Law / Latvia

Latvia

European Union law applies in Latvia Latvia is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Latvia, described on this page below, applies here too.

17 of 18 named instruments researched to a stage, across all six areas of law we track: 17 in force. As of 15 September 2026.

When they take effect17 of 17 carry a date.
2018: 6 instruments (6 in force) ’18 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 4 instruments (4 in force) 2024: 4 instruments (4 in force) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 3
  5. Age gating law 2
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (198 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Latvia and is not restated here; VARAM, the Ministry of Smart Administration and Regional Development, has been designated the lead competent authority, with the Consumer Rights Protection Centre, the Health Inspectorate, the State Data Inspectorate, and other named sector bodies as market surveillance authorities, per a February 2025 Cabinet of Ministers information report.

Latvia's own Mākslīgā intelekta centra likums (Law on the Artificial Intelligence Centre), in force since 20 March 2025, establishes a state-supported foundation to coordinate national AI policy, run a regulatory sandbox, and advise on AI or deepfake use during elections and Saeima appointment processes, but it imposes no duty on a private developer or deployer of an AI system, so it is described here rather than landed as an instrument.

Latvia does bind private conduct directly through the Krimināllikums (Criminal Law): Section 90.1, in force since 22 May 2024, criminalizes producing or disseminating deliberately false, discrediting information about a political party or a Saeima, municipal, or European Parliament candidate using deepfake technology during the pre-election campaign period or on election day, and Section 90.2 does the same for a state-official appointment process before the Saeima.

AI prohibited practices

Krimināllikums Sections 90.1 and 90.2, Criminalization of Deepfake Election and State-Appointment Disinformation

Krimināllikums, 90.1 un 90.2 pants, pievienoti ar 2024. gada 9. maija likumu, stājas spēkā 22.05.2024.Krimināllikums, official consolidated text, likumi.lv

In force since 22 May 2024. Binds public and private bodies.

What this law does

Section 90.1 criminalizes the deliberate production or dissemination of knowingly false, discrediting information about a political organization (party), an association of political organizations, or a candidate for the Saeima, a municipal council, or the European Parliament, using deepfake technology, when committed during the pre-election campaign period or on election day; the maximum penalty is five years' deprivation of liberty, or alternatively short-term deprivation of liberty, probationary supervision, or community service.

Section 90.2 criminalizes the same conduct directed at a candidate for a state office the Saeima elects, appoints, or confirms, when committed during that process, carrying the same maximum penalty.

What it requires

Privacy law6 instruments, 6 in force

Research summary (84 words)

Latvia's private-sector regime is the General Data Protection Regulation (GDPR) plus the Personal Data Processing Law (Fizisko personu datu apstrades likums, Latvijas Vestnesis No. 132/2018), which establishes the Data State Inspectorate (DVI) as supervisory authority and supplies the national institutional and procedural layer GDPR leaves to member states.

Article 25(2) of the Law restates GDPR Article 9's special-category list including biometric data, with no illustrative example list and no Latvia-specific narrowing or widening of the biometric category. As at 24 August 2026; later amendment is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Latvia

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Data State Inspectorate (DVI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Latvia-specific derogation to this timeline was found.

What it requires

Comprehensive regime

Personal Data Processing Law (Fizisko personu datu apstrādes likums)

Fizisko personu datu apstrades likums, Latvijas Vestnesis No. 132 (2018), in force 5 July 2018Latvijas Vestnesis official text, No. 132 (2018)

In force since 5 July 2018. Binds public and private bodies.

What this law does

Latvia's national supplement to the directly applicable General Data Protection Regulation (GDPR), establishing the Data State Inspectorate (DVI) as supervisory authority with GDPR Article 57-58 powers, national procedure for decisions, disputes and appeals, and data protection officer regulation. It does not restate GDPR's substantive lawful basis, rights, or transfer rules, which apply directly.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Latvia

Regulation (EU) 2016/679, Arts. 44-50Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Latvia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Latvia-specific transfer restriction beyond Chapter V was found.

What it requires

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Latvia

Regulation (EU) 2016/679, Arts. 15-22Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Latvia: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller, generally within one month. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect.

The Personal Data Processing Law's national role is institutional (the Data State Inspectorate's powers and complaint procedure) rather than a rewrite of the rights chapter; no Latvia-specific derogation narrowing these rights was found.

What it requires

Enforcement supervision

GDPR Articles 82-83 and DVI Enforcement in Latvia

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Data State Inspectorate (DVI) holds the General Data Protection Regulation (GDPR) Article 57-58 toolkit, investigative powers, corrective powers, and administrative fine authority up to the Article 83 tiers. DVI has issued fines under this authority, including a reported EUR 1.2 million penalty against a service provider. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Sensitive categories

Personal Data Processing Law Article 25(2), Special Categories in Latvia

Fizisko personu datu apstrades likums, Art. 25(2); Regulation (EU) 2016/679, Art. 9likumi.lv, Fizisko personu datu apstrades likums, Art. 25(2)

In force since 5 July 2018. Binds public and private bodies.

What this law does

Article 25(2) of the Personal Data Processing Law, confirmed at likumi.lv, restates General Data Protection Regulation (GDPR) Article 9's special-category list and its own biometric-data term mirroring GDPR Article 4(14)'s definition (processing necessary for unique identification). It carries no illustrative list, enumeration, or named example distinguishing facial recognition from voice data or any other biometric modality.

No Latvia-specific narrowing or widening of the biometric category beyond the GDPR baseline was found in this provision.

What it requires

Scraping law3 instruments, 3 in force

Research summary (140 words)

Latvia's Krimināllikums (Criminal Law) makes access to an automated data processing system a crime only where it involves breaching the system's protective means or accessing without permission or by using another person's rights, so crawling a public, unauthenticated page carries no exposure under this provision; a further section separately criminalizes unauthorized interference with system data, and another the manufacture or distribution of tools intended to compromise such systems.

The Autortiesību likums (Copyright Law) gives a database maker a sui generis right against extraction or re-utilization of the whole, or a substantial part, of a database reflecting a substantial investment, running fifteen years from completion, alongside a 2023-added, machine-readable-opt-out text-and-data-mining exception transposing the EU Digital Single Market Copyright Directive.

No dedicated personal-data, unfair-competition, or robots.txt-specific statute distinct from the General Data Protection Regulation (GDPR)-based privacy regime, already covered under privacy, exists in the primary text.

Computer misuse

Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences

Krimināllikums, 241., 243. un 244. pantsKrimināllikums, official consolidated text, likumi.lv

In force since 4 July 2024. Binds public and private bodies.

What this law does

Section 241 makes arbitrary access to the resources of an automated data processing system a crime only where it involves breaching the system's protective means, or is carried out without permission or by using rights granted to another person, and causes substantial harm; the maximum penalty rises from two to four years where the access is for financial gain, and to seven years where committed by an organized group, causing serious consequences, or directed at a system processing state-security-related information.

Because breaching a protective measure or exceeding an authorization is the trigger, crawling a public, unauthenticated page carries no exposure under this section. Section 243 separately criminalizes unauthorized modification, damage, destruction, impairment, or concealment of information in such a system, or knowingly entering false information into it, at penalties up to three years, rising to seven for an organized group or serious consequences.

Section 244 criminalizes the unauthorized manufacture, adaptation, distribution, acquisition, transport, or storage of a tool, device, software, password, or access code intended to influence such a system's resources or to gain access to it for committing a crime, at penalties up to two years, rising to five for an organized group or serious consequences.

What it requires

Copyright and text and data mining (TDM)

Autortiesību likums Article 21.1, Text and Data Mining Exception (Scraping and AI Training)

Autortiesību likums (scraping) 21.1 pants, pievienots ar 2023. gada 23. marta likumu 'Grozījumi Autortiesību likumā' (Latvijas Vēstnesis, 67, 04.04.2023.), stājas spēkā 05.04.2023.Grozījumi Autortiesību likumā (2023 Copyright Law amendments transposing Directive (EU) 2019/790), official text, likumi.lv

In force since 5 April 2023. Binds public and private bodies.

What this law does

Article 21.1 permits reproducing a lawfully accessible work to carry out text and data mining, defined as any automated analytical technique used to analyze text and data digitally to derive information such as patterns, trends, and correlations. Copies made for that purpose may be kept only as long as needed for the mining.

A rights holder can prohibit this use by giving clear notice in an appropriate manner, and a prohibition on the online use of publicly accessible works must be given in machine-readable form, including through metadata. A separate, non-waivable exception at Article 21.2 covers a research organization or a cultural heritage institution mining lawfully accessible works for scientific research, without that opt-out, but Article 21.2(5) excludes computer programs from its scope.

What it requires

Database right

Autortiesību likums Chapter IX, Sui Generis Database Right

Autortiesību likums IX nodaļa (57.-62. pants), Datubāzes aizsardzības īpatnības (sui generis), grozīta ar 2023. gada 23. marta likumu, stājas spēkā 05.04.2023.Autortiesību likums, official consolidated text, likumi.lv

In force since 5 April 2023. Binds public and private bodies.

What this law does

A person or legal entity that has taken the initiative and risk of investment in creating a database, where its creation, verification, or presentation reflects a substantial qualitative or quantitative investment, is recognized as its maker and can prevent extraction, meaning the permanent or temporary transfer of the whole or a substantial part of its content to another medium, and re-utilization, meaning making that content available to the public by distributing, renting, or providing online or other transmission of it.

Repeated and systematic extraction or re-utilization of insubstantial parts is also barred where it conflicts with the database's normal use or unreasonably prejudices the maker's legitimate interests. The right runs fifteen years from the year following completion, restarting on a substantial new investment, and does not reach a lawful user's extraction or re-utilization of an insubstantial part for any purpose, nor extraction for text and data mining permitted under Articles 21.1 and 21.2.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (730 words)

Latvia's NIS2 transposition, the Nacionālās kiberdrošības likums (National Cybersecurity Law, NKDL), was adopted by the Saeima on 20 June 2024, published in Latvijas Vēstnesis (128A, 04.07.2024), and entered into force on 1 September 2024; its own transitional provisions repealed the prior Informācijas tehnoloģiju drošības likums (Information Technology Security Law, the 2010 NIS1 transposition) outright on the same date, so no predecessor regime survives alongside it.

The version in force as of this review reflects amendments enacted 4 June 2026 that took effect 18 June 2026, with a further, narrower tranche (adding a national-security ownership category to Article 20) due to take effect 1 October 2026 and not yet reflected in the displayed text.

The Law binds a būtisko pakalpojumu sniedzējs (essential service provider, Article 20) or svarīgo pakalpojumu sniedzējs (important service provider, Article 21) by sector and, for most sectors, a large- or medium-enterprise size gate; Article 21(1)(2)(l)-(n) names an online marketplace, an online search engine and a social media platform provider expressly among the medium-or-large digital providers it reaches, and Article 20(8)(s)-(v) separately reaches a large cloud-computing, content-delivery-network, data-centre or domain-name-system provider as essential (with the medium tier of the same list important under Article 21(1)(1)), a sector class no activity in this vocabulary expresses.

The Law also binds direct and indirect state and municipal administration and other public-law bodies (Article 3(1)(2), Article 20(5)(6)(10)), excluding the state security services, so it reaches a government duty-bearer as well as a private one.

Article 27 sets the core risk-management duty (appropriate and proportionate technical and organisational measures), Article 28 requires a written cyber-risk-management and ICT-business-continuity plan with staff training, and Article 26 has the Cabinet set the minimum cybersecurity requirements the plan must meet, done by Cabinet Regulation No. 397 of 25 June 2025; a personnel-security screening duty for ICT staff with privileged access, Article 26.1, was inserted by the 2026 amendment.

Article 34 sets NIS2's own graduated incident-notification clock to the competent cyber incident prevention institution (an early warning within 24 hours, an initial report within 72 hours, a final report within one month), but that clock did not itself bind until 1 July 2025 under the Law's transitional provisions, nine months after the Law's own commencement.

Articles 39 and 40 add a coordinated-vulnerability-disclosure regime distinct from Article 34: any person who discovers a vulnerability in a subject's system must report it within five working days, and the subject must then remediate within a deadline the institution sets, capped at 90 days and extendable to 180 days on request; Article 46's fine, however, defines 'material non-compliance' by a closed three-item list that does not name a missed Article 40 remediation deadline, an open question flagged below rather than an unsupported penalty figure for that duty.

Supervision splits between the Nacionālais kiberdrošības centrs (National Cybersecurity Centre, NKDC, within the Ministry of Defence), which is the Article 41 competent authority for essential and important service providers generally and receives most subjects' incident and vulnerability reports through the Institute of Mathematics and Computer Science of the University of Latvia (the body that operates publicly as CERT.LV), and the Satversmes aizsardzības birojs (Constitution Protection Bureau, SAB), which holds the same role for an owner or lawful possessor of ICT critical infrastructure.

Article 46 sets NIS2's own two-tier fine, up to EUR 10,000,000 or, above EUR 500,000,000 turnover, 2 percent of turnover for an essential entity, and up to EUR 7,000,000 or 1.4 percent for an important entity, imposed directly by NKDC or SAB as an administrative fine with no criminal offence and no private right of action, appealable to court by the subject under the Administrative Procedure Law.

No Latvian instrument reviewed here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Latvia has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33-34 and the Fizisko personu datu apstrādes likums sits in the privacy topic rather than here.

Article 3(3)-(4) exempts a financial entity already subject to Regulation (EU) 2022/2554 (DORA), and any essential or important service provider covered by an equivalent sector-specific EU cybersecurity regime, from the Law's risk-management and supervision provisions to the extent that regime's own requirements are at least equivalent.

Sector security regimes

Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures

Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024, redakcija uz 18.06.2026), 25.-28. pantiNacionālās kiberdrošības likums (National Cybersecurity Law)

In force since 1 September 2024. Binds public and private bodies.

What this law does

Article 27 requires a subject (an essential service provider under Article 20, an important service provider under Article 21, or an owner or lawful possessor of ICT critical infrastructure) to take appropriate and proportionate technical and organisational measures to manage the cyber risks to the security of the electronic communications networks and information systems it uses, and to prevent or minimise the impact of a cyber incident on its service recipients and on other services.

Article 21(1)(2)(l)-(n) names an online marketplace, an online search engine and a social media platform provider expressly among the medium-or-large digital providers this duty reaches as important entities.

Article 28 additionally requires the subject to draft a cyber-risk-management and ICT-business-continuity plan and to train staff on it, with the plan's required content and the minimum cybersecurity requirements the subject's systems must meet set by Cabinet Regulation No. 397 of 25 June 2025; Article 25 requires the subject's head to appoint a cybersecurity manager (kiberdrošības pārvaldnieks) within three months of the subject's status notification, and Article 26.1, inserted by the amendment in force since 18 June 2026, adds a criminal-record screening duty for ICT staff with privileged system access.

Article 3(3)-(4) exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA), and any subject covered by an equivalent sector-specific EU cybersecurity regime, from these provisions to the extent that regime's own requirements are at least equivalent.

What it requires

Vulnerability and incident reporting

Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation

Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. pantiNacionālās kiberdrošības likums (National Cybersecurity Law), consolidated text in force 18.06.2026-30.09.2026, likumi.lv, Articles 39-40

In force since 1 September 2024. Binds public and private bodies.

What this law does

Article 39 requires any person who discovers a vulnerability in a subject's information system or electronic communications network to report it to the competent cyber incident prevention institution within five working days, and lets that person report anonymously and have their identity kept confidential.

Once the institution has assessed a report as substantiated and relayed it, Article 40 requires the affected subject to take the actions necessary to remediate the vulnerability within the institution's own deadline, capped at 90 days from receiving the information and extendable to 180 days on the subject's request for objective reasons, reporting progress to the institution as it goes. This is a subject-facing remediation clock rather than only a state-run coordination function.

Article 46(5), however, defines a fine-triggering 'material non-compliance' with a closed three-item list (failing to take appropriate measures, repeatedly refusing supervisory information requests, and a late or false significant-incident notification) that does not name a missed Article 40 deadline, so whether that specific failure draws the Article 46 fine, rather than only the non-monetary corrective and suspension powers Article 45 gives generally, is not settled by the text and is recorded as an open question here rather than as a penalty figure.

What it requires

Nacionālās kiberdrošības likums, Incident Notification

Nacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pantsNacionālās kiberdrošības likums (National Cybersecurity Law), consolidated text in force 18.06.2026-30.09.2026, likumi.lv, Article 34

In force since 1 July 2025. Binds public and private bodies.

What this law does

Article 34 requires a subject to notify the competent cyber incident prevention institution immediately of any cyber incident and to follow its instructions.

For a significant cyber incident, the subject must submit an early warning within 24 hours of becoming aware, an initial report within 72 hours (24 hours for a trust service provider), and, within one month of the initial report, a final report (or, if unresolved, a progress report followed by a final report once resolved); where relevant, the subject must also inform affected service recipients of protective measures and, after coordinating with the institution, of the incident itself.

This is NIS2 Article 23's own clock. Although the Law commenced 1 September 2024, its transitional provisions delayed Article 34's paragraphs two through five, the notification clock itself, until 1 July 2025.

For most private-sector and civilian public-sector subjects the competent cyber incident prevention institution is the Institute of Mathematics and Computer Science of the University of Latvia, which operates publicly as CERT.LV; the Military Intelligence and Security Service holds the same role for the defence sector. A missed or knowingly false notification is one of Article 46(5)'s three enumerated grounds for a material non-compliance fine.

What it requires

Age gating law2 instruments, 2 in force

Research summary (134 words)

Latvia's national age law sits in the Elektronisko plašsaziņas līdzekļu likums (Electronic Mass Media Law), which transposes the EU Audiovisual Media Services Directive's minor-protection and video-sharing-platform provisions.

A broadcast or on-demand audiovisual service carrying content that could harm a minor's physical, mental, or moral development must either keep it outside a 7:00 to 22:00 watershed or provide restricted access control, preceded by an acoustic warning and marked with a visual content symbol; an on-demand catalogue carries the same restricted-access-control duty.

A video-sharing platform provider must take appropriate measures against content and user-generated commercial communications that could harm minors and must publish its own code of conduct addressing communications aimed at or capable of affecting minors' development. No dedicated social-media minimum-age statute or app-store age-verification duty is on the books as of the date below.

Adult content age verification (AV)

Elektronisko plašsaziņas līdzekļu likums, Articles 23(4) and 24(9)-(10.1), Restricted Access Control for Content Harmful to Minors

Elektronisko plašsaziņas līdzekļu likums, 23. panta ceturtā daļa un 24. panta devītā, desmitā un 10.1 daļa; konsolidētais teksts likumi.lvElektronisko plašsaziņas līdzekļu likums, official consolidated text, likumi.lv

In force since 11 May 2021. Binds public and private bodies.

What this law does

Article 24(9) bans distributing audio and audiovisual works depicting physical or psychological violence, bloody or horror scenes, drug use or sexual acts, or containing coarse or indecent language, between 7:00 and 22:00.

Article 24(10) requires an electronic mass medium not observing that watershed for content that could harm a minor's physical, mental, or moral development to instead provide restricted access control, preceded by an acoustic warning signal and marked with a visual symbol describing the content's potentially harmful nature. Article 23(4) imposes the equivalent restricted-access-control duty on an on-demand catalogue offering such content.

Article 24(10.1) bars commercial use of a minor's personal data obtained through that access control, except where necessary to provide the service itself with the data subject's consent.

Note and primary source

Age-appropriate design code

Elektronisko plašsaziņas līdzekļu likums, Article 23.6, Video-Sharing Platform Minor Protection Measures

Elektronisko plašsaziņas līdzekļu likums, 23.6 pants, pievienots ar 2020. gada 5. novembra likumu, stājas spēkā 01.12.2020.Elektronisko plašsaziņas līdzekļu likums, official consolidated text, likumi.lv

In force since 1 December 2020. Binds private bodies.

What this law does

A video-sharing platform provider, defined by Article 23.5 as an information-society service whose main purpose or an essential function is to provide the public with programmes or user-generated videos it does not edit but organizes and promotes for profit, must take appropriate measures to protect the public from content and user-generated video or audio commercial communications that could harm minors' physical, mental, or moral development, that could incite violence or hatred, or that constitute a listed criminal offence.

It must publish its own publicly accessible code of conduct addressing commercial communications aimed at or capable of negatively affecting the psychological or physical development of minors, including in children's programming.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (147 words)

Latvia transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right and text-and-data-mining exceptions into the Autortiesību likums (Copyright Law) through amendments adopted 23 March 2023 and in force from 5 April 2023.

Article 53.1 gives a press publisher an exclusive right to reproduce and make available online its press publications, running two years from publication, and excluding private or non-commercial use, hyperlinks, and single words or very short extracts.

Article 21.1 permits reproducing a lawfully accessible work, including news content, for text and data mining, unless the rights holder has expressly and machine-readably reserved that use; a separate, non-waivable exception in Article 21.2 covers research organizations and cultural heritage institutions.

Latvia has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from ordinary unfair-competition law exists in the primary text.

Press publishers' right

Autortiesību likums Article 53.1, Press Publisher Online Rights (DSM Article 15 Transposition)

Autortiesību likums 53.1 pants, pievienots ar 2023. gada 23. marta likumu 'Grozījumi Autortiesību likumā' (Latvijas Vēstnesis, 67, 04.04.2023.), stājas spēkā 05.04.2023.Grozījumi Autortiesību likumā (2023 Copyright Law amendments transposing Directive (EU) 2019/790), official text, likumi.lv

In force since 5 April 2023. Binds private bodies.

What this law does

A press publisher holds an exclusive right to reproduce and make available online its press publications, defined as a journalistic compilation published under one title in a periodical or regularly updated edition, exercised against an information-society service provider. The right does not reach private or non-commercial use, hyperlinks, or the use of single words or very short extracts.

It cannot be invoked to prohibit use of works the publisher included under a simple licence, or whose copyright or related-rights term has expired, and runs for two years after the press publication is made public. An author whose work is included in a press publication has a right to a proportionate share of the revenue the publisher earns from this online use.

Note and primary source

Text and data mining (TDM) opt-out

Autortiesību likums Article 21.1, Text and Data Mining Exception (News Indexing and Aggregation)

Autortiesību likums (aggregation) 21.1 pants, pievienots ar 2023. gada 23. marta likumu 'Grozījumi Autortiesību likumā' (Latvijas Vēstnesis, 67, 04.04.2023.), stājas spēkā 05.04.2023.Grozījumi Autortiesību likumā (2023 Copyright Law amendments transposing Directive (EU) 2019/790), official text, likumi.lv

In force since 5 April 2023. Binds public and private bodies.

What this law does

Article 21.1 permits reproducing a lawfully accessible work, including a press publication or its fragments, to carry out text and data mining. Copies made for that purpose may be kept only as long as needed for the mining. A rights holder, including a press publisher, can prohibit this use by giving clear notice in an appropriate manner.

A prohibition on the online use of publicly accessible works must be given in machine-readable form, including through metadata, which is the opt-out an aggregator's automated indexing must honor. A separate, non-waivable exception at Article 21.2 covers a research organization or a cultural heritage institution mining lawfully accessible works for scientific research, without that opt-out.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.