Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-07-05
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the Data State Inspectorate (DVI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Latvia-specific derogation to this timeline was found.
What it asks of an app →
Comprehensive regime
cite Fizisko personu datu apstrades likums, Latvijas Vestnesis No. 132 (2018), in force 5 July 2018
stage In effect
since 2018-07-05
source Latvijas Vestnesis official text, No. 132 (2018)
Latvia's national supplement to the directly applicable General Data Protection Regulation (GDPR), establishing the Data State Inspectorate (DVI) as supervisory authority with GDPR Article 57-58 powers, national procedure for decisions, disputes and appeals, and data protection officer regulation. It does not restate GDPR's substantive lawful basis, rights, or transfer rules, which apply directly.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-50
stage In effect
since 2018-07-05
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Latvia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Latvia-specific transfer restriction beyond Chapter V was found.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 15-22
stage In effect
since 2018-07-05
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Latvia: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller, generally within one month. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect.
The Personal Data Processing Law's national role is institutional (the Data State Inspectorate's powers and complaint procedure) rather than a rewrite of the rights chapter; no Latvia-specific derogation narrowing these rights was found.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-07-05
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The Data State Inspectorate (DVI) holds the General Data Protection Regulation (GDPR) Article 57-58 toolkit, investigative powers, corrective powers, and administrative fine authority up to the Article 83 tiers. DVI has issued fines under this authority, including a reported EUR 1.2 million penalty against a service provider. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →
Sensitive categories
cite Fizisko personu datu apstrades likums, Art. 25(2); Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-07-05
source likumi.lv, Fizisko personu datu apstrades likums, Art. 25(2), fetched and read directly
Article 25(2) of the Personal Data Processing Law, read directly at likumi.lv, restates General Data Protection Regulation (GDPR) Article 9's special-category list and its own biometric-data term mirroring GDPR Article 4(14)'s definition (processing necessary for unique identification). It carries no illustrative list, enumeration, or named example distinguishing facial recognition from voice data or any other biometric modality.
No Latvia-specific narrowing or widening of the biometric category beyond the GDPR baseline was found in this provision.
What it asks of an app →