Legal experts: who can be held personally liable for the CSDD cyberattack?
Following a cyberattack on Latvia's road safety agency CSDD that exposed data of some 1.2 million people, legal experts explain that not only the institution but also specific employees and executives could face personal, including criminal, liability. The case is now with the Data State Inspectorate and State Police.

A cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) in early August, which resulted in the theft of personal data belonging to roughly 1.2 million people, has become one of the most serious known data breaches in Latvia. Following sharp criticism from the prime minister and the president, both the CSDD board and council resigned, but experts note that resignation alone does not settle the legal question of accountability.
The Data State Inspectorate is now reviewing the matter, while the State Police has opened a criminal proceeding against the attacker. President Edgars Rinkēvičs has asked the prosecutor general to examine the conduct of CSDD officials.
When an individual, not just the institution, is liable
Latvia's Criminal Law holds a person responsible for information system security if they were tasked with ensuring compliance and a breach led to data destruction, damage, theft, or substantial harm. Penalties range up to one year of imprisonment, or up to three years in cases of severe consequences. Someone can be deemed a "responsible person" not only by formal job title but also by the duties they actually carried out.
A precedent already exists: after a 2024 breach in the unified municipal information system, police sought criminal prosecution of the system administrator at the company managing it — the first such case in Latvia.
Particularly high liability tends to fall on board members, who, unlike in ordinary cases, must themselves prove they acted with due care. Outsourcing IT maintenance does not remove the client's own legal obligations, and an outsourced provider's employee could also bear personal responsibility.
Sometimes no one is held liable
If an attack exploited an unknown, unforeseeable vulnerability, or if all required security measures were properly in place, no individual may end up personally liable, while the organization's liability is assessed separately.
Since April 16, penalties for such violations have been increased. In the CSDD case, it has been publicly reported that requirements for penetration testing and multi-factor authentication were not met, though only the ongoing investigation will determine personal liability.
/nginx/o/2026/08/20/17859524t1h5642.jpg)

