Data protection
29 items across all issues
CJEU: publishing the personal data of all shareholders is contrary to the GDPRcobalt.legal·4 September 2026·LVCourt ruling·Data protection·Commercial law↗
On 3 September 2026 the Court of Justice of the European Union, in case C-798/24 (Jautiva), initiated following an application by 17 minority shareholders of a joint-stock company to the Constitutional Court, ruled that EU law does not require public access to shareholder register information and that the GDPR precludes rules providing for the disclosure to anyone of the personal data of all shareholders (identity, contact details, number of shares, voting rights). The Court noted that the objectives of business transparency, AML/CTF and sanctions do not justify general public access, since the data can be stored and disseminated. The Constitutional Court will now assess whether Latvia's rules on disclosure of shareholder data comply with the Constitution; amendments to the Commercial Law and the Enterprise Register rules are expected. The clients were represented by COBALT (L. Liepa, G. Šantare, M. Aktumane).
#DVIskaidro: Do you have to wait for a DVI decision to receive compensation?dvi.gov.lv·4 September 2026·LV·Case law↗
The Data State Inspectorate (DVI) explains that a person wishing to claim compensation in court for damage caused by a personal data protection breach under Article 82 of the GDPR does not first need to obtain a decision from the supervisory authority – the authority's investigation and the question of compensation are two separate matters. Referring to CJEU case law, the DVI notes that the purpose of compensation is to make good the damage actually suffered, not to punish the controller: a breach alone does not give rise to a right to compensation, damage and a causal link must be proven, and the amount also depends on the sensitivity of the data.
Ombudsman: don't wait for the next data security incident – act preventively nowlvportals.lv·4 September 2026·LV↗
Following data security incidents at AS "Latvijas valsts meži" and VAS "Road Traffic Safety Directorate" (CSDD), Ombudsman Karina Palkova urges state and municipal institutions to assess the security of their information systems preventively. Under the General Data Protection Regulation, institutions must check whether excessive data are being collected, whether unnecessary data are deleted in good time and whether stored data are adequately protected, with particular attention to systems holding health and children's data. Regular security audits, review of access management and incident detection mechanisms are recommended, in cooperation with the Data State Inspectorate, the National Cybersecurity Centre and CERT.LV.
Business tourism and new requirements for short-term accommodationifinanses.lv·4 September 2026·LV·Real estate·Data protection↗
An iBizness article (Artūrs Freibergs) on the amendments to the Tourism Law that entered into force on 10 July 2026 and implement EU Regulation 2024/1028 on data collection in short-term accommodation rental services. The law introduces the term "business tourism" and new requirements for short-term accommodation landlords (on Airbnb, Booking and other platforms) to provide data, and simplifies the granting of resort status to municipalities. The article is paywalled.
EU law does not require disclosure of information on all shareholders of a joint-stock company, including minority shareholderslvportals.lv·3 September 2026·LVCourt ruling·Commercial law·Data protection↗
The Court of Justice of the European Union, answering questions from the Constitutional Court in a case initiated by 17 minority shareholders of various joint-stock companies, held that Directive 2017/1132 does not require the disclosure of information on all shareholders of a joint-stock company. Latvia's rules, which provide for unrestricted online publication of shareholders' names, personal identity numbers, addresses, e-mails, number of shares and voting rights, constitute a serious interference with fundamental rights and are incompatible with the General Data Protection Regulation if access is not subject to conditions (such as demonstrating a legitimate interest). The Court pointed to less restrictive alternatives – access based on a legitimate interest, or publication only in respect of sanctioned persons.
Latvia's rules insufficiently protect shareholder data, the Court of Justice of the EU findstvnet.lv·3 September 2026·LVCourt ruling·Commercial law·Data protection↗
In a preliminary ruling on questions referred by the Constitutional Court, the Court of Justice of the European Union held that EU law does not require the disclosure of information on all shareholders of a joint-stock company, including minority shareholders, and that Latvia's rules – Section 4.15(2)(b) of the Law on the Enterprise Register of the Republic of Latvia, which provides for publication of shareholder data in the public part of the register – do not provide sufficient safeguards against misuse, since the data are available for bulk download by unidentified users. The Court pointed to less restrictive solutions, such as access after verification of a legitimate interest. The Constitutional Court must now rule on the provision's compliance with the Constitution.
Shareholder data need not be published onlineifinanses.lv·3 September 2026·LVCourt ruling·Commercial law·Data protection↗
The Court of Justice of the European Union held that EU law does not require shareholders' personal data to be published online, and that Latvia's requirement to publish shareholders' names, personal identity numbers, addresses and shareholding data in a freely accessible and downloadable form violates the rights to privacy and data protection guaranteed by the Charter of Fundamental Rights. The measure is neither appropriate nor necessary for the objective of an open business environment, and Latvia lacks sufficient safeguards against misuse of the data.
PTAC reports a possible security incident in a PTAC information systemlvportals.lv·3 September 2026·LV·Financial services↗
The Consumer Rights Protection Centre (PTAC) reports a possible security incident in the Remote Statistical Data Collection System (ASDIS, a class C system). The contact details (name, e-mail, telephone) of 697 company representatives and 34 PTAC officials were affected – mainly contacts of licensed consumer lenders, debt collection service providers and package travel service providers, most of which are already available in public registers. Supervisory data submitted by companies were not affected; the system has been shut down and users have been informed.
Why does the court send a notice on a day off?tiesas.lv·2 September 2026·LV·Civil procedure·Data protection↗
The courts portal explains that since 1 July 2026, in cases under the warning procedure for compulsory enforcement of obligations (SPIBK), court notices are generated and sent automatically, so they may arrive in the official e-address on Saturdays, Sundays and public holidays. If the debtor submits a reply via the e-case portal, the court ruling may be prepared and sent the same day; if no reply is received within 50 days, the system automatically generates a ruling, even if the deadline falls on a day off. The court urges people not to ignore notices received on days off and to check them on the Latvija.gov.lv portal.
Amendments to the Credit Information Bureaus Lawlikumi.lv·1 September 2026·LV·Legislation·Data protection↗
On 1 September the Official Gazette (Latvijas Vēstnesis) published the amendments to the Credit Information Bureaus Law adopted by the Saeima on 20 August, which enter into force on 15 September; the new paragraphs of Section 12 enter into force on 20 November 2026. Natural persons' rights are strengthened to obtain credit information about themselves and to monitor assessments of their creditworthiness, as well as to register in the bureau's system a note declining credit offers, visible to all bureau users (creditors); the bureau must delete a withdrawn note within three days.
Resilience is not built during a crisis – a crisis shows how far-sightedly resilience was builttegos.legal·1 September 2026·LV·Analysis & opinion·Contracts & trade↗
Kristīne Puķēna, senior lawyer at TEGOS, analyses companies' digital and organisational resilience in the context of the requirements of the National Cybersecurity Law, NIS2, DORA and the GDPR. The article stresses that the most common problems are unclear processes and undefined responsibility, so risk management, information protection and incident reporting procedures should be reviewed in calm times. In practical terms, it recommends putting contracts with service providers and subcontractors in order – roles, responsibility, service level (SLA) terms and incident response deadlines.
Publication of athletes' data where anti-doping rules have been breachedifinanses.lv·1 September 2026·LV·Case law↗
Lawyer Aleksandra Baranova (law firm Kronbergs Čukste Levin) analyses the CJEU judgment of 14 July 2026 in case C-474/24 on the Austrian anti-doping organisation's practice of publishing athletes' names, violations and the length of their bans. Four athletes challenged the publication as disproportionate processing of special categories of personal data; the article assesses the circumstances in which such publication is permissible under data protection law. The article is paywalled.
How private is the content of a work e-mail?ifinanses.lv·31 August 2026·LV·Employment law·Case law↗
Sworn attorney Annija Švemberga-Streikiša (AmberLaw) analyses the CJEU judgment of 16 July 2026 in joined cases C-258/23–C-260/23 on competition authorities' access to employees' e-mails. The Court held that work e-mail is correspondence protected by the EU Charter of Fundamental Rights, and an internal ban on private use of e-mail does not remove that protection; any access is an interference with fundamental rights that must have a legal basis. The article is paywalled.
Stricter oversight of ChatGPT, Reddit and Robloxifinanses.lv·31 August 2026·LV↗
Under the Digital Services Act, the European Commission has designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms (each with over 45 million monthly users in the EU). By December 2026 they must meet additional requirements – assess and mitigate systemic risks (illegal content, child safety, fundamental rights, elections); the Commission gains supervisory powers in cooperation with the Irish and Dutch regulators.
#DVIskaidro: The right of access. Why must you first contact the controller?dvi.gov.lv·31 August 2026·LV↗
The Data State Inspectorate (DVI) explains the data subject's right of access (Article 15 of the GDPR): the person must first contact the controller, which within one month (Article 12(3) of the GDPR, extendable by two months in complex cases) must provide specific, understandable information on the purposes of processing, the categories of data, the recipients, the retention periods and the source of the data. The DVI intervenes only if the controller fails to reply within a month, refuses or gives an incomplete reply, or the processing is manifestly unlawful.
DVI is already assessing the CSDD data leak; individual complaints are not necessarydvi.gov.lv·31 August 2026·LV↗
The Data State Inspectorate (DVI) informs that, in connection with the CSDD personal data leak, an investigation has already been launched and information has been requested from CSDD, so affected persons do not need to file individual complaints. The investigation will assess the circumstances of the leak and the conduct of CSDD as controller; any decision will be addressed to CSDD. The DVI reminds that it does not decide on compensation – such disputes are to be resolved in court.
Justice Minister: cybersecurity is management's responsibility, not just an IT tasktm.gov.lv·28 August 2026·LV·Judiciary↗
Justice Minister Edvards Smiltēns convened a meeting with state agencies and cybersecurity experts on rising cyber threats in the justice sector. He stressed that under the National Cybersecurity Law, managing risk and ensuring resilience of critical services is the responsibility of an organisation's leadership, not just IT staff. The Ministry committed to strengthening inter-agency cooperation and treating security audits as an ongoing process rather than a one-off exercise.
Excessive disclosure of health data to insurers is not permissibletiesibsargs.lv·26 August 2026·LV·Financial services↗
Latvia's Ombudsman states that insurers may not demand, and medical practitioners may not provide, a patient's complete medical history for evaluating an insurance claim. Only information directly relevant to the specific insured event may be shared, in line with the data-minimisation principle. The opinion addresses insurers' practices when handling clients' health data.
Baltic states strengthen cooperation for a safer, faster justice systemtm.gov.lv·25 August 2026·LV·Data protection↗
Justice ministers of Latvia, Lithuania and Estonia met in Tallinn to discuss court-system digitalisation, data exchange between institutions and the use of AI in judicial processes, stressing that decisions remain with judges. They backed expanding the European Public Prosecutor's Office to cover serious EU sanctions breaches. The states agreed to continue coordinating on cross-border crime.
DVI explains how controllers must notify people of a personal data breachdvi.gov.lv·24 August 2026·LV·Commercial law↗
Latvia's Data State Inspectorate explains how data controllers must notify individuals of a personal data breach, citing the summer CSDD security incident that affected roughly 1.2 million people's data as an example. It states that for mass incidents public notification (website, media) can replace individual letters if individual contact would be disproportionately burdensome, and notices must describe affected data, risks and recommended action.
CSDD cyberattack exploited an application the agency managed itselftvnet.lv·21 August 2026·LV·Judiciary↗
It emerged the CSDD cyberattack exploited an application the agency managed itself, outside telecom operator Tet's security contract. The Economy Minister said Tet covered only network infrastructure, and a transition period had let systems run without mandatory safeguards. Both sides acknowledged the need for closer cybersecurity coordination.
Latvia wants to legalise ethical hackers' access to information systemsbnn-news.com·20 August 2026·EN·Legislation↗
Latvia's Ministry of Defence has drafted amendments to the National Cyber Security Law creating a legal framework for security researchers to access information systems to identify vulnerabilities, without unduly burdening systems or compromising security. The rules would cover essential and important service providers and critical infrastructure operators. The proposal follows a 2026 court case in which inventor Raimonds Skuruls was fined EUR 4,290 for reporting a vulnerability to CSDD; public consultation runs through the end of August.
PTAC urges consumers to use AI tools wiselyptac.gov.lv·20 August 2026·LV·Financial services↗
PTAC reports a growing number of complaints drafted with AI tools that contain legally unfounded or mistaken arguments. The agency stresses that AI is not a legal adviser and bears no responsibility for the information it provides, urging consumers to verify AI suggestions against official sources, especially regarding deadlines and financial obligations.
Latvians increasingly send AI-written complaints: PTAC explains the catchbb.lv·20 August 2026·RU·Data protection↗
The Consumer Rights Protection Centre (PTAC) warns that more Latvians are submitting AI-drafted complaints that often contain serious errors. PTAC says AI can produce convincing text but lacks legal expertise — citing outdated legislation, wrong deadlines, and legally defective claims against businesses or in court. The agency recommends treating AI only as a supplementary tool and avoiding entering sensitive data without understanding how it is processed.
Experts: the CSDD data leak is an extremely serious national security threatnra.lv·20 August 2026·LV·Data protection↗
A commentary on the CSDD leak warns the stolen data could fuel targeted fraud — fake SMS, calls and ads impersonating authorities leading to phishing pages. The author advises never approving unsolicited Smart-ID requests and verifying communications only via official channels; fraudulent emails already circulating in CSDD's name are cited.
DVI explains: what happens after a personal data breachdvi.gov.lv·19 August 2026·LV·Civil procedure↗
DVI explains how it handles a personal-data-breach notification: it assesses the circumstances of the violation and the security measures the organisation had in place, not just the fact that an incident occurred. The authority stresses that DVI itself does not award compensation to affected individuals — claims for damages must be pursued in civil court with evidence of the harm suffered.
Video surveillance of an employee: when it's legal, when it's notpress.lv·19 August 2026·RU·Data protection↗
The article explains that employee video surveillance is lawful for an employer only when it serves a specific purpose — such as meeting legal obligations, gathering evidence for disputes, or monitoring work quality — has a proper legal basis, and employees are honestly informed about the monitoring and their rights. Surveillance is unlawful if cameras target private areas or shift from monitoring situations to tracking an individual employee. The framework rests on Article 96 of the Constitution, the GDPR, and the Law on Personal Data Processing.
"We're trying to cover our tracks": PM slams CSDD over massive data leaktvnet.lv·18 August 2026·LV·Judiciary↗
A cyberattack on CSDD exposed 18 years of payment data for 1.2 million residents and ~200,000 businesses. The PM sharply criticized CSDD for failing mandatory cybersecurity requirements, including missing two-factor authentication; the Data State Inspectorate must assess consequences by August 31. Possible foreign involvement is being investigated.
President: CSDD leadership cannot continue after massive data leakdiena.lv·18 August 2026·LV·Judiciary↗
The President said that after the massive CSDD data breach affecting 1.2 million residents and ~200,000 businesses, the agency's leadership should not remain in office given the loss of public trust. He called the attack a serious national-security threat; State Police opened a criminal investigation.
Nothing found.