Skip to the content
Global Data RulesData governance rules, country by country

Latvia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Latvia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Latvia follows European Union privacy rules. Personal data can leave the country once you have the right paperwork. But Latvia adds walls of its own. Accounting records may not be stored outside the European Union at all. Phone and internet companies must keep call records for eighteen months. Banks need the central bank's approval before handing systems to an outside supplier.

Data governance in Latvia

The eight things that decide how you handle data about people in Latvia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach you even with no office in Latvia. You are covered if you offer goods or services to people in Latvia, or track what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue cut-off. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than its own test of who is covered.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Personal data can leave Latvia, but the answer changes with the type of data. For ordinary personal data the European rules apply. You can send it anywhere once you have the right paperwork. For accounting records the door is shut at the edge of the European Union. Paper stays in Latvia. Electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

For personal data you can only send to approved countries, rather than avoiding banned ones. You may send data to a country the European Commission has approved. Or you can use the European Union's standard contract template. Or you can use approved group-wide rules. The approved list is real and long. It includes the United Kingdom, Japan, South Korea, Switzerland and, for signed-up companies only, the United States. None of this helps with accounting records. That wall is about geography, and no contract unlocks it.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The privacy regulator is the State Data Inspectorate, and it really works. In 2025 it took 1,034 complaints and ran 1,396 checks. It applied corrective measures 62 times. It issued fines totalling 326,400 euros (about 355,000 US dollars). The largest single fine was 300,000 euros (about 327,000 US dollars). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks on its own initiative. Separate regulators handle banking, telecoms and cyber security, and all are staffed.

How long you must keep it — and when to delete it

Latvia has an unusually crowded set of minimum keeping periods, and one surprising maximum. You must keep accounting registers for ten years, and supporting documents for at least five. Phone and internet companies must keep call records for eighteen months. Medical records run from one year to forty years, depending on the form. Pulling the other way, security audit trails must normally be deleted after one year. That is shorter than many global logging policies allow.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least two deadlines, and often three. If personal data is exposed, you have 72 hours to tell the State Data Inspectorate. You must also tell the people affected without delay if the risk to them is high. If you run an essential or important service, you have 24 hours to send an early warning to the cyber incident response body. A first report follows at 72 hours. Trust service providers get only 24 hours for that first report. Banks have a third set of reporting duties under European financial rules.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: a child can agree for themselves from age 13, not 16. So a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine. A company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.

What you have to do here:
Get a parent's consent for children · Keep logs
What it costs if you get it wrong:
Criminal liability

What's changing next

Two dated changes and three powers already in someone's hand. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out. That is a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification exam. The powers: the government may still write binding rules on where computer systems are hosted, and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being changed piece by piece.

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms rules

Official name: Elektronisko sakaru likums · Adopted by the Saeima 14 July 2022, published Latvijas Vēstnesis No. 144, 28 July 2022; Sections 99-101 · Act of parliament

In forceYes, with paperwork

Phone and internet companies in Latvia must keep call, connection, location and subscriber-identifying data for 18 months. They must hand it to investigating and security bodies on request. They may not tell anyone that a request was made. No rule says the data must physically stay in Latvia. But the secrecy rule and the authorised-staff rule make casual access from abroad impractical.

In force since 29 July 2022

Enforced by Public Utilities Commission

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Cloud and outsourcing rules

Official name: Nacionālās kiberdrošības likums · Adopted by the Saeima 20 June 2024, published Latvijas Vēstnesis No. 128A, 4 July 2024; amended with effect from 18 June 2026 · Act of parliament

In forceYes, with paperwork

Latvia's implementation of the European network and information security directive. It covers energy, transport, banking, health, water, digital infrastructure, cloud and data centre providers and much of the public sector. Twenty-four hours for an early warning, seventy-two for a first report. Fines reach 10 million euros or 2 percent of turnover.

In force since 1 September 2024Enforced from 1 April 2025

Enforced by National Cyber Security Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Government data must stay in the country

Official name: Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības" · Ministru kabineta 2025. gada 25. jūnija noteikumi Nr. 397, issued under the National Cyber Security Law; points 94, 101 and 129 · Directly binding regulation

In forceNo — it stays put

For Latvia's most critical state and infrastructure systems, who supplies you matters as much as where the data sits. The supplier, its board, its shareholders and its ultimate owner must come from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country. Audit information may only be handled inside NATO, European Union or European Free Trade Association territory.

In force since 2 July 2025

Enforced by Constitution Protection Bureau

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Fizisko personu datu apstrādes likums · Adopted by the Saeima 21 June 2018, published Latvijas Vēstnesis 4 July 2018 · Act of parliament

In forceYes, with paperwork

Latvia's national privacy act. It sets up the State Data Inspectorate. It lowers to 13 the age at which a child can agree online. It caps audit-trail storage at one year. It creates an official register of qualified data protection specialists. It adds no separate national limit on sending personal data abroad.

In force since 5 July 2018

Enforced by State Data Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data must stay in the country

Official name: Grāmatvedības likums · Adopted by the Saeima 10 June 2021, published 28 June 2021 · Act of parliament

In forceNo — it stays put

This is the hardest storage rule in Latvia, and the one most often missed. Paper accounting documents must be kept inside Latvia. Electronic accounting documents must be kept inside Latvia or another European Union country. Entries in accounting registers must also be made in Latvian. It binds Latvian companies, branches of foreign companies and permanent bases alike.

In force since 1 January 2022

Enforced by State Revenue Service

How this country controls where data goes: Not allowed

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Vispārīgā datu aizsardzības regula (Regulation (EU) 2016/679) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European Union privacy regulation is the base layer in Latvia and applies directly. It does not require data to stay in Europe. It sets the conditions for letting data leave. Fines reach 20 million euros or 4 percent of worldwide group turnover, whichever is higher. An order to stop using the data usually hurts more.

In force since 25 May 2018

Enforced by State Data Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Who you would hear from

  • Datu valsts inspekcija

    General privacy law, data protection specialist register, breach notifications

    Fully working. Created on 1 January 2001. It is a government body under Cabinet supervision, independent in its work, with a director appointed for five years. In 2025: 1,034 complaints, 1,396 checks, corrective measures in 62 cases, fines totalling 326,400 euros with a maximum of 300,000 euros, and 32 staff on average. In the first half of 2026: 832 complaints, 36 violations found, 73 checks on its own initiative. It publishes far more guidance than penalties, so read it as active rather than aggressive.

  • Nacionālais kiberdrošības centrs

    Cyber security supervision of essential and important service providers; incident reporting; data centre requirements

    Started work on 1 September 2024 under the Ministry of Defence, alongside CERT.LV at the University of Latvia's Institute of Mathematics and Computer Science. Changes in force on 18 June 2026 moved designation decisions to the Centre from the Digital Security Supervisory Committee. It can impose penalties up to 10 million euros or 2 percent of turnover.

  • Satversmes aizsardzības birojs

    Supervision of owners of critical information and communication technology infrastructure; security vetting of cyber security managers

    The National Cyber Security Law names it, with its own supervision and penalty powers of up to 10 million euros or 2 percent of turnover. It is an intelligence service, so its individual decisions are not published.

  • Latvijas Banka

    Banks, insurers, investment firms, payment and electronic money institutions, crypto-asset service providers

    The single financial regulator, after taking over the Financial and Capital Market Commission. It issues licensing and supervisory decisions. It can veto big bank outsourcing deals.

  • Sabiedrisko pakalpojumu regulēšanas komisija

    Electronic communications sector regulation

  • Valsts ieņēmumu dienests

    Tax and accounting records, including where accounting documents are stored

  • Nacionālais veselības dienests

    National health information system and medical records

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the 18-month blanket telecoms retention duty in Section 99(4) of the Electronic Communications Law is enforceable in full

    The Court of Justice of the European Union has repeatedly held that keeping everyone's traffic and location data breaks European Union law. We could not confirm whether a Latvian court has set aside or narrowed Section 99(4). So we record the rule as in force. Treat how far it really reaches as contested.

  • That the Cabinet has not yet issued the regulations on data centre security requirements and on where information systems must be placed, promised by Section 30(2) of the National Cyber Security Law

    We searched the official legislation database for 2025 and 2026 and found no such regulation. The National Cyber Security Centre's legislation page redirects to a general Ministry of Defence page that does not list it. We could not confirm this either way. The Cabinet questionnaire attached to the minimum cyber security requirements regulation refers to such rules, which suggests they are drafted or planned.

  • The total euro value of fines imposed by the State Data Inspectorate in the first half of 2026

    The Inspectorate's July 2026 half-year update gives counts (832 complaints, 36 violations, corrective measures in 9 cases) but no monetary totals. Only the 2025 annual report gives euro figures.

  • Whether the State Data Inspectorate can impose European-regulation fines on Latvian public authorities, or only pursue the responsible official under the administrative-offence route in Section 38

    Section 38 of the Personal Data Processing Law creates a penalty aimed at the official, capped at 200 fine units, for public bodies. That looks like Latvia using the choice Article 83(7) gives member states. We found no official statement from the Inspectorate confirming it. So this is our reading of the text, not a confirmed answer.

  • Whether privacy notices aimed at Latvian consumers must be provided in Latvian

    The Official Language Law makes private companies use Latvian in records and documents where their work touches the public interest. It names consumer rights protection expressly. That clearly covers information aimed at consumers. But we found no Inspectorate guidance applying it to privacy notices. Write yours in Latvian if you want to be safe.

  • The current text of Latvijas Banka's own outsourcing regulations for credit institutions

    The Credit Institutions Law leaves the detail of outsourcing policies and contracts to Latvijas Banka's own rules. We confirmed the law itself. We could not confirm the regulator's detailed rules, so we cannot tell you exactly what an outsourcing contract must contain. Ask Latvijas Banka.

  • That no localisation rule exists in Latvia for insurance, securities, payments, education, gaming, defence procurement or mapping data

    We read the Geospatial Information Law and the State Information Systems Law in full and found nothing. We also confirmed that financial services sit with Latvijas Banka under European rules that do not force data to stay at home. We cannot check every Cabinet regulation. So this is 'we found no rule, checked 18 August 2026', not 'there is no rule'. Check before you rely on it.

  • Who currently holds the post of Director of the State Data Inspectorate and when the five-year term expires

    The Inspectorate's 'About us' page explains how the director is appointed. We could not find the current holder's name or the end of their term. Ask the Inspectorate if you need it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.