What Is Personal Data Processing Law (Fizisko personu datu apstrādes likums)?
Latvia’s Personal Data Processing Law was adopted on 21 June 2018 and entered into force on 5 July 2018. The consolidated version is marked currently in force and effective from 4 June 2021, reflecting a 2019 transitional amendment and 2021 amendments concerning DVI administrative-decision deadlines and administrative-offence terminology. GDPR applies directly, while the PDL supplies national institutional, procedural, and purpose-specific rules. The law contains unusually concrete complaint-proceeding periods: a formal administrative proceeding is generally six months, extendable to one year for objective reasons and, by reasoned decision, to two years where lengthy fact-finding and the GDPR consistency mechanism are required. A distinctive public-record-adjacent rule concerns official-publication processing: Articles 16-21 are generally disapplied, but DVI or the controller may still order or decide erasure by reasoned decision where statutory conditions are met and privacy is balanced against the public interest in preserving the publication. No express Latvia-specific data-broker complaint, deletion, or suppression route was located. The page should not imply a universal route to remove Latvian public records or a dedicated broker deletion entitlement.
At a glance
- Full name
- Personal Data Processing Law (Fizisko personu datu apstrādes likums)
- Short code
- PDL
- Jurisdiction
- Latvia
- Enacted
- 2018
- Last major update
- Consolidated version effective 4 June 2021, reflecting amendments adopted 23 May 2019 and 6 May 2021
- Regulator
- Data State Inspectorate (DVI)
- Private right of action
- Limited
- Statutory citation
- Personal Data Processing Law (Fizisko personu datu apstrādes likums)
Scope, who PDL covers
Protected data
Data subject rights
GDPR rights to transparency and information, subject to specified Article 23 and expression-related restrictions
Right of access, with recipient information generally requestable for the prior 2 years, subject to national-security, public-safety, criminal-law, tax, anti-money-laundering, and financial-supervision limits
Right to rectification, subject to official-publication and purpose-specific exceptions
Right to erasure, subject to official-publication rules and reasoned DVI or controller decisions where statutory conditions are met
Right to restriction of processing
Right to data portability, with no separate statistical, archival, or research-specific derogation located
Right to object, subject to official-publication, statistics, archiving, research, and expression exceptions
Right to complain to DVI and seek judicial remedy
Right to use the 13-year information-society-service consent threshold, with parental or guardian consent required below that age
Notable features
Latvia combines GDPR rights with detailed Sections 26-37 covering restrictions and purpose-specific exceptions. Section 28’s official-publication rule is especially distinctive: Articles 16-21 are generally disapplied, yet DVI or the controller may decide erasure by reasoned decision after balancing privacy against the public interest in preserving the publication. The law also uses a 13-year consent threshold and a multi-tier 6-month, 1-year, and 2-year administrative timeline.
Enforcement & penalties
Regulator: Data State Inspectorate (DVI)
Penalties: GDPR Article 83 provides the baseline, including fines of up to €10 million or 2% of worldwide turnover for the lower tier and up to €20 million or 4% for the upper tier, including violations of Articles 12-22. The PDL also contains a narrow national offence provision for unlawful personal-data activity by a public-law legal person, or failure of a controller or processor obligation within such an entity: an official may receive a warning or a fine of up to 200 fine units. This is not a general fine schedule for all controllers and processors.
Private right of action: The GDPR Article 78(2) judicial-remedy trigger applies when DVI has not acted or provided information within 3 months, together with formal administrative proceedings under Section 23¹; no separate Latvia-specific general private damages route was identified.
Relevance to data brokers
No express Latvia-specific data-broker complaint, deletion, or suppression route was located. DVI directs individuals to contact the relevant database or information-system keeper first and then submit a DVI complaint with supporting evidence; this is a general GDPR route, not a broker-specific process. Official-publication erasure is a limited public-record-adjacent mechanism and should not be generalized to all Latvian public registers or records.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Latvia have a dedicated data-broker deletion route?+
Not located. DVI’s identified route is to contact the relevant database or information-system keeper first and then complain to DVI with supporting evidence.
Can official Latvian publications ever be erased?+
Sometimes, under a narrow mechanism. For official-publication processing, Articles 16-21 are generally disapplied, but DVI or the controller may order or decide erasure by reasoned decision where the publication violates GDPR, balancing privacy against the public interest in preservation.
How long can a Latvian formal administrative proceeding take?+
The formal proceeding is generally six months, extendable to one year for objective reasons and, by reasoned decision, up to two years where lengthy fact-finding and the GDPR consistency mechanism are required.
Official sources & citations
Other international privacy regimes
PDL sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
