Riga Startups

What Data Protection Actually Requires of a Latvian Startup

By Deepti Gupta · Reviewed by Vinayak Ravi · Riga Startups Editorial Team

Last verified · every figure links to its source, and the date each was checked is listed at the end · 12 min read

A Latvian startup is processing personal data from its first employee and its first customer, which means the General Data Protection Regulation applies from day one and not from some later size. Most of what it asks for is documentation you should want anyway. This covers what applies here, what Latvia has added on top of the Regulation, and what the Data State Inspectorate does about it.

Cover for What Data Protection Actually Requires of a Latvian Startup

This is the ordinary case for a small Latvian company handling employee and customer data. It is not advice on a particular processing operation, and anything involving health data, biometrics, large scale monitoring, or profiling that decides something about a person needs proper counsel. The Regulation is EU law and applies in every member state; only the Latvian additions are specific to here.

Does GDPR Apply to a Latvian Startup?

From the first person whose data you hold. There is no employee threshold and no turnover threshold. A company with one founder and a mailing list is a controller with the full set of obligations, and the parts that scale with size are the paperwork and the risk rather than whether the Regulation reaches you.

The confusion usually comes from article 30, which does carry a size test for records of processing, and which is widely misread as a general exemption for small companies. It is not one, and the test has holes big enough that most startups fall outside it anyway.

What applies immediately, whatever your size:

Who Enforces Data Protection in Latvia?

The Datu valsts inspekcija, the Data State Inspectorate. The Personal Data Processing Law sets it up, gives it the Regulation's investigative and corrective powers, and lets it inspect a place where processing happens. Its decisions can be contested and then appealed to the administrative court.

An inspection is not a dawn raid, but it does not need your cooperation either.

The Inspectorate also publishes guidance and an annual report, and answers questions in advance. For a small company that is the cheaper interaction, and it is available before something goes wrong rather than after.

Does a Latvian Startup Need a Data Protection Officer?

Usually not, and Latvia adds a wrinkle if you appoint one anyway. The Regulation requires an officer only where processing is by a public authority, or where core activities involve regular and systematic monitoring of people on a large scale, or large scale processing of special category data.

For an ordinary Latvian startup none of those is true, and appointing an officer is a choice rather than a duty. Two things are worth knowing before making it.

The sensible middle for a startup is to give one named person the responsibility internally, without calling them a data protection officer, and to buy advice when something unusual arrives.

What Records of Processing Must a Latvian Company Keep?

Assume you need them. Article 30 of the Regulation exempts organisations under 250 employees, then withdraws the exemption where processing is likely to result in a risk to people, is not occasional, or includes special category data. Employee payroll data alone is regular rather than occasional.

The record is an internal document and nobody asks to see it until they do, at which point its absence is the first thing on the list.

What it holds is not onerous: the purposes of each processing activity, the categories of people and data, who receives the data, any transfer outside the EU, retention periods where you can state them, and a general description of your security measures. For a company of ten that is a page or two, and writing it usually surfaces something nobody had noticed, most often an old tool still holding data for a purpose that ended.

The work is in keeping it current. Tie it to something that already happens, such as reviewing it whenever you add a vendor, rather than to a date nobody will remember.

What Do You Do When Personal Data Leaks in Latvia?

Notify the Inspectorate within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Where the risk to individuals is high, tell them too, without undue delay. A breach is broader than a hack and includes loss, accidental deletion, and sending data to the wrong recipient.

The clock is the part that catches companies, because it runs from awareness rather than from the end of your investigation.

Decide in advance who makes the call, because discovering a breach at seven on a Friday is not the moment to work out who is allowed to speak to a regulator.

13 years. The Regulation lets each member state set the threshold for information society services anywhere between thirteen and sixteen, and Latvia chose the lowest. Below that age the consent has to come from a parent or legal guardian, and your service has to make a reasonable effort to check.

This matters to any consumer product a teenager might plausibly sign up for, and it matters more than it looks because the age differs across the Union. A service available in Latvia and Germany faces two different thresholds for the same sign-up form, which is an argument for designing to the highest one you are exposed to rather than to the local minimum.

It also bites only where you are relying on consent. A service provided to the child under a contract, with a different lawful basis, is a different analysis, and one worth doing properly before building an age gate.

What Are the Rules for Cameras in a Latvian Office?

Latvia sets its own minimum for the sign. Where a controller uses an information sign for video surveillance, the Personal Data Processing Law requires it to state the controller's name, its contact details, the purpose of the processing, and how to get the rest. Household use is outside the rules, and that exception does not stretch to an office.

A camera in a workplace is processing employee data continuously, which puts it among the harder things a small company does.

What Can Getting Data Protection Wrong Cost in Latvia?

The Regulation's two tiers apply here as everywhere: up to EUR 10 million, or 2% of worldwide annual turnover, whichever is higher for most obligations, and up to EUR 20 million, or 4% of worldwide annual turnover, whichever is higher for breaching the principles, people's rights, or the transfer rules. Latvia's own penalties reach public officials, not companies.

The ceilings are not the realistic number for a startup, and quoting them at each other is how companies end up buying compliance theatre. The fine is set by reference to the nature and gravity of the infringement, the number of people affected, whether it was negligent or deliberate, what you did to mitigate, and whether you reported it yourself.

What Should a Latvian Startup Do First?

Five things, in order, and all of them are documents rather than software. Write the record of processing, list every vendor touching personal data and check you have terms with each, publish a privacy notice people can read, decide who handles a breach and a data subject request, and set retention periods you can actually keep.

Nothing on that list requires a consultant for a company of ten, and doing it in that order means each step tells you something you need for the next. Listing the vendors is what usually produces the surprises.

Then keep it alive with two habits. Review the record when you add a tool, which is the moment the answer changes, and delete on schedule rather than when storage runs out. A company that can show what it holds, why, and for how long has the substance of compliance, whatever the paperwork looks like.

Frequently Asked Questions

Does a Small Latvian Company Have to Follow GDPR?

Yes, from the first person whose data it holds. There is no employee or turnover threshold for the Regulation itself. The size test in article 30 applies only to records of processing, and it falls away where processing is regular rather than occasional, which employee payroll data always is.

Who Do You Report a Data Breach to in Latvia?

The Datu valsts inspekcija, within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Where the risk to the individuals is high, you tell them as well. A late notification with reasons is provided for; not notifying at all is not.

Does a Latvian Startup Need a Data Protection Officer?

Usually not. One is required only for public authorities, for large scale regular monitoring, or for large scale special category data. If you appoint one voluntarily, the Regulation's protections and duties attach, and Latvia keeps a list of specialists containing only people who have passed the qualification examination.

13 years. The Regulation lets member states pick anywhere from thirteen to sixteen for information society services, and Latvia took the lowest. Below that, a parent or guardian consents. Other member states set it higher, so a service sold across Europe should design to the strictest threshold it faces.

What Does a Camera Sign Have to Say in a Latvian Office?

At least the controller's name, its contact details, the purpose of the processing, and how to get the rest. That is the Personal Data Processing Law's minimum for a video surveillance sign. The sign is only the notice: you also need a lawful basis, a purpose, a retention period, and a decision on who may view the footage.

Sources

Every Figure, and When It Was Checked

Each value links to the source it was taken from. The date is when that source was last read and matched. Where a source cannot be checked automatically, it says so.

FigureValueLast checked
The age at which a child may consent to an information society service in Latvia without a parent13 years15 September 2026
What a video surveillance information sign must state at a minimumthe controller's name, its contact details, the purpose of the processing, and how to get the rest15 September 2026
Who the Data State Inspectorate enters on its list of data protection specialistsonly people who have passed the qualification examination15 September 2026
The maximum fine on an official of a public law legal person for unlawful acts with personal data200 penalty units15 September 2026
Value of one penalty unitEUR 511 September 2026
The upper fine tier in article 83 of the General Data Protection RegulationEUR 20 million, or 4% of worldwide annual turnover, whichever is higher15 September 2026, by hand
The lower fine tier in article 83 of the General Data Protection RegulationEUR 10 million, or 2% of worldwide annual turnover, whichever is higher15 September 2026, by hand
Time from becoming aware of a personal data breach within which the supervisory authority must be notified72 hours15 September 2026, by hand