Latvia
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.
Eight questions about Latvia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Latvia's rules apply to my company?
Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.
Territorial scope is set by Article 3 of Regulation (EU) 2016/679 (the General Data Protection Regulation), not by Latvian law. The Personal Data Processing Law (Fizisko personu datu apstrādes likums, adopted 21 June 2018, in force 5 July 2018) opens by saying its purpose is to create the national-level building blocks of the data protection system and to designate the supervisory authority; it does not narrow or widen GDPR's reach. The Article 27 representative duty is the GDPR's, not a Latvian add-on. Separately, several Latvian sectoral statutes reach any company registered in Latvia, including a branch of a foreign company and a permanent establishment of a non-resident: the Accounting Law names those entities expressly in Section 3, so a foreign group's Latvian branch is inside the accounting storage rule even if the group's systems sit in New York.
Sources
- Official sourceLikumi.lv, official consolidated legislation, VSIA Latvijas VēstnesisFizisko personu datu apstrādes likums (Personal Data Processing Law), Sections 1-3
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums (Accounting Law), Section 3 — who the law binds, including foreign branches
likumi.lv
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Can I store my users' data outside Latvia?
Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.
Sector by sector, checked 18 August 2026. ALL BUSINESSES — accounting records: hard wall. Accounting Law Section 27(1) says paper accounting documents must be stored in the territory of the Republic of Latvia, and electronic accounting documents must be stored in Latvia or another European Union member state. The section expressly ties itself to Regulation (EU) 2018/1807 on the free flow of non-personal data, so it is drafted as an EU-internal freedom and an external prohibition. This is the single most commonly missed Latvian storage rule: a Latvian company or a Latvian branch of a foreign group cannot lawfully keep its ledgers only on a United States or United Kingdom cloud. Rating: data must stay in the country at the European Union boundary. TELECOMS: Electronic Communications Law (14 July 2022) Section 99(4) requires an electronic communications merchant to retain the data listed in Sections 100 and 101 for 18 months. There is no express requirement to hold it in Latvia, but Section 99(6) bans the operator from telling anyone that data was requested or handed over, and Section 99(7) limits processing to authorised staff. Practical effect: an offshore support desk cannot be given routine access. Rating: data can leave with the right paperwork with a heavy retention floor. BANKING: Credit Institutions Law Section 10.1(7)-(10). Before receiving a significant outsourced service a bank must file a reasoned written application with Latvijas Banka, wait 30 working days, and may proceed only if no prohibition arrives. Latvijas Banka may prohibit the arrangement if it would restrict the regulator's ability to perform its statutory functions, and may inspect the supplier at the supplier's own premises. That is a location veto in all but name. Rating: data can leave with the right paperwork, with government permission as the gate. INSURANCE, INVESTMENT FIRMS, PAYMENTS, CRYPTO: same supervisor, Latvijas Banka, which absorbed the Financial and Capital Market Commission. No separate Latvian localisation rule found for these, checked 18 August 2026. Regulation (EU) 2022/2554 (the Digital Operational Resilience Act) has applied since 17 January 2025 and governs their information and communication technology outsourcing; it requires the contract to name the countries where data will be processed but imposes no localisation. STATE AND CRITICAL COMPUTER SYSTEMS: Cabinet Regulation No. 397 of 25 June 2025 on minimum cyber security requirements, in force 2 July 2025, points 94 and 101, restricts who may supply and manufacture Class A information system resources for owners of critical information and communication technology infrastructure — the supplier, its board, its shareholders and its beneficial owner must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country. Point 129.2 goes further and requires a compliance auditor to process audit information solely within NATO, European Union and European Free Trade Association territory. Rating: data must stay in the country at the allied-country boundary. HEALTH: no localisation rule found, checked 18 August 2026. Medical records are, however, required to be accumulated electronically in the single national health-sector information system, which the state runs in Latvia, and paper-record retention runs from one year to forty years depending on the document. MAPPING AND LOCATION DATA: no export restriction found, checked 18 August 2026. The Geospatial Information Law of 2009 is an implementation of the European INSPIRE directive and is about sharing and licensing, not about keeping data in the country. EDUCATION, GAMING, DEFENCE PROCUREMENT, GOVERNMENT CLOUD as such: no separate statutory localisation rule found beyond the cyber security supplier rules above, checked 18 August 2026. The State Information Systems Law contains no storage-location requirement.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums (Accounting Law), Section 27(1) — where accounting documents must be stored
likumi.lv
“Grāmatvedības dokumenti papīra formā glabājami Latvijas Republikas teritorijā. Grāmatvedības dokumenti elektroniskā formā glabājami Latvijas Republikas vai citas Eiropas Savienības dalībvalsts teritorijā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums (Electronic Communications Law), Sections 99-101 — 18-month retention
likumi.lv
“Elektronisko sakaru komersants nodrošina saglabājamo datu glabāšanu 18 mēnešus.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationKredītiestāžu likums (Credit Institutions Law), Section 10.1 — significant outsourcing filing and central bank veto
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397 (25.06.2025.) — Minimālās kiberdrošības prasības, points 94, 101 and 129.2
likumi.lv
“auditors apstrādā audita ietvaros iegūto informāciju vienīgi NATO, Eiropas Savienības un EBTA dalībvalstu teritorijā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationĢeotelpiskās informācijas likums (Geospatial Information Law) — checked, no export restriction found
likumi.lv
Link checked 18 August 2026
What do I need in place before data leaves Latvia?
For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.
The transfer regime is entirely the European Union's, applied unchanged in Latvia. Chapter V of Regulation (EU) 2016/679 sets it out. The approved-destination list, verified against the European Commission's own page on 18 August 2026, contains Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada (commercial bodies only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. The 2021 standard contractual clauses in Decision (EU) 2021/914 remain the operative set and are unamended; the promised new clauses for importers already directly caught by the regulation are still not adopted as of 18 August 2026. Binding corporate rules remain available. The narrow one-off exceptions in Article 49 are not for routine or bulk flows. A transfer impact assessment is still expected. The European Data Protection Board's Guidelines 02/2024, final in June 2025, confirm that an order from a non-European authority is not by itself a lawful basis to hand data over. The most time-sensitive item is the EU-US Data Privacy Framework. It is still in force and legally valid on 18 August 2026, but it is under pressure: the Latombe challenge was dismissed by the General Court on 3 September 2025 and appealed to the Court of Justice on 31 October 2025, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent United States developments affect the decision's validity. The Commission has not suspended or revoked it. Do not build a single-mechanism architecture on it. Regulation (EU) 2018/1807 forbids member states from imposing localisation on non-personal data except on public-security grounds — which is why the Accounting Law rule is drafted as an EU-internal freedom rather than a Latvia-only rule.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Chapter V — transfers to third countries
eur-lex.europa.eu
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data, ban on member-state localisation
eur-lex.europa.eu
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums — no separate national transfer approval regime
likumi.lv
Link checked 18 August 2026
Who enforces the rules in Latvia, and what can they do?
The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.
Datu valsts inspekcija (the State Data Inspectorate) was created on 1 January 2001 and is a direct administration institution under Cabinet supervision, independent in its work, with a director appointed by the Cabinet for five years. Its 2025 public report records 1,034 data subject complaints, 96 controller breach notifications, 194 other submissions, 1,396 personal data processing checks, corrective measures in 62 cases, fines from 150 euros to 300,000 euros totalling 326,400 euros, and an average of 32 officials and employees. Its first-half 2026 update records 832 complaints, 36 violations found, corrective measures in 9 cases, 73 own-initiative checks, 898 telephone consultations and 96 opinions on draft legislation. On the evidence this is an active regulator of moderate size, not an aggressive one: it publishes far more guidance than it does penalties. Other enforcers, all operational: Latvijas Banka (the central bank), which absorbed the Financial and Capital Market Commission and now supervises banks, insurers, investment firms, payment and electronic money institutions and crypto-asset service providers, and issues licensing and supervisory decisions; the National Cyber Security Centre (Nacionālais kiberdrošības centrs), which started work on 1 September 2024 under the Ministry of Defence, working with CERT.LV at the University of Latvia's Institute of Mathematics and Computer Science; and the Constitution Protection Bureau (Satversmes aizsardzības birojs), which supervises owners of critical information and communication technology infrastructure and can impose its own penalties of up to 10 million euros. One structural quirk: for public bodies, Section 38 of the Personal Data Processing Law routes unlawful data handling into the administrative-offence system with a penalty aimed at the official personally, capped at 200 fine units, which at five euros a unit is 1,000 euros (about $1,090). That is a very different lever from a corporate fine.
Sources
- Official sourceDatu valsts inspekcija (State Data Inspectorate)Datu valsts inspekcijas 2025. gada publiskais pārskats — complaints, checks, corrective measures and fine totals
dvi.gov.lv
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaInformācija par Datu valsts inspekcijas aktualitātēm 2026. gada pirmajā pusgadā, 24 July 2026
dvi.gov.lv
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaAbout us — legal basis, independence and five-year director term
dvi.gov.lv
Link checked 18 August 2026
- Official sourceAizsardzības ministrija (Ministry of Defence)Kiberdrošība — the National Cyber Security Centre began operating on 1 September 2024
mod.gov.lv
Link checked 18 August 2026
- Official sourceLatvijas BankaSupervision — Latvijas Banka supervises banks, insurers, investment firms, payment institutions and crypto-asset service providers
bank.lv
Link checked 18 August 2026
How long do I have to keep the data?
Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.
FLOORS. Accounting Law Section 28: annual reports until the company is reorganised or wound up; inventory lists, accounting registers and accounting organisation documents 10 years; payroll supporting documents dated before 1 January 1999, 75 years; payroll documents dated 1 January 1999 or later, 10 years (holiday pay records 10 years from the end of the employment relationship); all other supporting documents at least five years and for as long as needed to trace the transaction. Electronic Communications Law Section 99(4): 18 months for retained traffic, location and subscriber-identifying data, after which Section 99(8) requires deletion unless an authority asked for the data before the deadline or the operator still needs it for billing, claims or interconnection. Cabinet Regulation No. 265 on medical documentation: retention by document type of 1, 3, 5, 10, 15, 25 and 40 years after the last entry, and 10 years for radiology images, with destruction then governed by the Archives Law. CEILING. Personal Data Processing Law Section 37(2): where a controller is under a duty to keep system audit trails, they may be kept no longer than one year after the entry was made, unless other law or the nature of the processing says otherwise. Section 37(3) then lets the controller refuse a subject access request for information it no longer holds because the audit trail has expired. This is the mirror image of the usual problem: most organisations worry about keeping logs long enough, and Latvia caps them. CONFLICT RESOLUTION. Latvia resolves clashes by specificity, not by a general rule: the audit-trail ceiling itself carries an express 'unless other laws or the nature of processing provide otherwise' escape, so a longer sector-specific retention duty wins. The accounting floor has no such escape and is the harder constraint.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Section 28 — minimum retention of accounting documents
likumi.lv
“inventarizācijas sarakstiem, grāmatvedības reģistriem un grāmatvedības organizācijas dokumentiem — 10 gadi”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums, Section 37 — audit trails kept no longer than one year
likumi.lv
“tie ir uzglabājami ne ilgāk kā vienu gadu pēc ieraksta izdarīšanas, ja normatīvie akti vai apstrādes raksturs nenosaka citādi.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 265, Medicīnisko dokumentu lietvedības kārtība, point 35 — 1 to 40 year retention
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums, Section 99(4) and 99(8) — 18 months then deletion
likumi.lv
Link checked 18 August 2026
What happens if there is a breach?
Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.
Clock one, privacy: Article 33 of Regulation (EU) 2016/679, 72 hours to the State Data Inspectorate, and Article 34 notification to individuals without undue delay where the risk is high. The Inspectorate received 96 breach notifications in 2025, of which 83 were confidentiality breaches. Clock two, cyber security: National Cyber Security Law Section 33. On a significant cyber incident the subject must, without delay and no later than 24 hours, submit an electronic early warning to the competent cyber incident response body; then, without delay and no later than 72 hours, an initial report — but a trust service provider must file the initial report within 24 hours. On any cyber incident, an owner of critical information and communication technology infrastructure must also inform the competent state security institution immediately. The subject must also inform its own service recipients without delay where a significant incident or threat affects them. Clock three, finance: Regulation (EU) 2022/2554 (the Digital Operational Resilience Act) has applied to Latvian financial entities since 17 January 2025 and adds its own major incident reporting timetable to Latvijas Banka. The overlap is the failure point. A ransomware attack on a Latvian hospital or bank starts all three clocks at once, with the 24-hour cyber early warning biting well before the 72-hour privacy report is ready.
Sources
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums (National Cyber Security Law) — 24-hour early warning, 72-hour initial report
likumi.lv
“Nozīmīga kiberincidenta gadījumā subjekts nekavējoties, bet ne vēlāk kā 24 stundu laikā elektroniski iesniedz kompetentajai kiberincidentu novēršanas institūcijai agrīno brīdinājumu par nozīmīgo kiberincidentu.”
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaDatu valsts inspekcijas 2025. gada publiskais pārskats — 96 breach notifications received
dvi.gov.lv
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
What trips people up in Latvia?
Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.
1. AGE 13. Section 33 of the Personal Data Processing Law sets the information-society-services consent age at 13, the lowest the European regulation permits. A product built to a 16-year threshold is not wrong in Latvia, but a product built to assume 16 across Europe will over-collect parental consent, and a product built to a United States 13-year rule happens to fit. 2. CRIMINAL LIABILITY. Section 145 of the Criminal Law, in its version in force since 4 July 2024, punishes unlawful acts with personal data committed out of revenge, greed or blackmail with up to one year's deprivation of liberty; up to two years where substantial harm is caused; up to four years where committed by a public official or a responsible employee of a company or organisation; and up to five years for coercing or deceiving a controller, a processor or a data subject in order to carry out unlawful acts. This attaches to individuals and it is prosecution, not an administrative penalty. 3. ACCOUNTING STORAGE AND LANGUAGE. Accounting Law Section 27(1) is the geographic wall described above. Section 9(1) adds that entries in accounting registers must be made in Latvian, with a second language permitted alongside. A group standardising on an English-only United States-hosted resource planning system fails both tests at once. 4. THE ONE-YEAR LOG CEILING. Section 37(2) of the Personal Data Processing Law caps audit trails at one year where a retention duty applies. Most global security teams keep authentication and access logs for two years or more by default. 5. IN-COUNTRY PEOPLE AND SUPPLIER NATIONALITY. Cabinet Regulation No. 397 of 25 June 2025 requires an essential or important service provider to appoint a named cyber security manager who must be a citizen of a NATO, European Union or European Free Trade Association state, with defined qualifications, and for critical infrastructure owners the Constitution Protection Bureau must find no security risk in that person. For Class A information systems the supplier, its board, its shareholders and its beneficial owner must all be from an allied country. This is an ownership and nationality screen, not a data rule, and standard vendor due diligence will not catch it. 6. A SIXTH, QUIETER ONE. Latvia runs an official register of qualified data protection specialists at the Inspectorate, with a state qualification examination. Appointing a listed specialist is optional, not mandatory, but tenders and public-sector counterparties increasingly ask for one.
Sources
- Official sourceLikumi.lv, official consolidated legislationFizisko personu datu apstrādes likums, Sections 17, 18, 33 and 37
likumi.lv
“ja bērns ir vismaz 13 gadus vecs vai ja attiecībā uz bērnu, kurš vēl nav sasniedzis 13 gadu vecumu, piekrišanu ir devis viņa vecāks vai likumiskais aizbildnis.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationKrimināllikums (Criminal Law), Section 145 — unlawful activities with personal data
likumi.lv
“Par šā panta pirmajā vai otrajā daļā paredzēto noziedzīgo nodarījumu, ja to izdarījusi valsts amatpersona vai uzņēmuma (uzņēmējsabiedrības) vai organizācijas atbildīgs darbinieks, — soda ar brīvības atņemšanu uz laiku līdz četriem gadiem.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Sections 9 and 27
likumi.lv
“Grāmatvedības reģistros ierakstus izdara latviešu valodā.”
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397, Minimālās kiberdrošības prasības, points 11-13 and 94 — cyber security manager nationality and supplier ownership screen
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationDatu aizsardzības speciālista kvalifikācijas noteikumi (Cabinet Regulation No. 620 of 2020)
likumi.lv
What is changing soon in Latvia?
Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.
DATED. 12 January 2027 — Regulation (EU) 2023/2854 (the Data Act), which has applied since 12 September 2025, reaches its hard deadline: all cloud switching charges and data egress fees must be zero. Chapter VII of the same regulation restricts non-European government access to non-personal data held in the European Union. 14 October 2026 — the State Data Inspectorate's next data protection specialist qualification examination, announced 7 August 2026. 18 June 2026 — amendments to the National Cyber Security Law already took effect. They move designation decisions from the Digital Security Supervisory Committee to the National Cyber Security Centre, let the Centre remove an entity from the essential and important services list, delete the early warning sensors article, and widen the class of nationally significant private bodies. Anyone who mapped their obligations before June 2026 should re-check. DORMANT SWITCHES — these matter more than pending bills. 1. Section 30 of the National Cyber Security Law empowers the Cabinet to set data centre security requirements, rules on where information systems must be placed in data centres, and rules on security operations centres. We could not find those regulations issued. Until they are, hosting placement for essential and important service providers is governed only by the general minimum requirements. When they land, they will be a placement rule made by the Cabinet with no primary legislation needed. 2. The European Commission's adequacy decision for the EU-US Data Privacy Framework is under appeal at the Court of Justice, and on 31 July 2026 the European Data Protection Board asked the Commission to review its validity. If it falls, every Latvian company relying on it for United States transfers needs a replacement mechanism overnight. 3. The European Union cloud certification scheme is still not adopted, deadlocked over sovereignty since 2020, so national and sectoral rules like Latvia's allied-supplier screen continue to govern. The proposed Cloud and AI Development Act of 3 June 2026 and the Digital Omnibus of 19 November 2025 are proposals only and have no legal effect.
Sources
- Official sourceLikumi.lv, official consolidated legislationGrozījumi Nacionālās kiberdrošības likumā, in force 18 June 2026
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums, Section 30 — Cabinet power over data centre requirements and system placement
likumi.lv
“Ministru kabinets nosaka: 1) datu centru drošības prasības ... 2) noteikumus par informācijas sistēmu izvietošanu datu centros.”
Link checked 18 August 2026
- Official sourceDatu valsts inspekcijaData protection specialist qualification examination announced for 14 October 2026
dvi.gov.lv
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
Vispārīgā datu aizsardzības regula (Regulation (EU) 2016/679)
Directly binding regulation · Regulation (EU) 2016/679
The European Union privacy regulation is the base layer in Latvia and applies directly. It does not require data to stay in Europe; it sets conditions for letting it leave. Fines reach 20 million euros or 4 percent of worldwide group turnover, whichever is higher, and an order to stop processing usually hurts more.
Enforced by State Data Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a data protection officer — applies at: Public bodies, large-scale monitoring, large-scale special category data
- Appoint a local representative — applies at: Controllers and processors outside the European Union that target or monitor people in the European Union
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBreach of basic principles, individual rights or transfer rules
- Fixed maximum fine: €20,000,000 — about $22 millionSame, where higher than the turnover figure
- Order to stop: n/aOrder to stop processing or suspend transfers outside Europe
- Claims by individuals: n/aCompensation claims by individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
- Official sourceEuropean CommissionAdequacy decisions — approved destinations, verified 18 August 2026
commission.europa.eu
- Official sourceEUR-LexRegulation (EU) 2018/1807 — member states may not impose localisation on non-personal data except on public-security grounds
eur-lex.europa.eu
National rules2 rules
Fizisko personu datu apstrādes likums
Act of parliament · Adopted by the Saeima 21 June 2018, published Latvijas Vēstnesis 4 July 2018
Latvia's national privacy act. It sets up the State Data Inspectorate, lowers the age at which a child can consent online to 13, caps audit-trail retention at one year, and creates an official register of qualified data protection specialists. It adds no separate national restriction on sending personal data abroad.
Enforced by State Data Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 13Section 33. Latvia chose the lowest age the European regulation allows.
- Delete data after a period — 1 yearSection 37(2). Where an audit-trail retention duty applies, the trail may be kept no longer than one year after the entry, unless other law or the nature of the processing says otherwise.
- Keep logs — 1 year
- Appoint a data protection officerSections 17-18. A controller may appoint someone from the Inspectorate's official list of qualified data protection specialists, or any other qualified person. Using the list is optional.
- Tell people what you do
What it costs if you get it wrong
- Fixed maximum fine: 200 fine units (€1,000) — about $1 thousandSection 38: unlawful acts with personal data by a public-law legal person, or failure by a controller or processor in a public body — the penalty falls on the official personally
Sources
- Official sourceLikumi.lv, official consolidated legislation of the Republic of LatviaFizisko personu datu apstrādes likums — consolidated text
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lvPersonal Data Processing Law — official English translation
likumi.lv
Link checked 18 August 2026
- Official sourceLikumi.lvAdministratīvās atbildības likums, Section 16(2) — one fine unit is five euros
likumi.lv
“Viena naudas soda vienība ir pieci euro.”
Link checked 18 August 2026
Grāmatvedības likums
Act of parliament · Adopted by the Saeima 10 June 2021, published 28 June 2021
The single hardest storage rule in Latvia, and the one most often missed. Paper accounting documents must be kept inside Latvia. Electronic accounting documents must be kept inside Latvia or another European Union country. Entries in accounting registers must also be made in Latvian. It binds Latvian companies, foreign company branches and permanent establishments alike.
Enforced by State Revenue Service
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryPaper accounting documents must stay in Latvia. Electronic accounting documents must stay in Latvia or another European Union member state. Nothing outside the European Union.
- Keep data for a minimum period — 10 yearsInventory lists, accounting registers and accounting organisation documents: 10 years.
- Keep data for a minimum period — 5 yearsAll other supporting documents: at least 5 years, and as long as needed to trace the transaction.
- Keep data for a minimum period — 75 yearsPayroll supporting documents dated before 1 January 1999: 75 years.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under the Law on Taxes and Duties and the Administrative Liability LawFailure to keep accounting documents as required
Sources
- Official sourceLikumi.lv, official consolidated legislationGrāmatvedības likums, Sections 3, 9, 27 and 28
likumi.lv
“Grāmatvedības dokumenti papīra formā glabājami Latvijas Republikas teritorijā. Grāmatvedības dokumenti elektroniskā formā glabājami Latvijas Republikas vai citas Eiropas Savienības dalībvalsts teritorijā atbilstoši Eiropas Parlamenta un Padomes 2018. gada 14. novembra regulā (ES) Nr. 2018/1807 ... noteiktajām prasībām.”
Link checked 18 August 2026
Industry rules5 rules
Elektronisko sakaru likums
Act of parliament · Adopted by the Saeima 14 July 2022, published Latvijas Vēstnesis No. 144, 28 July 2022; Sections 99-101 · Telecoms
Phone and internet companies operating in Latvia must retain call, connection, location and subscriber-identifying data for 18 months and hand it to investigating and security bodies on request. They may not tell anyone that a request was made. There is no rule saying the data must physically stay in Latvia, but the secrecy and authorised-staff rules make casual offshore access impractical.
Enforced by Public Utilities Commission
Transfer model: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Keep data for a minimum period — 18 monthsTraffic data, location data and subscriber-identifying data generated in providing the service.
- Delete data after a period — 18 monthsSection 99(8): delete after the period, except data already requested by an authority or still needed for billing, claims, debt recovery or interconnection.
- Secure the dataSection 99(3): protect retained data against accidental or unlawful destruction, loss, alteration, unauthorised processing or disclosure.
- Do not hand data to foreign authorities on demandSection 99(6): the operator may not disclose that data was requested or handed over, nor identify the affected end users. Section 99(7): only staff authorised by the operator may process retained data.
What it costs if you get it wrong
- Loss of your licence: Regulatory measures under the Electronic Communications LawNon-compliance with retention and disclosure duties
Sources
- Official sourceLikumi.lv, official consolidated legislationElektronisko sakaru likums, Sections 99, 100 and 101
likumi.lv
“Elektronisko sakaru komersants nodrošina saglabājamo datu glabāšanu 18 mēnešus, kā arī to nodošanu šā panta pirmajā daļā minētajām institūcijām pēc to pieprasījuma.”
Link checked 18 August 2026
Nacionālās kiberdrošības likums
Act of parliament · Adopted by the Saeima 20 June 2024, published Latvijas Vēstnesis No. 128A, 4 July 2024; amended with effect from 18 June 2026
Latvia's implementation of the European network and information security directive. It covers energy, transport, banking, health, water, digital infrastructure, cloud and data centre providers and much of the public sector. Twenty-four hours for an early warning, seventy-two for a first report. Fines reach 10 million euros or 2 percent of turnover.
Enforced by National Cyber Security Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 1 April 2025Self-assessment and notification to the National Cyber Security Centre of essential or important service provider status was due by 1 April 2025; the official list was to be approved by 17 April 2025.
- Report cyber incidents — within 24 hoursEarly warning of a significant cyber incident.
- Report cyber incidents — within 72 hoursInitial report of a significant cyber incident. Trust service providers: 24 hours.
- Secure the dataRisk-based technical and organisational measures under the minimum cyber security requirements regulation.
- Independent auditCompliance audit by an auditor registered with the Digital Security Supervisory Committee.
- Appoint a data protection officer — from 1 October 2025A named cyber security manager had to be notified to the National Cyber Security Centre and the Constitution Protection Bureau by 1 October 2025. The person must be a citizen of a NATO, European Union or European Free Trade Association state.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $11 millionMaterial non-compliance by an essential service provider
- Percentage of global turnover: 2% of last financial year net turnoverEssential service provider with turnover above EUR 500 million
- Fixed maximum fine: €7,000,000 — about $8 millionMaterial non-compliance by an important service provider
- Percentage of global turnover: 1.4% of last financial year net turnoverImportant service provider with turnover above EUR 500 million
Sources
- Official sourceLikumi.lv, official consolidated legislationNacionālās kiberdrošības likums — consolidated text, including Sections 30, 33 and 46 and the transitional provisions
likumi.lv
“Nacionālais kiberdrošības centrs ir tiesīgs par būtisku neatbilstību šajā likumā noteiktajām prasībām piemērot būtisko pakalpojumu sniedzējam soda naudu līdz 10 miljoniem euro.”
Link checked 18 August 2026
- Official sourceAizsardzības ministrija (Ministry of Defence)Kiberdrošība — the National Cyber Security Centre, operating since 1 September 2024
mod.gov.lv
Link checked 18 August 2026
Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"
Directly binding regulation · Ministru kabineta 2025. gada 25. jūnija noteikumi Nr. 397, issued under the National Cyber Security Law; points 94, 101 and 129 · Government
For Latvia's most critical state and infrastructure systems, who supplies you is regulated as tightly as where the data sits. The supplier, its board, its shareholders and its ultimate owner must come from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside NATO, European Union or European Free Trade Association territory.
Enforced by Constitution Protection Bureau
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryPoint 129.2: a compliance auditor must process audit information solely within NATO, European Union and European Free Trade Association territory.
- Written vendor contractPoints 94 and 101: for Class A information systems of critical infrastructure owners, the supplier and the manufacturer must be registered in a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner state, with board, shareholders and beneficial owner from those states.
- Prove the data stays under local controlExemptions exist where the shareholder is a Latvian public person or where a specific permission is obtained.
- Hold a security certificateAudits must be carried out by an auditor registered with the Digital Security Supervisory Committee; cloud and data centre auditors need additional certification.
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $11 millionMaterial non-compliance by an owner of critical information and communication technology infrastructure, imposed by the Constitution Protection Bureau
- Percentage of global turnover: 2% of last financial year net turnoverSame, where turnover exceeds EUR 500 million
Sources
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 397, Minimālās kiberdrošības prasības, points 94, 101, 122-129
likumi.lv
“tā ir reģistrēta NATO, Eiropas Savienības vai EBTA dalībvalstī vai NATO Indijas un Klusā okeāna reģiona sadarbības valstī”
Link checked 18 August 2026
- Official sourceLikumi.lvNacionālās kiberdrošības likums, Sections 7 and 46(3) — Constitution Protection Bureau supervision and penalties
likumi.lv
Link checked 18 August 2026
Kredītiestāžu likums
Act of parliament · Credit Institutions Law, Section 10.1 (outsourcing) and Sections 61-63 (banking secrecy); most recently amended with effect from 9 June 2026 · Banking
A Latvian bank cannot simply move its systems to a new cloud or service provider. Significant outsourcing must be filed with Latvijas Banka, which has thirty working days to say no, and it can say no specifically because the arrangement would get in the way of supervision. Banking secrecy also follows the data into the supplier's hands.
Enforced by Bank of Latvia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyBefore receiving a significant outsourced service the bank must file a reasoned written application with Latvijas Banka. It may proceed only if no prohibition arrives within 30 working days; the clock can be paused once for up to 20 working days.
- Extra vendor secrecy termsA standard processor agreement is not enough. The outsourcing provider is bound by banking secrecy and may not disclose non-disclosable information; requests for that information must be sent to the bank itself, not the supplier.
- Written vendor contractRights and duties must be in a written outsourcing contract meeting Latvijas Banka's rules; the bank must also have an outsourcing policy and procedures.
- Independent auditLatvijas Banka may inspect the supplier at the supplier's own premises, take copies of any documents and interview its staff.
What it costs if you get it wrong
- Order to stop: Prohibition on receiving the planned outsourced serviceWhere the arrangement would restrict Latvijas Banka's ability to perform its statutory functions, or harm customers and depositors
- Loss of your licence: Withdrawal of authorisationSerious or repeated breach of prudential requirements
Sources
- Official sourceLikumi.lv, official consolidated legislationKredītiestāžu likums, Section 10.1(5)-(11) and Sections 61-63
likumi.lv
“Pirms nozīmīga ārpakalpojuma saņemšanas kredītiestāde iesniedz Latvijas Bankai motivētu rakstveida iesniegumu par plānoto ārpakalpojuma saņemšanu.”
Link checked 18 August 2026
- Official sourceLatvijas BankaSupervision — Latvijas Banka's supervisory remit and decisions
bank.lv
Link checked 18 August 2026
Ministru kabineta noteikumi Nr. 265 "Medicīnisko dokumentu lietvedības kārtība"
Directly binding regulation · Cabinet Regulation No. 265 of 4 April 2006, chapter V as amended · Health and social care
No rule was found requiring Latvian health data to stay in Latvia, checked 18 August 2026. What Latvia does impose is long minimum retention — from one year to forty years depending on the document — and a duty to feed medical records into the national health information system, which the state hosts in Latvia.
Enforced by National Health Service
Transfer model: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Keep data for a minimum period — 40 yearsUp to 40 years after the last entry for some record types; other types run 1, 3, 5, 10, 15 or 25 years. Radiology images: 10 years.
- Keep records of processingMedical records are accumulated electronically in the single national health-sector electronic information system, which the state runs in Latvia. Treatment institutions also keep records in their own systems.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine; plus privacy fines under the European regulationFailure to keep or destroy medical records as required
Sources
- Official sourceLikumi.lv, official consolidated legislationMinistru kabineta noteikumi Nr. 265, points 5, 35, 35.1 and 35.2
likumi.lv
“Medicīniskie ieraksti tiek elektroniski uzkrāti vienotajā veselības nozares elektroniskajā informācijas sistēmā.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the 18-month blanket telecoms retention duty in Section 99(4) of the Electronic Communications Law is enforceable in full
The Court of Justice of the European Union has repeatedly held that general and indiscriminate retention of traffic and location data is incompatible with European Union law. We could not find a Latvian Constitutional Court or Supreme Court judgment disapplying or reading down Section 99(4), and the Constitutional Court's case search was unreachable on 18 August 2026. We therefore record the rule as in force, not disapplied, but a reader should treat its practical scope as contested.
That the Cabinet has not yet issued the regulations on data centre security requirements and on where information systems must be placed, promised by Section 30(2) of the National Cyber Security Law
We scanned the official legislation database's publication index for 2025 and 2026 and found no such regulation, and the National Cyber Security Centre's legislation page redirects to a general Ministry of Defence page that does not list it. The index may paginate, so this is an absence of evidence rather than proof of absence. The Cabinet questionnaire annexed to the minimum cyber security requirements regulation refers to such rules, which suggests they are drafted or planned.
The total euro value of fines imposed by the State Data Inspectorate in the first half of 2026
The Inspectorate's July 2026 half-year update gives counts (832 complaints, 36 violations, corrective measures in 9 cases) but no monetary totals. Only the 2025 annual report gives euro figures.
Whether the State Data Inspectorate can impose European-regulation fines on Latvian public authorities, or only pursue the responsible official under the administrative-offence route in Section 38
Section 38 of the Personal Data Processing Law creates an official-facing penalty capped at 200 fine units for public-law legal persons, which reads like use of the Article 83(7) member-state option. We found no official statement from the Inspectorate confirming that reading, so it is inference from statutory text.
Whether privacy notices aimed at Latvian consumers must be provided in Latvian
The Official Language Law requires private companies to use Latvian in records and documents where their activity touches legitimate public interests, expressly including consumer rights protection. That plainly covers consumer-facing information, but we found no Inspectorate guidance applying it specifically to privacy notices, so the point is inferred rather than confirmed.
The current text of Latvijas Banka's own outsourcing regulations for credit institutions
The Credit Institutions Law repeatedly delegates the detailed content of outsourcing policies and contracts to Latvijas Banka's rules. We verified the statutory framework but did not retrieve the regulator's implementing regulations, so the detail of what must be in an outsourcing contract is unverified.
That no localisation rule exists in Latvia for insurance, securities, payments, education, gaming, defence procurement or mapping data
We read the Geospatial Information Law and the State Information Systems Law in full and found nothing, and confirmed that financial services sit with Latvijas Banka under European rules that impose no localisation. We cannot prove a negative across every Cabinet regulation, so this is 'no rule found, checked 18 August 2026' rather than 'there is no rule'.
Who currently holds the post of Director of the State Data Inspectorate and when the five-year term expires
The Inspectorate's 'About us' page describes the appointment mechanism but the name and term dates were not retrievable from the pages we fetched.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Latvia versus Argentina
- Latvia versus Armenia
- Latvia versus Australia
- Latvia versus Austria
- Latvia versus Azerbaijan
- Latvia versus Brazil
- Latvia versus Bulgaria
- Latvia versus Cambodia
- Latvia versus Canada
- Latvia versus China
- Latvia versus Croatia
- Latvia versus Cyprus
- Latvia versus Estonia
- Latvia versus France
- Latvia versus Georgia
- Latvia versus Germany
- Latvia versus Greece
- Latvia versus Hong Kong SAR
- Latvia versus Hungary
- Latvia versus Iceland
- Latvia versus India
- Latvia versus Indonesia
- Latvia versus Ireland
- Latvia versus Israel
- Latvia versus Italy
- Latvia versus Japan
- Latvia versus Lithuania
- Latvia versus Luxembourg
- Latvia versus Malta
- Latvia versus Mexico
- Latvia versus Mongolia
- Latvia versus Nepal
- Latvia versus Netherlands
- Latvia versus Poland
- Latvia versus Russia
- Latvia versus Saudi Arabia
- Latvia versus Serbia
- Latvia versus Singapore
- Latvia versus Slovakia
- Latvia versus Slovenia
- Latvia versus South Korea
- Latvia versus Spain
- Latvia versus Sri Lanka
- Latvia versus Sweden
- Latvia versus Switzerland
- Latvia versus Taiwan
- Latvia versus Thailand
- Latvia versus Turkey
- Latvia versus Ukraine
- Latvia versus United Arab Emirates
- Latvia versus United Kingdom
- Latvia versus United States
- Latvia versus Uzbekistan