A Latvian startup is processing personal data from its first employee and its first customer, which means the General Data Protection Regulation applies from day one and not from some later size. Most of what it asks for is documentation you should want anyway. This covers what applies here, what Latvia has added on top of the Regulation, and what the Data State Inspectorate does about it.
What Data Protection Actually Requires of a Latvian Startup
By Deepti Gupta · Reviewed by Vinayak Ravi · Riga Startups Editorial Team
Last verified · every figure links to its source, and the date each was checked is listed at the end · 12 min read

This is the ordinary case for a small Latvian company handling employee and customer data. It is not advice on a particular processing operation, and anything involving health data, biometrics, large scale monitoring, or profiling that decides something about a person needs proper counsel. The Regulation is EU law and applies in every member state; only the Latvian additions are specific to here.
Does GDPR Apply to a Latvian Startup?
From the first person whose data you hold. There is no employee threshold and no turnover threshold. A company with one founder and a mailing list is a controller with the full set of obligations, and the parts that scale with size are the paperwork and the risk rather than whether the Regulation reaches you.
The confusion usually comes from article 30, which does carry a size test for records of processing, and which is widely misread as a general exemption for small companies. It is not one, and the test has holes big enough that most startups fall outside it anyway.
What applies immediately, whatever your size:
- A lawful basis for every processing operation. Consent is one of six and usually the weakest. Employment data generally rests on the contract and on legal obligations, customer billing on the contract, and product analytics on legitimate interests, which has to be assessed rather than asserted.
- Telling people what you do with their data, in a privacy notice written for the reader rather than for a regulator.
- Answering data subject requests for access, correction, deletion, and portability, inside the Regulation's deadlines.
- Written terms with every processor. Your payroll bureau, your hosting provider, your CRM, your email tool. Article 28 requires a contract with specified content, and most vendors publish one you accept rather than negotiate.
- Security appropriate to the risk, which for a small company means the ordinary things: access control, encryption in transit, backups, and removing leavers' access.
Who Enforces Data Protection in Latvia?
The Datu valsts inspekcija, the Data State Inspectorate. The Personal Data Processing Law sets it up, gives it the Regulation's investigative and corrective powers, and lets it inspect a place where processing happens. Its decisions can be contested and then appealed to the administrative court.
An inspection is not a dawn raid, but it does not need your cooperation either.
- It can visit where the processing happens. Article 15 of the Personal Data Processing Law lets the Inspectorate visit the processing site, obtain information by any lawful method, and take other necessary steps.
- It tells you first, and proceeds anyway. Before visiting it informs the controller of the purpose, time, and place, and asks for an authorised representative to be present. The law then says plainly that failure to provide one does not prevent the inspection.
- Its officials identify themselves and state the subject. They attend in the presence of the controller's representative or an employee, show a service certificate, and say what is being examined.
- Its decisions are reviewable. The law provides for contesting and appealing a decision, which is what makes an inspection an administrative process rather than a verdict.
The Inspectorate also publishes guidance and an annual report, and answers questions in advance. For a small company that is the cheaper interaction, and it is available before something goes wrong rather than after.
Does a Latvian Startup Need a Data Protection Officer?
Usually not, and Latvia adds a wrinkle if you appoint one anyway. The Regulation requires an officer only where processing is by a public authority, or where core activities involve regular and systematic monitoring of people on a large scale, or large scale processing of special category data.
For an ordinary Latvian startup none of those is true, and appointing an officer is a choice rather than a duty. Two things are worth knowing before making it.
- Latvia runs a qualification examination. The Personal Data Processing Law lets a controller appoint either a person on the Inspectorate's list of data protection specialists or another person who meets the Regulation's own criteria. The list contains only people who have passed the qualification examination, which is a signal of competence rather than a legal requirement.
- Appointing one has consequences. Once appointed, the officer must be involved in all data protection matters, must not be instructed how to do the job, cannot be dismissed for doing it, and their details go to the Inspectorate and into your privacy notice. A nominal appointment that ignores all of that is worse than no appointment.
The sensible middle for a startup is to give one named person the responsibility internally, without calling them a data protection officer, and to buy advice when something unusual arrives.
What Records of Processing Must a Latvian Company Keep?
Assume you need them. Article 30 of the Regulation exempts organisations under 250 employees, then withdraws the exemption where processing is likely to result in a risk to people, is not occasional, or includes special category data. Employee payroll data alone is regular rather than occasional.
The record is an internal document and nobody asks to see it until they do, at which point its absence is the first thing on the list.
What it holds is not onerous: the purposes of each processing activity, the categories of people and data, who receives the data, any transfer outside the EU, retention periods where you can state them, and a general description of your security measures. For a company of ten that is a page or two, and writing it usually surfaces something nobody had noticed, most often an old tool still holding data for a purpose that ended.
The work is in keeping it current. Tie it to something that already happens, such as reviewing it whenever you add a vendor, rather than to a date nobody will remember.
What Do You Do When Personal Data Leaks in Latvia?
Notify the Inspectorate within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Where the risk to individuals is high, tell them too, without undue delay. A breach is broader than a hack and includes loss, accidental deletion, and sending data to the wrong recipient.
The clock is the part that catches companies, because it runs from awareness rather than from the end of your investigation.
- Notify late rather than not at all. The Regulation allows a notification after 72 hours accompanied by the reasons for the delay. Silence is the thing that turns an incident into an enforcement case.
- You can notify in stages. Where you do not have the full picture, provide information in phases rather than waiting until you do.
- Document every breach, including the ones you decide not to notify, with the reasoning. That record is how you show the decision was made properly.
- A processor tells you, and you tell the authority. Your vendor notifies you without undue delay; the duty to notify the Inspectorate stays with you as controller.
Decide in advance who makes the call, because discovering a breach at seven on a Friday is not the moment to work out who is allowed to speak to a regulator.
At What Age Can a Child Consent in Latvia?
13 years. The Regulation lets each member state set the threshold for information society services anywhere between thirteen and sixteen, and Latvia chose the lowest. Below that age the consent has to come from a parent or legal guardian, and your service has to make a reasonable effort to check.
This matters to any consumer product a teenager might plausibly sign up for, and it matters more than it looks because the age differs across the Union. A service available in Latvia and Germany faces two different thresholds for the same sign-up form, which is an argument for designing to the highest one you are exposed to rather than to the local minimum.
It also bites only where you are relying on consent. A service provided to the child under a contract, with a different lawful basis, is a different analysis, and one worth doing properly before building an age gate.
What Are the Rules for Cameras in a Latvian Office?
Latvia sets its own minimum for the sign. Where a controller uses an information sign for video surveillance, the Personal Data Processing Law requires it to state the controller's name, its contact details, the purpose of the processing, and how to get the rest. Household use is outside the rules, and that exception does not stretch to an office.
A camera in a workplace is processing employee data continuously, which puts it among the harder things a small company does.
- The sign is the visible part and the smallest part. Behind it you need a lawful basis, a purpose you can state precisely, a retention period, and a decision about who can view the footage.
- Large scale public space monitoring is not household use. The Law says so explicitly, and it also excludes cases where technical aids are used to structure the information.
- Employee monitoring needs a proportionality argument. Security at an entrance is easier to justify than a camera pointed at desks, and recording sound is harder again.
- Keep the footage briefly. A retention period measured in days is defensible for security; keeping months of recordings because the system defaults to it is not.
What Can Getting Data Protection Wrong Cost in Latvia?
The Regulation's two tiers apply here as everywhere: up to EUR 10 million, or 2% of worldwide annual turnover, whichever is higher for most obligations, and up to EUR 20 million, or 4% of worldwide annual turnover, whichever is higher for breaching the principles, people's rights, or the transfer rules. Latvia's own penalties reach public officials, not companies.
The ceilings are not the realistic number for a startup, and quoting them at each other is how companies end up buying compliance theatre. The fine is set by reference to the nature and gravity of the infringement, the number of people affected, whether it was negligent or deliberate, what you did to mitigate, and whether you reported it yourself.
- The national offence regime is aimed elsewhere. The Personal Data Processing Law fines an official of a public law legal person up to 200 penalty units, currently EUR 1,000, for unlawful acts with personal data or for failing to fulfil controller or processor duties in a public institution. A private company's exposure runs through the Regulation and the Inspectorate instead.
- Corrective powers usually hurt more than fines. An order to stop a processing operation, or to delete data you built a product on, is a bigger event for a startup than a penalty.
- People can also sue. The Regulation gives a right to compensation for material and non-material damage, separately from anything a regulator does.
- Customers ask before regulators do. For a company selling to businesses, the practical enforcement is a security questionnaire in a procurement process, and the answer to it is the same documentation this guide describes. Selling to Latvian public buyers covers where those questionnaires come from.
What Should a Latvian Startup Do First?
Five things, in order, and all of them are documents rather than software. Write the record of processing, list every vendor touching personal data and check you have terms with each, publish a privacy notice people can read, decide who handles a breach and a data subject request, and set retention periods you can actually keep.
Nothing on that list requires a consultant for a company of ten, and doing it in that order means each step tells you something you need for the next. Listing the vendors is what usually produces the surprises.
Then keep it alive with two habits. Review the record when you add a tool, which is the moment the answer changes, and delete on schedule rather than when storage runs out. A company that can show what it holds, why, and for how long has the substance of compliance, whatever the paperwork looks like.
Frequently Asked Questions
Does a Small Latvian Company Have to Follow GDPR?
Yes, from the first person whose data it holds. There is no employee or turnover threshold for the Regulation itself. The size test in article 30 applies only to records of processing, and it falls away where processing is regular rather than occasional, which employee payroll data always is.
Who Do You Report a Data Breach to in Latvia?
The Datu valsts inspekcija, within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Where the risk to the individuals is high, you tell them as well. A late notification with reasons is provided for; not notifying at all is not.
Does a Latvian Startup Need a Data Protection Officer?
Usually not. One is required only for public authorities, for large scale regular monitoring, or for large scale special category data. If you appoint one voluntarily, the Regulation's protections and duties attach, and Latvia keeps a list of specialists containing only people who have passed the qualification examination.
What Age Can a Child Consent to an App in Latvia?
13 years. The Regulation lets member states pick anywhere from thirteen to sixteen for information society services, and Latvia took the lowest. Below that, a parent or guardian consents. Other member states set it higher, so a service sold across Europe should design to the strictest threshold it faces.
What Does a Camera Sign Have to Say in a Latvian Office?
At least the controller's name, its contact details, the purpose of the processing, and how to get the rest. That is the Personal Data Processing Law's minimum for a video surveillance sign. The sign is only the notice: you also need a lawful basis, a purpose, a retention period, and a decision on who may view the footage.
Sources
- Fizisko personu datu apstrādes likums, the Personal Data Processing Law. Articles 3 to 5 establish the Inspectorate and its powers, article 15 inspections, articles 17 to 19 the data protection specialist and the qualification examination, article 33 a child's consent, article 36 video surveillance, and articles 38 and 39 the administrative offences and who prosecutes them.
- Regulation (EU) 2016/679, the General Data Protection Regulation. Article 28 processor contracts, article 30 records of processing, articles 33 and 34 breach notification, article 37 when an officer is required, and article 83 the fine tiers.
- Administratīvās atbildības likums, for the value of a penalty unit.
- Datu valsts inspekcija, for its guidance, its annual reports, and the list of data protection specialists.
Every Figure, and When It Was Checked
Each value links to the source it was taken from. The date is when that source was last read and matched. Where a source cannot be checked automatically, it says so.
| Figure | Value | Last checked |
|---|---|---|
| The age at which a child may consent to an information society service in Latvia without a parent | 13 years | 15 September 2026 |
| What a video surveillance information sign must state at a minimum | the controller's name, its contact details, the purpose of the processing, and how to get the rest | 15 September 2026 |
| Who the Data State Inspectorate enters on its list of data protection specialists | only people who have passed the qualification examination | 15 September 2026 |
| The maximum fine on an official of a public law legal person for unlawful acts with personal data | 200 penalty units | 15 September 2026 |
| Value of one penalty unit | EUR 5 | 11 September 2026 |
| The upper fine tier in article 83 of the General Data Protection Regulation | EUR 20 million, or 4% of worldwide annual turnover, whichever is higher | 15 September 2026, by hand |
| The lower fine tier in article 83 of the General Data Protection Regulation | EUR 10 million, or 2% of worldwide annual turnover, whichever is higher | 15 September 2026, by hand |
| Time from becoming aware of a personal data breach within which the supervisory authority must be notified | 72 hours | 15 September 2026, by hand |