GDPR Articles 82-83 and DVI Enforcement in Latvia
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect the Data State Inspectorate to have jurisdiction and fining power over your processing of personal data of a person in Latvia, up to the General Data Protection Regulation (GDPR) Article 83 tiers.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Kriminallikums (Criminal Law) Section 145, Illegal Activities Involving Personal Data of Natural Persons, criminalizes unlawful activity involving a natural person's personal data in three escalating tiers: up to two years' deprivation of liberty where substantial harm is caused (para. 1); up to four years where committed by a personal data processing controller or processor for vengeance, gain, or blackmail (para. 2); and up to five years where committed by using violence, threats, bad-faith abuse of trust, or deceit against the controller, processor, or data subject (para. 3), each alternatively punishable by temporary deprivation of liberty, probationary supervision, community service, or a fine. This is a dedicated personal-data criminal offense in the Criminal Law, distinct from DVI's administrative fining power under GDPR Article 83.
Penalty structure
GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for infringements including the Article 9 special category rules, the Article 12 to 22 data subject rights, and the Chapter V transfer rules. The lower Article 83(4) tier, up to EUR 10,000,000 or 2% of turnover, applies instead to the Article 25 to 39 controller and processor obligations. No Latvia-specific modification to these ceilings, such as a public-sector carve-out, is stated in the Act.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Data State Inspectorate (Datu valsts inspekcija, DVI), Latvia's independent supervisory authority under the GDPR.
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data State Inspectorate (DVI) holds the General Data Protection Regulation (GDPR) Article 57-58 toolkit, investigative powers, corrective powers, and administrative fine authority up to the Article 83 tiers. DVI has issued fines under this authority, including a reported EUR 1.2 million penalty against a service provider. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
DVI enforcement record, reported by TGS Baltic and GDPRhub
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.