The head of the communication department of CSDD, Mārtiņš Malmeisters, reported that compensation claims have been sent to various email addresses of the agency. Each request has been responded to individually by the directorate. Additionally, CSDD has received official statements signed with an electronic signature. According to Malmeisters, claimants most often demand compensation of around 10,000 euros. A representative of CSDD emphasized that the investigation into the cyberattack is ongoing. The question of possible compensation payments for the acquisition of personal data from the directorate's information system will primarily depend on the decision of the Data State Inspectorate. The inspectorate will need to determine whether CSDD is liable for non-compliance with the General Data Protection Regulation of the European Union. According to the regulation, an individual may receive compensation if it is proven that CSDD failed to fulfill its legal obligations and as a result of this violation, the person suffered harm. Malmeisters stressed that at this stage, it is premature to demand compensation. Clients will be informed of further steps after relevant decisions are made. At the same time, CSDD continues to assess additional measures that can be taken to mitigate potential damage caused by the data leak. As previously reported, as a result of the cyberattack on CSDD in early August, attackers obtained personal data of 1.2 million individuals, as well as information about approximately 200,000 legal entities. The data was obtained from information about payments made to the directorate over the past 18 years. Following calls from several officials to resign, both the board and the council of CSDD made this decision. Latvian Minister of Transport, Rihards Kozlovskis, initiated an official investigation to be conducted on an expedited basis. Its goal is to establish all circumstances of the cyberattack and the large-scale data leak, as well as to identify those responsible. As part of the investigation, among other things, the contract between CSDD and the company Tet for cybersecurity services will need to be evaluated. The Prosecutor General's Office has also initiated a prosecutorial review of possible violations or negligence that could have led to the data leak from CSDD's information systems. The State Police, in turn, has opened a criminal case regarding the cyberattack. The final decision on the possibility of receiving compensation will depend on the conclusions of the Data State Inspectorate and the results of the investigations. The mere fact of a leak is not enough: claimants will need to prove a violation by CSDD and the harm caused to them.