Saturday, 19 September 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 19 September 2026 at 16:50

Lawyer: Transport Ministry report strengthens compensation claims over CSDD data leak

Attorney Lauris Klagišs says a newly published Transport Ministry assessment officially confirms security failures at Latvia's road traffic agency CSDD, providing strong grounds for people seeking compensation over August's data breach.

Foto: Latvijas Avīze

Following the data leak at Latvia's Road Traffic Safety Directorate (CSDD), public discussion continues over residents' chances of obtaining compensation. Attorney Lauris Klagišs wrote on Facebook that a newly published Transport Ministry assessment of the CSDD cyber incident provides strong legal grounds for those planning or already pursuing compensation claims.

According to Klagišs, claimants no longer need to wait for a ruling from the State Data Inspection to prove the agency's negligence, since the ministry's assessment already documents serious data-protection violations.

Failures identified

The Transport Ministry's assessment found that CSDD made multiple errors and omissions in its cybersecurity management, at times taking only a formal approach. The breach originated from a vulnerability in CSDD's web application med.csdd.lv. Investigators also found incomplete security-check coverage, inadequate network protection, and a lack of multi-factor authentication. The system lacked sufficient controls to monitor request volumes and detect anomalies, allowing the attacker to extract data extensively over a prolonged period.

The attack resulted in the theft of data belonging to approximately 1.15 million individuals and up to 200,000 legal entities. The assessment also found that historical personal data had been retained for an unnecessarily long time, which the lawyer describes as a clear violation of data-processing principles.

Outsourcing oversight questioned

The ministry's commission also highlighted problems with oversight of outsourced services, noting that a professional security monitoring provider would normally be expected to detect and limit unusual, prolonged data activity in time to prevent mass extraction. Klagišs said this is why he had previously filed official freedom-of-information requests seeking the IT infrastructure procurement contract between CSDD and TET, arguing that responsibility for a breach of this scale must be examined down to its roots.

The lawyer stressed that the ministry's findings are now officially documented evidence of the agency's negligence and provide a solid basis for pursuing compensation claims in civil disputes.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category