Expert: Compensation after CSDD data leak can be sought before DVI ruling
Following a cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) that resulted in a data leak, affected people do not need to wait for the Data State Inspectorate's (DVI) review to conclude before seeking compensation, a legal expert says.

People affected by a data leak stemming from a cyberattack on the Road Traffic Safety Directorate (CSDD) can pursue compensation claims without waiting for the Data State Inspectorate (DVI) to complete its investigation, according to Viktorija Soņeca, a researcher at the University of Latvia's Faculty of Law and an expert in European Union law.
According to Soņeca, the option to seek redress for damages already exists now, and affected individuals do not have to wait until the DVI finishes assessing how the incident occurred and whether CSDD violated data protection requirements.
What happened
CSDD was targeted by a cyberattack that resulted in a leak of personal data held by the institution. The incident has raised concerns among affected residents about how any resulting harm will be compensated and what procedure applies in such cases.
The DVI is currently conducting a review to establish the circumstances of the incident and the institution's responsibility. However, as the expert stresses, the conclusion of that process is not a precondition for individuals to file a compensation claim.

/nginx/o/2026/09/02/17890806t1h5cc9.jpg)
