Skip to the content
Global Data RulesData governance rules, country by country

Latvia

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.

Eight questions about Latvia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Latvia's rules apply to my company?

Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Latvia?

Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.

High confidenceDepends on your industryBlocklistOfficial 'this country is safe' decisionStandard contract clauses

What do I need in place before data leaves Latvia?

For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consent

Who enforces the rules in Latvia, and what can they do?

The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.

High confidenceActive

How long do I have to keep the data?

Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Latvia?

Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.

High confidenceGet a parent's consent for childrenCriminal liabilityKeep the data in the countryKeep logsAppoint a data protection officer

What is changing soon in Latvia?

Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.

Medium confidenceIn forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

Vispārīgā datu aizsardzības regula (Regulation (EU) 2016/679)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European Union privacy regulation is the base layer in Latvia and applies directly. It does not require data to stay in Europe; it sets conditions for letting it leave. Fines reach 20 million euros or 4 percent of worldwide group turnover, whichever is higher, and an order to stop processing usually hurts more.

In force since 25 May 2018

Enforced by State Data Inspectorate

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

National rules2 rules

Fizisko personu datu apstrādes likums

Act of parliament · Adopted by the Saeima 21 June 2018, published Latvijas Vēstnesis 4 July 2018

In forceYes, with paperwork

Latvia's national privacy act. It sets up the State Data Inspectorate, lowers the age at which a child can consent online to 13, caps audit-trail retention at one year, and creates an official register of qualified data protection specialists. It adds no separate national restriction on sending personal data abroad.

In force since 5 July 2018

Enforced by State Data Inspectorate

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Grāmatvedības likums

Act of parliament · Adopted by the Saeima 10 June 2021, published 28 June 2021

In forceNo — it stays put

The single hardest storage rule in Latvia, and the one most often missed. Paper accounting documents must be kept inside Latvia. Electronic accounting documents must be kept inside Latvia or another European Union country. Entries in accounting registers must also be made in Latvian. It binds Latvian companies, foreign company branches and permanent establishments alike.

In force since 1 January 2022

Enforced by State Revenue Service

Transfer model: Not allowed

High confidence

Industry rules5 rules

Elektronisko sakaru likums

Act of parliament · Adopted by the Saeima 14 July 2022, published Latvijas Vēstnesis No. 144, 28 July 2022; Sections 99-101 · Telecoms

In forceYes, with paperwork

Phone and internet companies operating in Latvia must retain call, connection, location and subscriber-identifying data for 18 months and hand it to investigating and security bodies on request. They may not tell anyone that a request was made. There is no rule saying the data must physically stay in Latvia, but the secrecy and authorised-staff rules make casual offshore access impractical.

In force since 29 July 2022

Enforced by Public Utilities Commission

Transfer model: No restriction · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

High confidence

Nacionālās kiberdrošības likums

Act of parliament · Adopted by the Saeima 20 June 2024, published Latvijas Vēstnesis No. 128A, 4 July 2024; amended with effect from 18 June 2026

In forceYes, with paperwork

Latvia's implementation of the European network and information security directive. It covers energy, transport, banking, health, water, digital infrastructure, cloud and data centre providers and much of the public sector. Twenty-four hours for an early warning, seventy-two for a first report. Fines reach 10 million euros or 2 percent of turnover.

In force since 1 September 2024But only enforceable from 1 April 2025

Enforced by National Cyber Security Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"

Directly binding regulation · Ministru kabineta 2025. gada 25. jūnija noteikumi Nr. 397, issued under the National Cyber Security Law; points 94, 101 and 129 · Government

In forceNo — it stays put

For Latvia's most critical state and infrastructure systems, who supplies you is regulated as tightly as where the data sits. The supplier, its board, its shareholders and its ultimate owner must come from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside NATO, European Union or European Free Trade Association territory.

In force since 2 July 2025

Enforced by Constitution Protection Bureau

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Datu valsts inspekcija

    General privacy law, data protection specialist register, breach notifications

    Fully operational. Created 1 January 2001; a direct administration institution under Cabinet supervision, independent in its work, director appointed for five years. 2025: 1,034 complaints, 1,396 checks, corrective measures in 62 cases, fines totalling EUR 326,400 with a maximum of EUR 300,000, average staff 32. First half of 2026: 832 complaints, 36 violations found, 73 own-initiative checks. Publishes far more guidance than penalties, so best read as active rather than aggressive.

  • Nacionālais kiberdrošības centrs

    Cyber security supervision of essential and important service providers; incident reporting; data centre requirements

    Started operating 1 September 2024 under the Ministry of Defence, working with CERT.LV at the University of Latvia's Institute of Mathematics and Computer Science. Amendments in force 18 June 2026 moved designation decisions to the Centre from the Digital Security Supervisory Committee. Can impose penalties up to EUR 10 million or 2 percent of turnover.

  • Satversmes aizsardzības birojs

    Supervision of owners of critical information and communication technology infrastructure; security vetting of cyber security managers

    Named in the National Cyber Security Law with its own supervisory and penalty powers of up to EUR 10 million or 2 percent of turnover. Operates as an intelligence service, so its individual decisions are not published.

  • Latvijas Banka

    Banks, insurers, investment firms, payment and electronic money institutions, crypto-asset service providers

    Single financial regulator after absorbing the Financial and Capital Market Commission. Issues licensing and supervisory decisions; holds a veto over significant bank outsourcing.

  • Sabiedrisko pakalpojumu regulēšanas komisija

    Electronic communications sector regulation

  • Valsts ieņēmumu dienests

    Tax and accounting records, including where accounting documents are stored

  • Nacionālais veselības dienests

    National health information system and medical records

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the 18-month blanket telecoms retention duty in Section 99(4) of the Electronic Communications Law is enforceable in full

    The Court of Justice of the European Union has repeatedly held that general and indiscriminate retention of traffic and location data is incompatible with European Union law. We could not find a Latvian Constitutional Court or Supreme Court judgment disapplying or reading down Section 99(4), and the Constitutional Court's case search was unreachable on 18 August 2026. We therefore record the rule as in force, not disapplied, but a reader should treat its practical scope as contested.

  • That the Cabinet has not yet issued the regulations on data centre security requirements and on where information systems must be placed, promised by Section 30(2) of the National Cyber Security Law

    We scanned the official legislation database's publication index for 2025 and 2026 and found no such regulation, and the National Cyber Security Centre's legislation page redirects to a general Ministry of Defence page that does not list it. The index may paginate, so this is an absence of evidence rather than proof of absence. The Cabinet questionnaire annexed to the minimum cyber security requirements regulation refers to such rules, which suggests they are drafted or planned.

  • The total euro value of fines imposed by the State Data Inspectorate in the first half of 2026

    The Inspectorate's July 2026 half-year update gives counts (832 complaints, 36 violations, corrective measures in 9 cases) but no monetary totals. Only the 2025 annual report gives euro figures.

  • Whether the State Data Inspectorate can impose European-regulation fines on Latvian public authorities, or only pursue the responsible official under the administrative-offence route in Section 38

    Section 38 of the Personal Data Processing Law creates an official-facing penalty capped at 200 fine units for public-law legal persons, which reads like use of the Article 83(7) member-state option. We found no official statement from the Inspectorate confirming that reading, so it is inference from statutory text.

  • Whether privacy notices aimed at Latvian consumers must be provided in Latvian

    The Official Language Law requires private companies to use Latvian in records and documents where their activity touches legitimate public interests, expressly including consumer rights protection. That plainly covers consumer-facing information, but we found no Inspectorate guidance applying it specifically to privacy notices, so the point is inferred rather than confirmed.

  • The current text of Latvijas Banka's own outsourcing regulations for credit institutions

    The Credit Institutions Law repeatedly delegates the detailed content of outsourcing policies and contracts to Latvijas Banka's rules. We verified the statutory framework but did not retrieve the regulator's implementing regulations, so the detail of what must be in an outsourcing contract is unverified.

  • That no localisation rule exists in Latvia for insurance, securities, payments, education, gaming, defence procurement or mapping data

    We read the Geospatial Information Law and the State Information Systems Law in full and found nothing, and confirmed that financial services sit with Latvijas Banka under European rules that impose no localisation. We cannot prove a negative across every Cabinet regulation, so this is 'no rule found, checked 18 August 2026' rather than 'there is no rule'.

  • Who currently holds the post of Director of the State Data Inspectorate and when the five-year term expires

    The Inspectorate's 'About us' page describes the appointment mechanism but the name and term dates were not retrievable from the pages we fetched.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.