Latvia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Latvia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Latvia follows European Union privacy rules. Personal data can leave the country once you have the right paperwork. But Latvia adds walls of its own. Accounting records may not be stored outside the European Union at all. Phone and internet companies must keep call records for eighteen months. Banks need the central bank's approval before handing systems to an outside supplier.
Data governance in Latvia
The eight things that decide how you handle data about people in Latvia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules reach you even with no office in Latvia. You are covered if you offer goods or services to people in Latvia, or track what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue cut-off. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than its own test of who is covered.
- What you have to do here:
- Appoint a representative
Who is covered is set by Article 3 of Regulation (EU) 2016/679, the General Data Protection Regulation. It is not set by Latvian law. Latvia's Personal Data Processing Law (Fizisko personu datu apstrādes likums) was adopted on 21 June 2018 and came into force on 5 July 2018. It says its job is to build the national parts of the data protection system and to name the regulator. It does not widen or narrow the European rules. The duty to name a representative in Article 27 is European, not a Latvian addition. Some Latvian industry laws work differently. They reach any company registered in Latvia, including a branch of a foreign company and a permanent base of a non-resident. The Accounting Law names those in Section 3. So a foreign group's Latvian branch is caught by the accounting storage rule, even if the group's systems sit in New York.
Sources
- Official sourceLikumi.lv, official consolidated legislation, VSIA Latvijas VēstnesisFizisko personu datu apstrādes likums (Personal Data Processing Law), Sections 1-3
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums (Accounting Law), Section 3 — who the law binds, including foreign branches
likumi.lv
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
Personal data can leave Latvia, but the answer changes with the type of data. For ordinary personal data the European rules apply. You can send it anywhere once you have the right paperwork. For accounting records the door is shut at the edge of the European Union. Paper stays in Latvia. Electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses
Industry by industry, checked 18 August 2026. ALL BUSINESSES - accounting records. This is a firm wall. Accounting Law Section 27(1) says paper accounting documents must be stored in the Republic of Latvia. Electronic accounting documents must be stored in Latvia or another European Union member state. The section ties itself to Regulation (EU) 2018/1807 on the free flow of non-personal data. So it is written as freedom inside the European Union and a ban outside it. This is the Latvian storage rule people miss most often. A Latvian company, or the Latvian branch of a foreign group, cannot lawfully keep its ledgers only on a United States or United Kingdom cloud. Closed at the European Union border. TELECOMS. The keep-it duty is in the Electronic Communications Law of 14 July 2022, Section 99(4). A telecoms company must keep the data listed in Sections 100 and 101 for 18 months. There is no express rule that the data sits in Latvia. But Section 99(6) bans the operator from telling anyone that data was requested or handed over. Section 99(7) limits who can handle it to authorised staff. So an offshore support desk cannot be given routine access. Paperwork works here, with a long keep-it period. BANKING. Credit Institutions Law Section 10.1(7)-(10). Before taking a significant outsourced service, a bank must file a written application with reasons to Latvijas Banka. It must wait 30 working days. It may go ahead only if no ban arrives. Latvijas Banka may ban the arrangement if it would limit the regulator's ability to do its job. It may also inspect the supplier at the supplier's own premises. That is a location veto in all but name. Government permission is the gate. INSURANCE, INVESTMENT FIRMS, PAYMENTS, CRYPTO. Same supervisor, Latvijas Banka, which took over the Financial and Capital Market Commission. We found no separate Latvian rule that data must stay in the country for these, checked 18 August 2026. Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied since 17 January 2025 and covers their technology outsourcing. It makes the contract name the countries where data will be handled. It does not make the data stay at home. STATE AND CRITICAL COMPUTER SYSTEMS. Cabinet Regulation No. 397 of 25 June 2025 sets minimum cyber security requirements and came into force on 2 July 2025. Points 94 and 101 limit who may supply and make Class A information system resources for owners of critical technology infrastructure. The supplier, its board, its shareholders and its true owner must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country. Point 129.2 goes further. An auditor checking compliance may handle audit information only inside NATO, European Union and European Free Trade Association territory. Closed at the allied-country border. HEALTH. We found no rule that health data must stay in Latvia, checked 18 August 2026. Medical records must be gathered electronically in the single national health information system, which the state runs in Latvia. Paper records must be kept for between one year and forty years, depending on the document. MAPPING AND LOCATION DATA. We found no export restriction, checked 18 August 2026. The Geospatial Information Law of 2009 puts the European INSPIRE directive into Latvian law. It is about sharing and licensing, not about keeping data in the country. EDUCATION, GAMING, DEFENCE BUYING, GOVERNMENT CLOUD. We found no separate storage-location rule in statute beyond the cyber security supplier rules above, checked 18 August 2026. The State Information Systems Law contains no storage-location requirement.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums (Accounting Law), Section 27(1) — where accounting documents must be stored
likumi.lv
“Grāmatvedības dokumenti papīra formā glabājami Latvijas Republikas teritorijā. Grāmatvedības dokumenti elektroniskā formā glabājami Latvijas Republikas vai citas Eiropas Savienības dalībvalsts teritorijā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums (Electronic Communications Law), Sections 99-101 — 18-month retention
likumi.lv
“Elektronisko sakaru komersants nodrošina saglabājamo datu glabāšanu 18 mēnešus.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationKredītiestāžu likums (Credit Institutions Law), Section 10.1 — significant outsourcing filing and central bank veto
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397 (25.06.2025.) — Minimālās kiberdrošības prasības, points 94, 101 and 129.2
likumi.lv
“auditors apstrādā audita ietvaros iegūto informāciju vienīgi NATO, Eiropas Savienības un EBTA dalībvalstu teritorijā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationĢeotelpiskās informācijas likums (Geospatial Information Law) — checked, no export restriction found
likumi.lv
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
For personal data you can only send to approved countries, rather than avoiding banned ones. You may send data to a country the European Commission has approved. Or you can use the European Union's standard contract template. Or you can use approved group-wide rules. The approved list is real and long. It includes the United Kingdom, Japan, South Korea, Switzerland and, for signed-up companies only, the United States. None of this helps with accounting records. That wall is about geography, and no contract unlocks it.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
The transfer rules are entirely European and apply unchanged in Latvia. Chapter V of Regulation (EU) 2016/679 sets them out. We checked the approved-destination list against the European Commission's own page on 18 August 2026. It contains Andorra, Argentina, Brazil (new, 26 January 2026, both ways), Canada (commercial bodies only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the European Patent Organisation, and the United States for companies signed up to the European Union-United States Data Privacy Framework. None has been withdrawn or suspended. The 2021 standard contract clauses in Decision (EU) 2021/914 are still the current set and have not been changed. New clauses were promised for companies abroad that the regulation already catches directly. They are still not adopted as of 18 August 2026. Company-wide rules approved by a regulator remain available. The narrow one-off exceptions in Article 49 are not for routine or bulk flows. You are still expected to write down why the destination country is safe. European Data Protection Board Guidelines 02/2024 were made final in June 2025. They confirm that an order from a non-European authority is not on its own a legal reason to hand data over. The most time-sensitive item is the European Union-United States Data Privacy Framework. It is still in force and legally valid on 18 August 2026, but it is under pressure. The General Court threw out the Latombe challenge on 3 September 2025. It was appealed to the Court of Justice on 31 October 2025. On 31 July 2026 the European Data Protection Board formally asked the Commission to look at whether recent United States developments affect the decision. The Commission has not suspended or cancelled it. Do not make it your only route. Regulation (EU) 2018/1807 stops member states forcing non-personal data to stay on their own soil, except on public security grounds. That is why the Accounting Law rule is written as freedom inside the European Union rather than as a Latvia-only rule.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Chapter V — transfers to third countries
eur-lex.europa.eu
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data, ban on member-state localisation
eur-lex.europa.eu
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums — no separate national transfer approval regime
likumi.lv
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The privacy regulator is the State Data Inspectorate, and it really works. In 2025 it took 1,034 complaints and ran 1,396 checks. It applied corrective measures 62 times. It issued fines totalling 326,400 euros (about 355,000 US dollars). The largest single fine was 300,000 euros (about 327,000 US dollars). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks on its own initiative. Separate regulators handle banking, telecoms and cyber security, and all are staffed.
Datu valsts inspekcija, the State Data Inspectorate, was created on 1 January 2001. It is a government body under Cabinet supervision but independent in its work. The Cabinet appoints its director for five years. Its 2025 public report records 1,034 complaints from members of the public, 96 breach reports from companies, 194 other submissions, and 1,396 checks on how data is used. It applied corrective measures in 62 cases. Fines ran from 150 euros to 300,000 euros and totalled 326,400 euros. It had 32 officials and employees on average. Its first-half 2026 update records 832 complaints, 36 violations found, corrective measures in 9 cases, 73 checks on its own initiative, 898 telephone consultations and 96 opinions on draft laws. On this evidence it is an active regulator of moderate size, not an aggressive one. It publishes far more guidance than penalties. Other enforcers, all working. Latvijas Banka, the central bank, took over the Financial and Capital Market Commission. It now supervises banks, insurers, investment firms, payment and electronic money institutions and crypto-asset service providers, and issues licensing and supervisory decisions. The National Cyber Security Centre (Nacionālais kiberdrošības centrs) started work on 1 September 2024 under the Ministry of Defence. It works with CERT.LV at the University of Latvia's Institute of Mathematics and Computer Science. The Constitution Protection Bureau (Satversmes aizsardzības birojs) supervises owners of critical technology infrastructure and can impose its own penalties of up to 10 million euros. One odd feature. For public bodies, Section 38 of the Personal Data Processing Law sends unlawful data handling into the administrative-offence system. The penalty targets the official personally and is capped at 200 fine units. At five euros a unit that is 1,000 euros (about 1,090 US dollars). That is a very different lever from a company fine.
Sources
- Official sourceDatu valsts inspekcija (State Data Inspectorate)Datu valsts inspekcijas 2025. gada publiskais pārskats — complaints, checks, corrective measures and fine totals
dvi.gov.lv
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaInformācija par Datu valsts inspekcijas aktualitātēm 2026. gada pirmajā pusgadā, 24 July 2026
dvi.gov.lv
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaAbout us — legal basis, independence and five-year director term
dvi.gov.lv
Link checked 18 August 2026
- Official sourceAizsardzības ministrija (Ministry of Defence)Kiberdrošība — the National Cyber Security Centre began operating on 1 September 2024
mod.gov.lv
Link checked 18 August 2026
- Official sourceLatvijas BankaSupervision — Latvijas Banka supervises banks, insurers, investment firms, payment institutions and crypto-asset service providers
bank.lv
Link checked 18 August 2026
How long you must keep it — and when to delete it
Latvia has an unusually crowded set of minimum keeping periods, and one surprising maximum. You must keep accounting registers for ten years, and supporting documents for at least five. Phone and internet companies must keep call records for eighteen months. Medical records run from one year to forty years, depending on the form. Pulling the other way, security audit trails must normally be deleted after one year. That is shorter than many global logging policies allow.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUMS. Accounting Law Section 28: annual reports until the company is reorganised or wound up; inventory lists, accounting registers and accounting organisation documents 10 years; payroll supporting documents dated before 1 January 1999, 75 years; payroll documents dated 1 January 1999 or later, 10 years, with holiday pay records 10 years from the end of the job; all other supporting documents at least five years, and for as long as you need to trace the transaction. Electronic Communications Law Section 99(4): 18 months for stored traffic, location and subscriber-identifying data. Section 99(8) then requires deletion. The exceptions are where an authority asked for the data before the deadline, or the operator still needs it for billing, claims or interconnection. Cabinet Regulation No. 265 on medical documentation: keep-it periods by document type of 1, 3, 5, 10, 15, 25 and 40 years after the last entry, and 10 years for radiology images. Destruction after that is governed by the Archives Law. MAXIMUM. Personal Data Processing Law Section 37(2). Where you have a duty to keep system audit trails, you may keep them no longer than one year after the entry was made. Other laws, or the nature of the work, can change that. Section 37(3) then lets you refuse a person's request for information you no longer hold because the audit trail has expired. This is the reverse of the usual problem. Most organisations worry about keeping logs long enough. Latvia caps them. WHICH ONE WINS. Latvia settles clashes by which rule is more specific, not by a general rule. The one-year audit-trail cap says expressly that other laws, or the nature of the work, can override it. So a longer industry keep-it duty wins. The accounting minimum has no such escape, and it is the harder limit.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Section 28 — minimum retention of accounting documents
likumi.lv
“inventarizācijas sarakstiem, grāmatvedības reģistriem un grāmatvedības organizācijas dokumentiem — 10 gadi”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums, Section 37 — audit trails kept no longer than one year
likumi.lv
“tie ir uzglabājami ne ilgāk kā vienu gadu pēc ieraksta izdarīšanas, ja normatīvie akti vai apstrādes raksturs nenosaka citādi.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 265, Medicīnisko dokumentu lietvedības kārtība, point 35 — 1 to 40 year retention
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums, Section 99(4) and 99(8) — 18 months then deletion
likumi.lv
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least two deadlines, and often three. If personal data is exposed, you have 72 hours to tell the State Data Inspectorate. You must also tell the people affected without delay if the risk to them is high. If you run an essential or important service, you have 24 hours to send an early warning to the cyber incident response body. A first report follows at 72 hours. Trust service providers get only 24 hours for that first report. Banks have a third set of reporting duties under European financial rules.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE ONE, privacy. Article 33 of Regulation (EU) 2016/679: 72 hours to the State Data Inspectorate. Article 34: tell the people affected without undue delay where the risk is high. The Inspectorate received 96 breach reports in 2025, of which 83 involved data being seen by the wrong people. DEADLINE TWO, cyber security. National Cyber Security Law Section 33. On a significant cyber incident you must send an electronic early warning to the cyber incident response body. It is due without delay and no later than 24 hours. An initial report follows without delay and no later than 72 hours. A trust service provider must file that initial report within 24 hours. On any cyber incident, an owner of critical technology infrastructure must also inform the state security body immediately. You must also tell your own customers without delay where a significant incident or threat affects them. DEADLINE THREE, finance. Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied to Latvian financial companies since 17 January 2025. It adds its own timetable for reporting major incidents to Latvijas Banka. The overlap is where things go wrong. A ransomware attack on a Latvian hospital or bank starts all three deadlines at once. The 24-hour cyber early warning lands well before the 72-hour privacy report is ready.
Sources
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums (National Cyber Security Law) — 24-hour early warning, 72-hour initial report
likumi.lv
“Nozīmīga kiberincidenta gadījumā subjekts nekavējoties, bet ne vēlāk kā 24 stundu laikā elektroniski iesniedz kompetentajai kiberincidentu novēršanas institūcijai agrīno brīdinājumu par nozīmīgo kiberincidentu.”
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaDatu valsts inspekcijas 2025. gada publiskais pārskats — 96 breach notifications received
dvi.gov.lv
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One: a child can agree for themselves from age 13, not 16. So a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine. A company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.
- What you have to do here:
- Get a parent's consent for children · Keep logs
- What it costs if you get it wrong:
- Criminal liability
1. AGE 13. Section 33 of the Personal Data Processing Law sets the age at which a child can agree to online services at 13. That is the lowest the European regulation allows. A product built for 16 is not wrong in Latvia. But a product that assumes 16 across Europe will collect parental consent it does not need. A product built to the United States rule of 13 happens to fit. 2. YOU CAN GO TO PRISON. Section 145 of the Criminal Law has been in its current form since 4 July 2024. It covers unlawful acts with personal data done out of revenge, greed or blackmail. The basic penalty is up to one year in prison. It is up to two years where substantial harm is caused. It is up to four years where a public official, or a responsible employee of a company or organisation, does it. It is up to five years for forcing or tricking a company, a supplier or a person into carrying out unlawful acts. This applies to individuals, and it is a prosecution, not a fine. 3. ACCOUNTING STORAGE AND LANGUAGE. Accounting Law Section 27(1) is the geographic wall described above. Section 9(1) adds that entries in accounting registers must be made in Latvian. A second language is allowed alongside. A group standardising on an English-only, United States-hosted resource planning system fails both tests at once. 4. THE ONE-YEAR LOG CAP. Section 37(2) of the Personal Data Processing Law caps audit trails at one year where a keep-it duty applies. Most global security teams keep sign-in and access logs for two years or more by default. 5. LOCAL PEOPLE AND SUPPLIER NATIONALITY. Cabinet Regulation No. 397 of 25 June 2025 makes an essential or important service provider appoint a named cyber security manager. That person must be a citizen of a NATO, European Union or European Free Trade Association state, with set qualifications. For critical infrastructure owners, the Constitution Protection Bureau must find no security risk in that person. For Class A information systems, the supplier, its board, its shareholders and its true owner must all be from an allied country. This is an ownership and nationality screen, not a data rule. Standard supplier checks will not catch it. 6. A SIXTH, QUIETER ONE. Latvia runs an official register of qualified data protection specialists at the Inspectorate, with a state qualification exam. Appointing someone from the list is optional, not required. But tenders and public-sector customers increasingly ask for one.
Sources
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums, Sections 17, 18, 33 and 37
likumi.lv
“ja bērns ir vismaz 13 gadus vecs vai ja attiecībā uz bērnu, kurš vēl nav sasniedzis 13 gadu vecumu, piekrišanu ir devis viņa vecāks vai likumiskais aizbildnis.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationKrimināllikums (Criminal Law), Section 145 — unlawful activities with personal data
likumi.lv
“Par šā panta pirmajā vai otrajā daļā paredzēto noziedzīgo nodarījumu, ja to izdarījusi valsts amatpersona vai uzņēmuma (uzņēmējsabiedrības) vai organizācijas atbildīgs darbinieks, — soda ar brīvības atņemšanu uz laiku līdz četriem gadiem.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Sections 9 and 27
likumi.lv
“Grāmatvedības reģistros ierakstus izdara latviešu valodā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397, Minimālās kiberdrošības prasības, points 11-13 and 94 — cyber security manager nationality and supplier ownership screen
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationDatu aizsardzības speciālista kvalifikācijas noteikumi (Cabinet Regulation No. 620 of 2020)
likumi.lv
What's changing next
Two dated changes and three powers already in someone's hand. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out. That is a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification exam. The powers: the government may still write binding rules on where computer systems are hosted, and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being changed piece by piece.
DATED. 12 January 2027 - Regulation (EU) 2023/2854, the Data Act, has applied since 12 September 2025 and reaches its hard deadline. All cloud switching charges and data export fees must be zero. Chapter VII of the same regulation limits when a non-European government can get non-personal data held in the European Union. 14 October 2026 - the State Data Inspectorate's next data protection specialist qualification exam, announced on 7 August 2026. 18 June 2026 - changes to the National Cyber Security Law already took effect. They move designation decisions from the Digital Security Supervisory Committee to the National Cyber Security Centre. They let the Centre remove a company from the essential and important services list. They delete the article on early warning sensors. And they widen the group of nationally significant private bodies. If you mapped your duties before June 2026, check them again. POWERS ALREADY IN SOMEONE'S HAND. These matter more than pending bills. 1. Section 30 of the National Cyber Security Law gives the Cabinet three powers. It can set data centre security requirements, rules on where information systems must sit inside data centres, and rules on security operations centres. We could not find those rules issued. Until they are, hosting placement for essential and important service providers follows only the general minimum requirements. When they land, they will be a placement rule made by the Cabinet, with no new act of parliament needed. 2. The European Commission decided the United States is safe enough under the European Union-United States Data Privacy Framework. That decision is under appeal at the Court of Justice. On 31 July 2026 the European Data Protection Board asked the Commission to review it. If it falls, every Latvian company relying on it for United States transfers needs a replacement route overnight. 3. The European Union cloud certification scheme is still not adopted. It has been stuck over sovereignty since 2020. So national and industry rules like Latvia's allied-supplier screen keep applying. Two more are proposals only, with no legal effect. They are the Cloud and AI Development Act of 3 June 2026 and the Digital Omnibus of 19 November 2025.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrozījumi Nacionālās kiberdrošības likumā, in force 18 June 2026
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums, Section 30 — Cabinet power over data centre requirements and system placement
likumi.lv
“Ministru kabinets nosaka: 1) datu centru drošības prasības ... 2) noteikumus par informācijas sistēmu izvietošanu datu centros.”
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaData protection specialist qualification examination announced for 14 October 2026
dvi.gov.lv
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms rules
Official name: Elektronisko sakaru likums · Adopted by the Saeima 14 July 2022, published Latvijas Vēstnesis No. 144, 28 July 2022; Sections 99-101 · Act of parliament
Phone and internet companies in Latvia must keep call, connection, location and subscriber-identifying data for 18 months. They must hand it to investigating and security bodies on request. They may not tell anyone that a request was made. No rule says the data must physically stay in Latvia. But the secrecy rule and the authorised-staff rule make casual access from abroad impractical.
Enforced by Public Utilities Commission
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Keep data for a minimum period — 18 monthsTraffic data, location data and subscriber-identifying data generated in providing the service.
- Delete data after a period — 18 monthsSection 99(8): delete after the period, except data already requested by an authority or still needed for billing, claims, debt recovery or interconnection.
- Secure the dataSection 99(3): protect stored data against accidental or unlawful destruction, loss, change, unauthorised use or disclosure.
- Do not hand data to foreign authorities on demandSection 99(6): the operator may not say that data was requested or handed over, and may not identify the end users affected. Section 99(7): only staff authorised by the operator may handle the stored data.
What it costs if you get it wrong
- Loss of your licence: Regulatory measures under the Electronic Communications LawNon-compliance with retention and disclosure duties
Sources
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums, Sections 99, 100 and 101
likumi.lv
“Elektronisko sakaru komersants nodrošina saglabājamo datu glabāšanu 18 mēnešus, kā arī to nodošanu šā panta pirmajā daļā minētajām institūcijām pēc to pieprasījuma.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Nacionālās kiberdrošības likums · Adopted by the Saeima 20 June 2024, published Latvijas Vēstnesis No. 128A, 4 July 2024; amended with effect from 18 June 2026 · Act of parliament
Latvia's implementation of the European network and information security directive. It covers energy, transport, banking, health, water, digital infrastructure, cloud and data centre providers and much of the public sector. Twenty-four hours for an early warning, seventy-two for a first report. Fines reach 10 million euros or 2 percent of turnover.
Enforced by National Cyber Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 1 April 2025You had to assess yourself and tell the National Cyber Security Centre whether you are an essential or important service provider by 1 April 2025. The official list was to be approved by 17 April 2025.
- Report cyber incidents — within 24 hoursEarly warning of a significant cyber incident.
- Report cyber incidents — within 72 hoursInitial report of a significant cyber incident. Trust service providers: 24 hours.
- Secure the dataTake technical and organisational steps based on your risk, under the minimum cyber security requirements regulation.
- Independent auditCompliance audit by an auditor registered with the Digital Security Supervisory Committee.
- Appoint a data protection officer — from 1 October 2025A named cyber security manager had to be notified to the National Cyber Security Centre and the Constitution Protection Bureau by 1 October 2025. The person must be a citizen of a NATO, European Union or European Free Trade Association state.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $11 millionMaterial non-compliance by an essential service provider
- Percentage of global turnover: 2% of last financial year net turnoverEssential service provider with turnover above EUR 500 million
- Fixed maximum fine: €7,000,000 — about $8 millionMaterial non-compliance by an important service provider
- Percentage of global turnover: 1.4% of last financial year net turnoverImportant service provider with turnover above EUR 500 million
Sources
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums — consolidated text, including Sections 30, 33 and 46 and the transitional provisions
likumi.lv
“Nacionālais kiberdrošības centrs ir tiesīgs par būtisku neatbilstību šajā likumā noteiktajām prasībām piemērot būtisko pakalpojumu sniedzējam soda naudu līdz 10 miljoniem euro.”
Link checked 18 August 2026
- Official sourceAizsardzības ministrija (Ministry of Defence)Kiberdrošība — the National Cyber Security Centre, operating since 1 September 2024
mod.gov.lv
Link checked 18 August 2026
Government data must stay in the country
Official name: Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības" · Ministru kabineta 2025. gada 25. jūnija noteikumi Nr. 397, issued under the National Cyber Security Law; points 94, 101 and 129 · Directly binding regulation
For Latvia's most critical state and infrastructure systems, who supplies you matters as much as where the data sits. The supplier, its board, its shareholders and its ultimate owner must come from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country. Audit information may only be handled inside NATO, European Union or European Free Trade Association territory.
Enforced by Constitution Protection Bureau
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryPoint 129.2: an auditor checking compliance may handle audit information only inside NATO, European Union and European Free Trade Association territory.
- Written vendor contractPoints 94 and 101: for Class A information systems of critical infrastructure owners, the supplier and the maker must be registered in a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner state. Their board, shareholders and true owner must be from those states too.
- Prove the data stays under local controlExemptions exist where the shareholder is a Latvian public person or where a specific permission is obtained.
- Hold a security certificateAudits must be carried out by an auditor registered with the Digital Security Supervisory Committee; cloud and data centre auditors need additional certification.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $11 millionMaterial non-compliance by an owner of critical information and communication technology infrastructure, imposed by the Constitution Protection Bureau
- Percentage of global turnover: 2% of last financial year net turnoverSame, where turnover exceeds EUR 500 million
Sources
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397, Minimālās kiberdrošības prasības, points 94, 101, 122-129
likumi.lv
“tā ir reģistrēta NATO, Eiropas Savienības vai EBTA dalībvalstī vai NATO Indijas un Klusā okeāna reģiona sadarbības valstī”
Link checked 18 August 2026
- Official sourceLikumi.lvNacionālās kiberdrošības likums, Sections 7 and 46(3) — Constitution Protection Bureau supervision and penalties
likumi.lv
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Kredītiestāžu likums · Credit Institutions Law, Section 10.1 (outsourcing) and Sections 61-63 (banking secrecy); most recently amended with effect from 9 June 2026 · Act of parliament
A Latvian bank cannot simply move its systems to a new cloud or service provider. Big outsourcing deals must be filed with Latvijas Banka. It has thirty working days to say no. It can say no because the deal would get in the way of supervision. Banking secrecy also follows the data into the supplier's hands.
Enforced by Bank of Latvia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyBefore receiving a significant outsourced service the bank must file a reasoned written application with Latvijas Banka. It may proceed only if no prohibition arrives within 30 working days; the clock can be paused once for up to 20 working days.
- Extra vendor secrecy termsA standard supplier agreement is not enough. The outsourcing provider is bound by banking secrecy and may not disclose protected information. Requests for that information must go to the bank itself, not the supplier.
- Written vendor contractRights and duties must be in a written outsourcing contract meeting Latvijas Banka's rules; the bank must also have an outsourcing policy and procedures.
- Independent auditLatvijas Banka may inspect the supplier at the supplier's own premises, take copies of any documents and interview its staff.
What it costs if you get it wrong
- Order to stop: Prohibition on receiving the planned outsourced serviceWhere the arrangement would restrict Latvijas Banka's ability to perform its statutory functions, or harm customers and depositors
- Loss of your licence: Withdrawal of authorisationSerious or repeated breach of prudential requirements
Sources
- Official sourceLikumi.lv, official consolidated legislationKredītiestāžu likums, Section 10.1(5)-(11) and Sections 61-63
likumi.lv
“Pirms nozīmīga ārpakalpojuma saņemšanas kredītiestāde iesniedz Latvijas Bankai motivētu rakstveida iesniegumu par plānoto ārpakalpojuma saņemšanu.”
Link checked 18 August 2026
- Official sourceLatvijas BankaSupervision — Latvijas Banka's supervisory remit and decisions
bank.lv
Link checked 18 August 2026
Health data rules
Official name: Ministru kabineta noteikumi Nr. 265 "Medicīnisko dokumentu lietvedības kārtība" · Cabinet Regulation No. 265 of 4 April 2006, chapter V as amended · Directly binding regulation
We found no rule requiring Latvian health data to stay in Latvia, checked 18 August 2026. Latvia does set long minimum keep-it periods, from one year to forty years depending on the document. It also makes you feed medical records into the national health information system, which the state hosts in Latvia.
Enforced by National Health Service
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Keep data for a minimum period — 40 yearsUp to 40 years after the last entry for some record types; other types run 1, 3, 5, 10, 15 or 25 years. Radiology images: 10 years.
- Keep records of how you use dataMedical records are accumulated electronically in the single national health-sector electronic information system, which the state runs in Latvia. Treatment institutions also keep records in their own systems.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine; plus privacy fines under the European regulationFailure to keep or destroy medical records as required
Sources
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 265, points 5, 35, 35.1 and 35.2
likumi.lv
“Medicīniskie ieraksti tiek elektroniski uzkrāti vienotajā veselības nozares elektroniskajā informācijas sistēmā.”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Fizisko personu datu apstrādes likums · Adopted by the Saeima 21 June 2018, published Latvijas Vēstnesis 4 July 2018 · Act of parliament
Latvia's national privacy act. It sets up the State Data Inspectorate. It lowers to 13 the age at which a child can agree online. It caps audit-trail storage at one year. It creates an official register of qualified data protection specialists. It adds no separate national limit on sending personal data abroad.
Enforced by State Data Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 13Section 33. Latvia chose the lowest age the European regulation allows.
- Delete data after a period — 1 yearSection 37(2). Where you must keep an audit trail, you may keep it no longer than one year after the entry. Other laws, or the nature of the work, can change that.
- Keep logs — 1 year
- Appoint a data protection officerSections 17-18. You may appoint someone from the Inspectorate's official list of qualified data protection specialists, or any other qualified person. Using the list is optional.
- Tell people what you do
What it costs if you get it wrong
- Fixed maximum fine: 200 fine units (€1,000) — about $1 thousandSection 38: unlawful acts with personal data by a public-law legal person, or failure by a controller or processor in a public body — the penalty falls on the official personally
Sources
- Official sourceLikumi.lv, official consolidated legislation of the Republic of LatviaFizisko personu datu apstrādes likums — consolidated text
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lvPersonal Data Processing Law — official English translation
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lvAdministratīvās atbildības likums, Section 16(2) — one fine unit is five euros
likumi.lv
“Viena naudas soda vienība ir pieci euro.”
Link checked 18 August 2026
Personal data must stay in the country
Official name: Grāmatvedības likums · Adopted by the Saeima 10 June 2021, published 28 June 2021 · Act of parliament
This is the hardest storage rule in Latvia, and the one most often missed. Paper accounting documents must be kept inside Latvia. Electronic accounting documents must be kept inside Latvia or another European Union country. Entries in accounting registers must also be made in Latvian. It binds Latvian companies, branches of foreign companies and permanent bases alike.
Enforced by State Revenue Service
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryPaper accounting documents must stay in Latvia. Electronic accounting documents must stay in Latvia or another European Union member state. Nothing outside the European Union.
- Keep data for a minimum period — 10 yearsInventory lists, accounting registers and accounting organisation documents: 10 years.
- Keep data for a minimum period — 5 yearsAll other supporting documents: at least 5 years, and as long as needed to trace the transaction.
- Keep data for a minimum period — 75 yearsPayroll supporting documents dated before 1 January 1999: 75 years.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under the Law on Taxes and Duties and the Administrative Liability LawFailure to keep accounting documents as required
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Sections 3, 9, 27 and 28
likumi.lv
“Grāmatvedības dokumenti papīra formā glabājami Latvijas Republikas teritorijā. Grāmatvedības dokumenti elektroniskā formā glabājami Latvijas Republikas vai citas Eiropas Savienības dalībvalsts teritorijā atbilstoši Eiropas Parlamenta un Padomes 2018. gada 14. novembra regulā (ES) Nr. 2018/1807 ... noteiktajām prasībām.”
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Vispārīgā datu aizsardzības regula (Regulation (EU) 2016/679) · Regulation (EU) 2016/679 · Directly binding regulation
The European Union privacy regulation is the base layer in Latvia and applies directly. It does not require data to stay in Europe. It sets the conditions for letting data leave. Fines reach 20 million euros or 4 percent of worldwide group turnover, whichever is higher. An order to stop using the data usually hurts more.
Enforced by State Data Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a data protection officer — applies at: Public bodies, large-scale monitoring, large-scale special category data
- Appoint a representative — applies at: Controllers and processors outside the European Union that target or monitor people in the European Union
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBreach of basic principles, individual rights or transfer rules
- Fixed maximum fine: €20,000,000 — about $22 millionSame, where higher than the turnover figure
- Order to stop: n/aOrder to stop processing or suspend transfers outside Europe
- Claims by individuals: n/aCompensation claims by individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
- Official sourceEuropean CommissionAdequacy decisions — approved destinations, verified 18 August 2026
commission.europa.eu
- Official sourceEUR-LexRegulation (EU) 2018/1807 — member states may not impose localisation on non-personal data except on public-security grounds
eur-lex.europa.eu
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the 18-month blanket telecoms retention duty in Section 99(4) of the Electronic Communications Law is enforceable in full
The Court of Justice of the European Union has repeatedly held that keeping everyone's traffic and location data breaks European Union law. We could not confirm whether a Latvian court has set aside or narrowed Section 99(4). So we record the rule as in force. Treat how far it really reaches as contested.
That the Cabinet has not yet issued the regulations on data centre security requirements and on where information systems must be placed, promised by Section 30(2) of the National Cyber Security Law
We searched the official legislation database for 2025 and 2026 and found no such regulation. The National Cyber Security Centre's legislation page redirects to a general Ministry of Defence page that does not list it. We could not confirm this either way. The Cabinet questionnaire attached to the minimum cyber security requirements regulation refers to such rules, which suggests they are drafted or planned.
The total euro value of fines imposed by the State Data Inspectorate in the first half of 2026
The Inspectorate's July 2026 half-year update gives counts (832 complaints, 36 violations, corrective measures in 9 cases) but no monetary totals. Only the 2025 annual report gives euro figures.
Whether the State Data Inspectorate can impose European-regulation fines on Latvian public authorities, or only pursue the responsible official under the administrative-offence route in Section 38
Section 38 of the Personal Data Processing Law creates a penalty aimed at the official, capped at 200 fine units, for public bodies. That looks like Latvia using the choice Article 83(7) gives member states. We found no official statement from the Inspectorate confirming it. So this is our reading of the text, not a confirmed answer.
Whether privacy notices aimed at Latvian consumers must be provided in Latvian
The Official Language Law makes private companies use Latvian in records and documents where their work touches the public interest. It names consumer rights protection expressly. That clearly covers information aimed at consumers. But we found no Inspectorate guidance applying it to privacy notices. Write yours in Latvian if you want to be safe.
The current text of Latvijas Banka's own outsourcing regulations for credit institutions
The Credit Institutions Law leaves the detail of outsourcing policies and contracts to Latvijas Banka's own rules. We confirmed the law itself. We could not confirm the regulator's detailed rules, so we cannot tell you exactly what an outsourcing contract must contain. Ask Latvijas Banka.
That no localisation rule exists in Latvia for insurance, securities, payments, education, gaming, defence procurement or mapping data
We read the Geospatial Information Law and the State Information Systems Law in full and found nothing. We also confirmed that financial services sit with Latvijas Banka under European rules that do not force data to stay at home. We cannot check every Cabinet regulation. So this is 'we found no rule, checked 18 August 2026', not 'there is no rule'. Check before you rely on it.
Who currently holds the post of Director of the State Data Inspectorate and when the five-year term expires
The Inspectorate's 'About us' page explains how the director is appointed. We could not find the current holder's name or the end of their term. Ask the Inspectorate if you need it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.