Lawyer: €10,000 compensation not automatic after CSDD data breach
After a cyberattack on Latvia's road traffic agency CSDD affected around 1.2 million residents, lawyer Edijs Liepiņš explains that a data leak alone does not automatically entitle victims to compensation — it must be proven in court.

Following a cyberattack on the Register module managed by Latvia's Road Traffic Safety Directorate (CSDD), which affected roughly 1.2 million residents, calls have spread on social media urging people to immediately demand €10,000 in compensation from the agency, creating the impression that such a payout is almost automatically owed to anyone whose data ended up in third parties' hands. Lawyer Edijs Liepiņš told LA.LV that this assumption does not align with case law of the Court of Justice of the European Union (CJEU) or the General Data Protection Regulation (GDPR).
What EU case law says
Citing a CJEU ruling from 14 December 2023 involving Bulgaria's National Revenue Agency, where a cyberattack exposed data of more than 6 million people online, Liepiņš notes that a data leak or unauthorized third-party access does not by itself prove the data controller failed to meet security obligations. The controller always has the right to prove otherwise, and can be released from liability if it shows it was not responsible for the incident.
In a separate case involving an Austrian postal company that processed data on individuals' political sympathies without consent, the CJEU found that a GDPR violation alone does not automatically create a right to compensation.
Three conditions for compensation
According to the lawyer, filing a compensation claim requires three conditions to be met simultaneously: a GDPR violation must have occurred, the data subject must have suffered actual harm, and there must be a direct causal link between the two. Concerns about possible future misuse of data can qualify as non-material damage, but must be substantiated by the specific circumstances, and the burden of proof lies with the affected person.
Liepiņš also points out that much basic personal information is already legally and publicly available in state-maintained registers, such as the public database of the Enterprise Register — a factor worth considering before filing a court claim. He predicts that as artificial intelligence advances, such complex cyberattacks will become more frequent, requiring greater attention to data protection from both state institutions and businesses.
/nginx/o/2026/09/04/17896653t1h2533.png)
/nginx/o/2026/09/02/17891026t1h26d6.jpg)
