataGuidanceOrganisations must notify DVI of a Data Protection Officer's appointment.
  3. ConfirmedOneTrust DataGuidanceDVI guidance (June 2026) confirms that an international group of companies may appoint a single DPO provided each entity can easily communicate with them, while each entity remains responsible for its own compliance decisions.
  4. ConfirmedOneTrust DataGuidanceDVI's August 2022 guidance describes the DPO's primary function as leading consultant on personal data protection issues, with duties resembling an internal auditor, while final processing decisions remain with organisational management.

#

Full GDPR Chapter V applies directly via EU membership; no Latvia-specific derogation, additional localisation mandate, or independent adequacy instrument was found, which is the expected baseline for an EU Member State.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — GreenFull GDPR Chapter V applies directly via EU membership; no Latvia-specific derogation, additional localisation mandate, or independent adequacy instrument was found, which is the expected baseline for an EU Member State.

Sub-modules (6)

Transfer MechanismsGreen

Latvia relies on the standard GDPR Chapter V mechanisms (adequacy, SCCs, BCRs, derogations) as an EU Member State; DVI's EDPB membership confirms full participation in the harmonised EU transfer regime.

Claims: CLM-LV-77d0c3ef

Adequacy ReceivedGreen

Adequacy decisions are an EU Commission competence exercised at Union level, not a Latvia-specific instrument; no Latvia-specific 'adequacy received' determination is applicable.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedGreen

Latvia does not independently grant adequacy; this is an EU Commission competence exercised on behalf of the Union.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsAmber

No Latvia-specific SCC/BCR uptake data or supplementary national form was identified.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentAmber

No Latvia-specific TIA guidance beyond the general EDPB/Schrems II framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationGreen

No Latvia-specific data-localisation mandate was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative44 words

As an EU Member State, Latvia's cross-border transfer regime is governed entirely by GDPR Chapter V (Articles 44-49): adequacy decisions are an EU Commission competence (not a Latvia-specific instrument), and SCCs/BCRs apply directly without a confirmed Latvia-specific overlay. No Latvia-specific data-localisation mandate was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. UncertainEDPBAs an EU Member State and EDPB member, Latvia applies the GDPR Chapter V cross-border transfer regime (adequacy, SCCs, BCRs, derogations) directly, with no confirmed Latvia-specific derogation identified.

#

Telecoms/eprivacy and employment sub-modules are well evidenced via DVI enforcement/guidance; financial, health, credit-scoring and insurance sub-modules carry no confirmed Latvia-specific findings.

Primary frameworkGDPR plus sector-specific instruments (Law on Information Society Services 2004, as amended)
Traffic-light rationale — AmberTelecoms/eprivacy and employment sub-modules are well evidenced via DVI enforcement/guidance; financial, health, credit-scoring and insurance sub-modules carry no confirmed Latvia-specific findings.

Sub-modules (7)

Financial Sector OverlayRed

No Latvia-specific financial-sector data-protection overlay was identified in this pass.

Absence provenance: not recorded. Searched: not recorded.

Health Sector OverlayRed

No Latvia-specific health-sector data-protection overlay was identified in this pass.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyAmber

DVI applies both the GDPR and the Law on Information Society Services 2004, as amended, to regulate cookie and tracker practices, as evidenced by its 2021-2022 preventive audit of e-merchant websites.

Claims: CLM-LV-e5a1029b

Employment DataGreen

DVI has published dedicated guidance for employers on processing employee personal data consistent with GDPR principles, including appropriate legal bases.

Claims: CLM-LV-540fa8cd

Credit And ScoringRed

No Latvia-specific credit-scoring overlay was identified in this pass.

Absence provenance: not recorded. Searched: not recorded.

EducationAmber

DVI clarified personal-data rules applicable to student test papers in March 2026, addressing an education-sector processing scenario.

Claims: CLM-LV-9b0c72d3

InsuranceRed

No Latvia-specific insurance-sector overlay was identified in this pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative50 words

Sectoral overlays confirmed for Latvia are concentrated in telecoms/eprivacy (Law on Information Society Services 2004, as amended, applied alongside GDPR to cookie practices) and employment data (DVI employer guidance). Financial-sector, health-sector, credit-scoring and insurance overlays were not confirmed in this research pass; an education-sector clarification (student test papers) was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceDVI's preventive check of website cookie practices assessed compliance with both the GDPR and the Law on Information Society Services 2004, as amended, which together regulate the use of cookies on Latvian websites.
  2. ConfirmedOneTrust DataGuidanceDVI has published guidance for employers on processing employee personal data in accordance with GDPR principles, including guidance on appropriate legal bases for such processing.
  3. ProbableOneTrust DataGuidanceDVI issued clarification in March 2026 on the personal-data rules applicable to the handling of student test papers.

#

Cookie/tracker enforcement and guidance are well evidenced and show active but imperfect compliance across the merchant sector; dark-patterns, opt-out-signal, clean-room and direct-marketing sub-modules lack confirmed Latvia-specific findings.

Primary frameworkGDPR plus Law on Information Society Services 2004, as amended (ePrivacy transposition)
Traffic-light rationale — AmberCookie/tracker enforcement and guidance are well evidenced and show active but imperfect compliance across the merchant sector; dark-patterns, opt-out-signal, clean-room and direct-marketing sub-modules lack confirmed Latvia-specific findings.

Sub-modules (6)

Cookies And TrackersAmber

DVI's 2021-2022 preventive audit found widespread cookie-consent non-compliance among e-merchants, and its April 2022 cookie guide clarifies which cookie categories require consent.

Claims: CLM-LV-01af6e44, CLM-LV-bb27ce09

Dark PatternsAmber

No Latvia-specific dark-patterns finding was identified beyond the general EDPB guidance framework.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsAmber

No Latvia-specific Global Privacy Control/DAA opt-out-signal finding was identified.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrAmber

No Latvia-specific data clean-room/collaboration-room finding was identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

No Latvia-specific cross-context advertising finding beyond general GDPR profiling rules was identified.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingAmber

No Latvia-specific direct-marketing consent/suppression finding beyond the general GDPR/ePrivacy framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative49 words

DVI has actively enforced cookie-consent standards, conducting a 2021-2022 preventive audit of 29 websites belonging to 26 large e-merchants that found none obtained appropriate consent, with three traders found in significant violation. DVI subsequently published a cookie guide (1 April 2022) distinguishing consent-requiring personalised/analytical cookies from consent-exempt technical/functional cookies.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceDVI's 2021-2022 preventive check of cookie practices across 29 websites of 26 e-merchants found that none of the websites tested ensured appropriate consent was obtained, with three traders found in significant violation and 23 others required to remediate non-compliance.
  2. ConfirmedOneTrust DataGuidanceDVI's April 2022 cookie guide clarifies that personalised and analytical cookies require user consent, while technical/functional cookies necessary for website operation do not.

#

The GDPR baseline (Art 9, Art 22, Art 2(2)(d)) applies directly, but no Latvia-specific statutory overlay, DPA guidance, or enforcement action on profiling, ADM transparency, AI risk assessment, biometric regime, genetic data or surveillance carveouts was confirmed.

Primary frameworkGDPR Articles 9, 22 and 2(2)(d) (no confirmed Latvia-specific overlay)
Traffic-light rationale — AmberThe GDPR baseline (Art 9, Art 22, Art 2(2)(d)) applies directly, but no Latvia-specific statutory overlay, DPA guidance, or enforcement action on profiling, ADM transparency, AI risk assessment, biometric regime, genetic data or surveillance carveouts was confirmed.

Sub-modules (6)

Profiling RestrictionsAmber

No Latvia-specific profiling-restriction finding beyond general GDPR Article 22 was identified.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyAmber

No Latvia-specific ADM-transparency finding was identified.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsAmber

No Latvia-specific AI-risk-assessment or EU AI Act interface finding was identified in this pass.

Absence provenance: not recorded. Searched: not recorded.

Biometric RegimeAmber

No Latvia-specific biometric-data regime beyond the general GDPR Article 9 special-category framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataAmber

No Latvia-specific genetic-data regime beyond the general GDPR Article 9 special-category framework was identified.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

No Latvia-specific state-surveillance carveout beyond the general GDPR Article 2(2)(d) law-enforcement exclusion was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative43 words

GDPR Article 9(4) permits Latvia to add further conditions on genetic, biometric and health data, but no confirmed Latvia-specific biometric, genetic, ADM-transparency or AI-risk-assessment overlay was located in this pass. No Latvia-specific state-surveillance carveout beyond the general GDPR Article 2(2)(d)/national-security exclusions was identified.

#

The GDPR default age-of-consent rule applies by direct effect, but confirmation of any Latvia-specific lower threshold (permitted between 13 and 16) was not found; dependent-adults and minor-profiling-ban sub-modules carry no confirmed findings.

Primary frameworkGDPR Article 8 (default age 16, absent confirmed national derogation)
Traffic-light rationale — AmberThe GDPR default age-of-consent rule applies by direct effect, but confirmation of any Latvia-specific lower threshold (permitted between 13 and 16) was not found; dependent-adults and minor-profiling-ban sub-modules carry no confirmed findings.

Sub-modules (5)

Age VerificationAmber

No Latvia-specific age-verification mandate or DVI guidance was identified.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansAmber

No Latvia-specific minor-profiling-ban finding was identified.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsAmber

DVI's March 2026 clarification on student test papers addresses an education-sector processing scenario involving minors' data; this finding is homed under sectoral_watch.education (see CLM-LV-9b0c72d3) and is cross-referenced here for completeness.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsAmber

No Latvia-specific dependent-adults (elderly/incapacitated) data-protection finding was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative69 words

GDPR Article 8 sets a default age of 16 for a child's own consent to information-society-service processing, with member states permitted to lower this to a minimum of 13; this research could not confirm whether Latvia has enacted a specific national derogation from the 16-year default. DVI's March 2026 clarification on student test papers touches an education setting involving minors' data but does not itself establish an age-of-consent rule.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. UncertainEDPBGDPR Article 8 sets a default age of 16 for a child's own valid consent to information-society-service processing, below which a holder of parental responsibility must consent; member states may lower this default to a minimum of 13, but confirmation of a Latvia-specific derogation was not found.

#

Multiple concrete enforcement decisions, an active CJEU reference on private compensation rights, and ongoing 2026 regulatory activity together demonstrate a functioning, actively-used enforcement and redress ecosystem.

Primary frameworkGDPR Articles 58, 77-84; Personal Data Processing Law of 21 June 2018
Traffic-light rationale — GreenMultiple concrete enforcement decisions, an active CJEU reference on private compensation rights, and ongoing 2026 regulatory activity together demonstrate a functioning, actively-used enforcement and redress ecosystem.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

DVI exercises GDPR Article 58(2) investigative/corrective powers and Article 83 fining powers, as demonstrated by its 2019 decision against an online retailer, calculated with reference to Article 83(5)(b) and (e).

Claims: CLM-LV-6e0b4471

Enforcement Activity IndexGreen

DVI's enforcement record includes fines against an online retailer (€7,000, 2019), HH Invest SIA (€15,000, 2020) and Lursoft (€65,000, 2021), indicating sustained enforcement activity over multiple years.

Claims: CLM-LV-3a7fd902, CLM-LV-59ad0e3c

Regulator Funding And CapacityAmber

No specific DVI funding/headcount data was identified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsAmber

No Latvia-specific collective-redress or class-action mechanism for data-protection claims was identified.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionGreen

Latvia's Supreme Court referred a preliminary question to the CJEU (C-507/23) on Article 82(1) GDPR compensation for non-material damage, confirming Latvian courts recognise direct data-subject compensation claims.

Claims: CLM-LV-88c0e1b5

Recent Developments 180DAmber

Within the recent-developments window, DVI published June 2026 guidance on group DPO appointment, and the Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new subscriber-data access procedures and updated fine structures.

Claims: CLM-LV-d0a9f622, CLM-LV-71bf03ea

Category narrative106 words

DVI exercises GDPR Article 58 investigative and corrective powers and Article 83 fining powers, evidenced by a 2019 €7,000 fine (erasure/non-cooperation), a December 2020 €15,000 fine against HH Invest SIA (inadequate information to a data subject), and a 2021 €65,000 fine against Lursoft for unlawful processing. Latvia's Supreme Court (Augstākā tiesa, Senāts) referred a preliminary question to the CJEU (C-507/23) on Article 82(1) GDPR compensation for non-material damage, confirming an operative private right of action before Latvian courts. Recent developments include June 2026 DVI guidance on group DPO appointments and Latvian parliamentary amendments to the Law on Administrative Liability affecting subscriber-data access procedures and fine structures.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedEDPB (republishing DVI press release)DVI's Director imposed a €7,000 administrative fine in 2019 under GDPR Article 83(5)(b) and (e), exercising Article 58(2) corrective powers against an online retailer for GDPR non-compliance and non-cooperation.
  2. ConfirmedOneTrust DataGuidanceDVI fined HH Invest SIA €15,000 in December 2020 for providing insufficient information to a data subject regarding the processing of their personal data.
  3. ConfirmedOneTrust DataGuidanceDVI fined Lursoft €65,000 in 2021 for unlawful processing of personal data.
  4. ConfirmedEUR-LexLatvia's Augstākā tiesa (Senāts) referred a preliminary-ruling question to the CJEU (Case C-507/23) concerning Article 82(1) GDPR's right to compensation for non-material damage, including whether an apology can constitute permissible compensation.
  5. ConfirmedOneTrust DataGuidanceOn 3 June 2026, DVI published guidance on the appointment of a single Data Protection Officer for a group of companies, covering accessibility, conflict-of-interest and cross-border-transfer considerations for the DPO role.
  6. UncertainOneTrust DataGuidanceThe Latvian Parliament adopted amendments to the Law on Administrative Liability introducing new procedures for accessing subscriber data and updating fine structures.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Latvia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s), 19 source(s) in the cumulative register.