Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
LatviaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.
The catch
The relaxed European headline stops being true the moment you touch four things. (1) Accounting records: paper must stay in Latvia and electronic copies must stay inside the European Union, so a United States accounting or resource-planning cloud is unlawful for a Latvian company. (2) Telecoms: eighteen months of call and connection records, plus a gag on telling the customer. (3) Banking: significant outsourcing needs a filing with the central bank and a thirty-working-day wait. (4) State critical computer systems: the supplier and its owners must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside that same group of countries.
Does this apply to me?
Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.High confidence
Can the data leave the country?
Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.High confidence
What do I have to do to send it abroad?
For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.High confidence
Who enforces this — and are they actually working?
The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.High confidence
How long must I keep it, and when must I delete it?
Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.High confidence
What happens when something goes wrong?
Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.High confidence
What's the trap?
Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.High confidence
What's about to change?
Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.Medium confidence
Hardest industry wall
  • All industries Grāmatvedības likums
  • Government Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"
LithuaniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Lithuania has no general rule that data must stay in the country. Private companies follow the European rulebook: data can go abroad once the right paperwork is in place. The wall is in government. The data behind the state's most important computer systems must sit in Lithuanian state data centres — and a copy of the most critical state data must be kept abroad on purpose.
The catch
The easy answer stops being true the moment you sell computing to the Lithuanian state. State information resources are graded into four importance levels. The top two must be held in state data centres inside Lithuania. The bottom two may sit in a foreign or private data centre, but a copy must still be kept in a Lithuanian state data centre — and the government has only approved data centres in European Union, European Economic Area and NATO countries. Lithuania also runs a 'digital embassy': copies of the most critical state data are deliberately stored outside Lithuania so the state survives an invasion. Banking, payments, insurance, securities, telecoms and online gambling have no storage-location rule that we could find. Health records are not walled off by a location rule, but almost all of them flow into a state health system that lives inside that government wall.
Does this apply to me?
Yes. A company with no office in Lithuania is still caught if it offers goods or services to people in Lithuania, or watches what they do online. There is no size or revenue threshold to hide under — a two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative inside the Union who can be contacted by regulators and by the public.High confidence
Can the data leave the country?
For an ordinary business, yes. Lithuania has not added a national storage-location rule on top of the European rules, so data can leave once you have the standard European paperwork. The exception is government. If a computer system counts as a state information resource, Lithuania grades it by importance, and the two top grades must be held in state data centres inside Lithuania. The two lower grades can sit abroad, but a copy must still be kept in a Lithuanian state data centre. Lithuania also forces the opposite move for its most critical state data: a copy must be kept outside the country, in what it calls a digital embassy.Medium confidence
What do I have to do to send it abroad?
Lithuania uses the European model: a destination is off-limits unless you have an approved route out. The easiest route is an approved-country list, which is populated and currently includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others, plus United States companies signed up to the European Union–United States Data Privacy Framework. If your destination is not on the list, the normal answer is a set of standard contract clauses published by the European Commission. Lithuania adds one local step: if you want to use your own custom contract wording instead of the standard clauses, you need written permission from the Lithuanian regulator first.High confidence
Who enforces this — and are they actually working?
The main regulator is the State Data Protection Inspectorate, and it is genuinely working. In 2025 it received 2,081 complaints, up 48 percent on the year before, ran 26 inspections and had 54 staff. By 31 July 2026 it had already published 122 decisions for the year. But the fines are small: it issued only five fines in the whole of 2025, the largest being 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less well known data regulator for journalism, and a separate cyber regulator inside the defence ministry.High confidence
How long must I keep it, and when must I delete it?
Both directions apply and they pull against each other. The ceiling comes from Europe: you must delete personal data once you no longer need it for the purpose you collected it for. The floors come from Lithuanian sector rules and from retention tables issued by the Chief Archivist. Some floors are very long. Health records in the state e-health system are kept for the patient's whole life plus three years, then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. When a floor and the ceiling clash, the floor wins for as long as it lasts, because keeping the data is then a legal duty.Medium confidence
What happens when something goes wrong?
Count at least two clocks, and they do not agree. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If you are covered by the Cybersecurity Law, a serious cyber incident must be reported to the National Cyber Security Centre within 24 hours — a full day earlier — with a fuller assessment at 72 hours and a final report within one month. Other incidents get 72 hours. Financial firms have a third clock under European digital resilience rules. Lithuanian organisations are visibly bad at the first clock: only 63 percent of breach reports in 2025 arrived on time.High confidence
What's the trap?
Five things that are not in the summary. Children can consent for themselves at 14 in Lithuania, not 16, so an age gate built for the European default is wrong here. You may never publish a Lithuanian personal identification number, and you may never use one for marketing. Complaining about a government body is worth less than you think, because fines on public institutions are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. And if you sell cloud services to the Lithuanian state, your data centre may simply be ineligible.High confidence
What's about to change?
Two dated changes matter in the next twelve months, and both are European. From 12 January 2027 every cloud provider must let customers move their data out for free — no exit fees at all. Around the same period, the technical security requirements of Lithuania's cyber law start biting for organisations registered in April 2025, roughly two years after registration. The bigger Lithuanian risk is not a new law at all: the government can change where state data must live by resolution, without going to parliament and without consulting anyone.Medium confidence
Hardest industry wall
  • Government Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis
  • Government Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai
  • Government Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai