Palkova emphasized that the state is obliged not only to respond to already occurred leaks and cyberattacks but also to proactively identify risks. According to her, the protection of personal data begins at the stage of deciding what information to collect, how long to store it, and how to protect it. The ombudsman calls for particular attention to systems that process health data and personal data of children. In particular, this concerns the E-veselība and E-klase systems. The consequences of a leak of such information, in Palkova's opinion, could be especially serious. The statement was prompted by several recent incidents involving data security. The most significant of these was a cyberattack on the Road Traffic Safety Directorate (CSDD), as a result of which attackers obtained data on approximately 1.2 million individuals and about 200,000 legal entities. In connection with this incident, the Data State Inspectorate (DVI) continues its investigation, and several inquiries are underway. The ombudsman recommends that state institutions check the procedure for granting access rights to information systems, the regularity of their security checks, the control of data circulation, as well as mechanisms for timely detection and resolution of incidents. Palkova also considers close cooperation with the Data State Inspectorate, the National Cyber Security Centre, CERT.LV, and operators of the relevant information systems to be necessary. Another incident occurred this week at the Consumer Rights Protection Centre (PTAC). A security breach was discovered in the ASDIS system for remote statistical data retrieval. According to preliminary data, attackers obtained contact information for representatives of 697 enterprises and 34 officials from PTAC — names, surnames, email addresses, and phone numbers. At the same time, data directly related to the supervision of enterprises was not affected, and a significant portion of the obtained information is already available in open state registers. The ASDIS system is currently disabled. The Data State Inspectorate notes that based on the available information, there are currently no grounds to consider the incident at PTAC as posing a high risk to citizens' rights.