New security rules for information systems and data centres take effect in Latvia
New Cabinet of Ministers regulations setting security requirements for hosting information systems and for data centres have applied in Latvia since 1 October. They cover entities under the National Cybersecurity Law.
New Cabinet of Ministers regulations governing where information systems are hosted and setting security requirements for data centres came into force in Latvia on 1 October 2026.
A unified standard
The document lays down a single set of requirements for entities that fall under the National Cybersecurity Law (NKDL). These entities must now organise the operation of their information systems and the security of their data centres in line with the new rules.
What the rules cover
The regulations address several areas:
- maintenance of information systems;
- physical security of data centres;
- digital security of data centres;
- compliance checks;
- transfer of telemetry data to the authorities responsible for preventing cyber incidents.
Geographical framework
According to the source, the new regulation introduces a clear geographical framework for hosting information systems. The available excerpt does not provide further detail on this part.
In this way, the new rules bring together requirements for system maintenance and data centre protection in one place, while also providing for compliance verification and data sharing with cybersecurity authorities.