## What Happened? A recent cyberattack on CSDD has become one of the most serious information security incidents in the history of the state. The President of Latvia has already called this large-scale data leak a significant threat to national security. From August 8 to 10, 2026, the perpetrators managed to obtain historical payment receipt data dating back to 2008. The incident affects 1.2 million individuals and 200,000 legal entities. Since a vast amount of personal information is at risk in this case, it is crucial for each person as a data subject to understand their rights under the EU General Data Protection Regulation (GDPR/VDAR) and know what actions can be taken. It is likely that highly sensitive personal data has fallen into the hands of cybercriminals: name and surname, personal code, vehicle registration number, registered address, as well as payment information. Cybersecurity experts warn that the main danger lies not so much in the fact of the breach itself, but in how this data will be used further. It may circulate on the black market for a long time. Criminals can use this information to create extremely convincing personalized phishing attacks — for example, sending fake fines that accurately state the person's name and the state registration number of their vehicle. There is also a high risk of attempts to send users fake confirmation requests via Smart-ID or eParaksts mobile. If a person confirms such a request, it could lead to serious financial consequences. ## ## How to Know if Your Data Was Leaked? "You do not need to live in ignorance." According to Article 15, Part 1, and Article 34 of the GDPR, you have the right to directly contact CSDD and demand a clear answer: - whether your data was stolen; - which specific categories of data are affected; - whether, for example, your personal code and address were leaked. CSDD is obliged to respond without undue delay, usually within one month. This information should be provided free of charge. ## ## Can Compensation Be Demanded? If you have incurred real financial losses due to the data leak — for example, if you became a victim of fraud directly as a result of this leak — or if you suffered significant non-material (moral) damage, Article 82 of the GDPR provides the right to demand compensation from CSDD. However, compensation is not paid automatically. When making a claim, it will be necessary to legally justify the violation on the part of CSDD — for example, proving that adequate protection of information systems was not ensured. Additionally, it is necessary to prove the damage incurred and a clear causal link between the data leak and the consequences that followed. ## ## What to Do If CSDD Does Not Respond? If CSDD does not provide a clear answer, delays in providing information, or if you are dissatisfied with the institution's actions regarding data protection, Article 77 of the GDPR allows you to file an official complaint with the Data State Inspectorate (DVI). If a dispute arises over the recovery of damages, according to Article 79 of the GDPR, the data subject has the right to go to court. ## ## What Do They Recommend Doing Now? To obtain specific information about your data, you should send an official request to the CSDD data protection specialist at the email datu.specialists@csdd.gov.lv and request individual information about the processing of your data and existing risks. If after this incident you start receiving: - suspicious SMS; - calls from fraudsters; - bills or fines supposedly sent by CSDD, be sure to save screenshots, call logs, and all related documents. They may become extremely important evidence of causation if you decide to file a claim for damages. Under no circumstances should you confirm Smart-ID or e-Paraksts requests that you did not initiate on your device. ## ## What Is Known About the Attack Itself? As previously reported, the Deputy Head of the Cyber Incident Prevention Institution Cert.lv, Varis Teivans, stated that as a result of the cyberattack on CSDD, personal data of 1.2 million individuals and approximately 200,000 legal entities were obtained. This concerns data related to payments made to CSDD over the past 18 years. According to Teivans, the investigation established that the attack occurred by exploiting a vulnerability in the internet-accessible CSDD system. Furthermore, several requirements of the Cabinet of Ministers applicable to class A information systems were not met, including requirements for multi-factor authentication and conducting penetration tests.