Lawyer: Transport Ministry report strengthens compensation claims over CSDD data leak
Attorney Lauris Klagišs says a newly published Transport Ministry assessment officially confirms security failures at Latvia's road traffic agency CSDD, providing strong grounds for people seeking compensation over August's data breach.

Following the data leak at Latvia's Road Traffic Safety Directorate (CSDD), public discussion continues over residents' chances of obtaining compensation. Attorney Lauris Klagišs wrote on Facebook that a newly published Transport Ministry assessment of the CSDD cyber incident provides strong legal grounds for those planning or already pursuing compensation claims.
According to Klagišs, claimants no longer need to wait for a ruling from the State Data Inspection to prove the agency's negligence, since the ministry's assessment already documents serious data-protection violations.
Failures identified
The Transport Ministry's assessment found that CSDD made multiple errors and omissions in its cybersecurity management, at times taking only a formal approach. The breach originated from a vulnerability in CSDD's web application med.csdd.lv. Investigators also found incomplete security-check coverage, inadequate network protection, and a lack of multi-factor authentication. The system lacked sufficient controls to monitor request volumes and detect anomalies, allowing the attacker to extract data extensively over a prolonged period.
The attack resulted in the theft of data belonging to approximately 1.15 million individuals and up to 200,000 legal entities. The assessment also found that historical personal data had been retained for an unnecessarily long time, which the lawyer describes as a clear violation of data-processing principles.
Outsourcing oversight questioned
The ministry's commission also highlighted problems with oversight of outsourced services, noting that a professional security monitoring provider would normally be expected to detect and limit unusual, prolonged data activity in time to prevent mass extraction. Klagišs said this is why he had previously filed official freedom-of-information requests seeking the IT infrastructure procurement contract between CSDD and TET, arguing that responsibility for a breach of this scale must be examined down to its roots.
The lawyer stressed that the ministry's findings are now officially documented evidence of the agency's negligence and provide a solid basis for pursuing compensation claims in civil disputes.


/nginx/o/2026/09/15/17919353t1h1bcc.png)