How to inform individuals in case of personal data breaches according to the Latvian authority

The National Data Inspectorate of Latvia (DVI) has published guidelines on how to inform data subjects in the event of a large-scale data breach, based on a recent cyber incident.

Following a cyber incident affecting the Road Traffic Safety Directorate (CSDD) and impacting approximately 1,200,000 individuals, the authority reminded that when individual notification is disproportionate, the GDPR allows for public communication. Publishing a notice on a website, social media, or through the media can be an appropriate solution. This communication must enable individuals to determine if they are affected, understand the nature of the compromised data, the risks involved, and the measures to take to protect themselves. The data controller must clearly distinguish confirmed facts from mere probabilities and provide practical advice, such as vigilance against fraud attempts.

Regarding the incident announced on August 18, 2026, where third parties accessed data from former payment receipts of the CSDD, the Inspectorate reviewed the information disseminated by the organization. It concluded that the CSDD had fulfilled its obligation to inform the data subjects of the breach of their personal data.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire