Skip to content

Evidence request lists

Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Children Consent Age 13 + S.16

LV-PDPL-Childrens-Consent-Age-13-Section-16-Digital-Services-Lower-Than-GDPR-Default-16
Latvia PDPL Children Consent Age 13 + S.16 + Digital Services + Lower Than GDPR Default 16

Latvia PDPL Section 16 Children Consent Age - Latvia adopts age 13 as the digital consent threshold for direct provision of Information Society Services to children (lower than GDPR Article 8(1) default of 16, exercising the Member State derogation permitted to set anywhere between 13-16). One of the lowest digital consent ages in EU + EU comparison: Belgium 13 + Denmark 13 + Estonia 13 + Finland 13 + Latvia 13 + Malta 13 + Poland 13 + Portugal 13 + Spain 14 + Cyprus 14 + Italy 14 + UK 13 + Bulgaria 14 + Austria 14 + Hungary 16 + Germany 16 + Netherlands 16 + Ireland 16 + Luxembourg 16 + Romania 16 + Slovenia 16. Below age 13: parental consent required + reasonable efforts to verify parental consent + age verification mechanisms (account creation with date-of-birth + parental email/SMS verification + payment-card verification + ID-document verification for higher-risk processing) + age-a

Artefacts an auditor will ask for
  • Age verification mechanism (account + payment + parental email/SMS)
  • Parental consent records for under-13
  • Age-appropriate design documentation
  • UNICEF Children Rights compliance
  • Online Safety considerations
Where this commonly fails
  • No age verification
  • Defaulting to GDPR 16 instead of Latvia 13
  • No parental consent mechanism
  • No age-appropriate design

Cross-Border + S.60 + Cooperation + Administrative Liability + Transitional

LV-PDPL-Cross-Border-Transfer-S60-Cooperation-Authorities-S65-Administrative-Liability-S50-Transitional-S68-EDPB-LED
Latvia PDPL Cross-Border + S.60 + Cooperation + S.65 + Administrative Liability + Transitional

Latvia PDPL Cross-Border + International Cooperation + Enforcement. Section 60 Cross-Border Transfers - implements GDPR Chapter V (Articles 44-50) including: (1) adequacy decisions; (2) appropriate safeguards (BCRs + SCCs 2021 + EU-US Data Privacy Framework 2023 + Approved Codes of Conduct + Approved Certification Mechanisms); (3) derogations (explicit informed consent + contract + public interest + vital interests + legal claims + register-based + limited transfers). Latvia member EEA + EU adequacy applies to UK + Switzerland + Canada + Japan + Korea + Israel + Argentina + Uruguay + Andorra + Faroe Islands + Guernsey + Isle of Man + Jersey + New Zealand. Schrems II Transfer Impact Assessment + supplementary measures. Section 65 Cooperation Among Authorities - DVI cooperation with other Member State supervisory authorities under GDPR Chapter VII + EDPB participation + mutual assistance +

Artefacts an auditor will ask for
  • Cross-border transfer inventory + safeguards
  • SCC 2021 executed copies
  • Transfer Impact Assessment per Schrems II
  • One-Stop-Shop LSA designation
  • DVI cooperation records
  • Administrative Procedure Law compliance evidence
  • Latvian Civil Code Article 1635 civil-liability assessment
Where this commonly fails
  • Transfer without lawful basis
  • Old SCCs not refreshed to 2021
  • No TIA
  • Inadequate procedural compliance
  • No civil-liability exposure analysis

DPO + Designation + Qualifications + Notification + S.18 + S.21

LV-PDPL-DPO-Data-Protection-Officer-Designation-Qualifications-Notification-S18-S21
Latvia PDPL DPO + Designation + Qualifications + Notification + S.18 + S.21

Latvia PDPL DPO regime. Section 18 DPO Notification - controllers + processors required to notify DVI of DPO designation + name + contact details + DPO publicly available contact (email + postal + phone) + notification within 1 month of designation + notification of changes + DVI maintains public register of DPOs. Section 21 DPO Qualifications - DPO must possess sufficient knowledge of data protection law + practical experience + ability to fulfil tasks (Article 39 GDPR) + may be employee or external consultant + sufficient resources + reporting to highest management level + independence + no conflict of interest. Mandatory DPO designation per GDPR Article 37 (public bodies + core activities involving systematic monitoring or large-scale special-category processing) + additional Latvian voluntary designation for SME compliance + DVI-accredited DPO training programmes + Latvian DPO Associ

Artefacts an auditor will ask for
  • DVI DPO notification evidence
  • DPO qualifications records
  • DPO independence + reporting line
  • DPO contact publication
  • Conflict-of-interest assessment
  • DPO continuing education
Where this commonly fails
  • DVI not notified of DPO
  • DPO not independent
  • DPO conflict of interest
  • No DPO contact publication

DVI Powers + S.35 + Codes + Certification + Complaints

LV-PDPL-Supervisory-Authority-Data-State-Inspectorate-DVI-Powers-S35-Codes-of-Conduct-S55-Certification-S45-Complaints-S40
Latvia PDPL Supervisory Authority + DVI Powers + S.35 + Codes of Conduct + Certification + Complaints

Latvia PDPL supervisory authority regime. Section 35 Powers of the Data State Inspectorate - DVI investigative + corrective + authorisation + advisory powers (GDPR Article 58 implementation): investigations (notifications + audits + on-site inspection + access to premises and data) + reprimands + warnings + temporary or definitive bans on processing + order to bring processing into compliance + suspend data flows + administrative fines up to EUR 20M or 4% global turnover (GDPR Article 83) + DVI sole supervisory authority for Latvia + Lead Supervisory Authority for Latvia-headquartered controllers under GDPR One-Stop-Shop. Section 40 Complaint Handling - data subjects may complain directly to DVI + DVI registers + investigates + responds within reasonable timeframe + redress + judicial review by Administrative District Court of Riga. Section 45 Certification Bodies - voluntary DVI-accredi

Artefacts an auditor will ask for
  • DVI investigation + audit response procedures
  • Codes of conduct registration
  • Certification body engagement
  • Complaint handling SLA + escalation
  • ISO 27701 ISMS-P or Europrivacy certification
  • Administrative Court review procedure
Where this commonly fails
  • No DVI escalation procedure
  • No codes adoption
  • No certification
  • No complaint SLA
  • No administrative review procedure

Data Subject Rights + Section 18 + 38 + Portability

LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38
Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38

Latvia PDPL data subject rights regime (GDPR Articles 12-22 implemented + Latvian additions). Section 18 Right to Correction (Tiesibas uz datu labosanu) - data subject may request correction of inaccurate or incomplete data + Section 22-23 Accuracy obligations + 30-day response standard SLA. Section 38 Right to Data Portability (Tiesibas uz datu parnesamibu) - data subject may receive personal data provided to controller in structured commonly-used machine-readable format and may transmit to another controller without hindrance + GDPR Article 20 implementation + DVI portability guidance + technical standards (CSV + JSON + XML acceptable) + healthcare portability + financial portability + electronic medical records portability. Latvia goes beyond GDPR with explicit cross-reference to Latvian Civil Code Article 1635 personal data civil liability + Articles 16+ Constitutional Court privacy

Artefacts an auditor will ask for
  • Rights request SLAs (30-day) + log
  • Latvian Civil Code Article 1635 awareness
  • Section 38 portability format documentation
  • Identity verification policy
  • Deceased-persons rights process
  • DPIA for automated decisions
Where this commonly fails
  • Slow rights response
  • Missing portability format support
  • No deceased-persons rights process
  • No automated-decision opt-out

Journalism + S.10 + Personal ID Numbers + Video Surveillance + Direct Marketing

LV-PDPL-Special-Contexts-Journalistic-Academic-Artistic-Literary-S10-Personal-ID-Numbers-S9-Video-Surveillance-S25-Direct-Marketing-S28
Latvia PDPL Special Contexts + Journalism + S.10 + Personal ID Numbers + Video Surveillance + Direct Marketing

Latvia PDPL Special-Contexts processing derogations and elaborations. Section 10 Processing for Journalistic + Academic + Artistic + Literary Expression - extensive GDPR Article 85 derogation balancing freedom of expression + privacy + Press Law of Republic of Latvia + Public Broadcasting Law + Latvian Journalists Code of Ethics + academic freedom + creative expression + public figure considerations + legitimate interest test + Constitutional Court decisions on press freedom and privacy. Section 9 Processing of Personal Identification Numbers (Personas kods) - strict regulation restricting use of 11-digit Latvian unique national ID outside statutory contexts including tax administration (State Revenue Service) + social insurance (State Social Insurance Agency) + healthcare (National Health Service) + banking (Anti-Money Laundering Law cross-reference) + with mandatory legal basis + data

Artefacts an auditor will ask for
  • Section 10 derogation memos for journalism
  • Personas kods register + minimisation evidence
  • Video Surveillance DPIA + signage
  • Direct marketing opt-in evidence
  • Workplace surveillance Labour Code consultation
Where this commonly fails
  • Unjustified journalism derogation
  • Personas kods minimisation gap
  • CCTV without signage
  • Direct marketing without opt-in

Lawful Basis + Public Interest + Special Categories + Personal ID Numbers

LV-PDPL-Lawful-Basis-Public-Interest-Tasks-S5-Sensitive-Special-Categories-Genetic-Biometric-S30-Purpose-Limit-Sec20-Data-Minim-Sec21
Latvia PDPL Lawful Basis + S.5 Public Interest + S.30 Special Categories + Purpose Limitation

Latvia PDPL Section 5 Lawful Basis for Public Interest Tasks - explicit Latvian elaboration of GDPR Article 6(1)(e) public interest task ground including processing by public bodies for archiving + scientific + historical research + statistical purposes + tasks of public interest delegated by law. Section 9 Processing of Personal Identification Numbers (Personas kods - Latvian unique national 11-digit ID consisting of date of birth plus 5 digits) - strict regulation restricting use of Personas kods identifier outside statutory contexts including public administration + tax + social insurance + healthcare + banking with mandatory legal basis + minimisation. Section 30 Genetic and Biometric Data extension of GDPR Article 9 sensitive category protection including processing for research + medical purposes + criminal investigation under LED. Latvia adopts GDPR purpose limitation + data minim

Artefacts an auditor will ask for
  • Lawful basis register per processing
  • Personas kods register + lawful-basis documentation
  • Special-categories consent records
  • Latvian Civil Code Article 1635 compliance memo
  • DPIA for genetic + biometric
Where this commonly fails
  • Processing Personas kods without statutory basis
  • Special categories without explicit consent + Article 9
  • No purpose limitation policy
  • Personas kods minimisation gap

Scope + Saeima + GDPR Implementation + DVI

LV-PDPL-Scope-PersonalDataProcessingLaw-Saeima-21-June-2018-Effective-5-July-2018-GDPR-Implementation-DVI
Latvia PDPL Scope + Saeima 21 June 2018 + Effective 5 July 2018 + GDPR Implementation + DVI

Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums) adopted by Saeima (Latvian Parliament) on 21 June 2018 + promulgated by President Raimonds Vejonis + effective 5 July 2018 + replaces 2000 Personal Data Protection Law (Fizisko personu datu aizsardzibas likums) which transposed Directive 95/46/EC. Latvian GDPR implementation statute providing national derogations + specifications permitted under EU Regulation 2016/679 + transposes EU Law Enforcement Directive 2016/680 (LED) for processing by competent authorities for criminal-investigation purposes. Constitutional anchor Latvian Constitution Article 96 right to privacy + Charter of Fundamental Rights Articles 7-8. Data State Inspectorate (Datu valsts inspekcija - DVI) as independent supervisory authority + located in Riga + Director General + Council + Department of Privacy and Personal Data Protection + Departme

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • DVI engagement records
  • Legal opinion on Latvia-specific provisions
  • One-Stop-Shop LSA designation evidence
Where this commonly fails
  • Treating Latvia PDPL same as GDPR without Latvian derogations
  • No DVI engagement
  • Failure to identify LED-applicable processing
  • No Latvian-language privacy notices
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) framework page.