Law / Latvia

Latvia

privacy

Latvia's private-sector regime is the General Data Protection Regulation (GDPR) plus the Personal Data Processing Law (Fizisko personu datu apstrades likums, Latvijas Vestnesis No. 132/2018), which establishes the Data State Inspectorate (DVI) as supervisory authority and supplies the national institutional and procedural layer GDPR leaves to member states.

Article 25(2) of the Law, read directly, restates GDPR Article 9's special-category list including biometric data, with no illustrative example list and no Latvia-specific narrowing or widening of the biometric category. As at 2026-08-24; later amendment is not independently confirmed.

13 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Latvia

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-07-05 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the Data State Inspectorate (DVI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Latvia-specific derogation to this timeline was found.

What it asks of an app

Comprehensive regime

Personal Data Processing Law (Fizisko personu datu apstrades likums)

cite Fizisko personu datu apstrades likums, Latvijas Vestnesis No. 132 (2018), in force 5 July 2018 stage In effect since 2018-07-05 source Latvijas Vestnesis official text, No. 132 (2018)

Latvia's national supplement to the directly applicable General Data Protection Regulation (GDPR), establishing the Data State Inspectorate (DVI) as supervisory authority with GDPR Article 57-58 powers, national procedure for decisions, disputes and appeals, and data protection officer regulation. It does not restate GDPR's substantive lawful basis, rights, or transfer rules, which apply directly.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Latvia

cite Regulation (EU) 2016/679, Arts. 44-50 stage In effect since 2018-07-05 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Latvia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Latvia-specific transfer restriction beyond Chapter V was found.

What it asks of an app

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Latvia

cite Regulation (EU) 2016/679, Arts. 15-22 stage In effect since 2018-07-05 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Latvia: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller, generally within one month. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect.

The Personal Data Processing Law's national role is institutional (the Data State Inspectorate's powers and complaint procedure) rather than a rewrite of the rights chapter; no Latvia-specific derogation narrowing these rights was found.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and DVI Enforcement in Latvia

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-07-05 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

The Data State Inspectorate (DVI) holds the General Data Protection Regulation (GDPR) Article 57-58 toolkit, investigative powers, corrective powers, and administrative fine authority up to the Article 83 tiers. DVI has issued fines under this authority, including a reported EUR 1.2 million penalty against a service provider. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

Sensitive categories

Personal Data Processing Law Article 25(2), Special Categories in Latvia

cite Fizisko personu datu apstrades likums, Art. 25(2); Regulation (EU) 2016/679, Art. 9 stage In effect since 2018-07-05 source likumi.lv, Fizisko personu datu apstrades likums, Art. 25(2), fetched and read directly

Article 25(2) of the Personal Data Processing Law, read directly at likumi.lv, restates General Data Protection Regulation (GDPR) Article 9's special-category list and its own biometric-data term mirroring GDPR Article 4(14)'s definition (processing necessary for unique identification). It carries no illustrative list, enumeration, or named example distinguishing facial recognition from voice data or any other biometric modality.

No Latvia-specific narrowing or widening of the biometric category beyond the GDPR baseline was found in this provision.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.