Semjonovs: CSDD data leak accountability should not wait, board and council responsible
Following the massive CSDD data leak, journalist Sandijs Semjonovs argues that those responsible should be held accountable now rather than waiting for the investigation to conclude. He notes the first compensation claim, for 10,000 euros, has already been filed.

Following the large-scale data leak at Latvia's Road Traffic Safety Directorate (CSDD), public discussion is intensifying over whether affected individuals will be entitled to compensation. No official clarity exists yet, as both a criminal investigation and a review by the State Data Inspectorate are still underway. The Transport Ministry has said that any decision on compensation will largely depend on the Data Inspectorate's findings, noting that an individual could receive compensation only if it is established that CSDD failed to meet its legal obligations and that this caused harm to the person.
Semjonovs' position
Speaking on the TV24 programme "Preses klubs," journalist and "Klimata balss" host Sandijs Semjonovs argued that waiting is not justified. In his view, if the state was unable to protect citizens' data, those responsible should answer for it immediately rather than only after a lengthy investigation.
Semjonovs pointed out that a first claim has already been filed — a lawyer named Zalāns has reportedly submitted a claim for 10,000 euros in compensation. Semjonovs said he expects the case to prove interesting to follow.
Who should be held responsible
Semjonovs believes the question of accountability should be viewed far more broadly than it currently is. He argued that particular attention should be paid to CSDD's management, since it is responsible for the company's operations and for ensuring data security. He suggested that any claims should be directed at CSDD's board and supervisory council, arguing that these bodies should bear responsibility for what happened.
Background on the cyberattack
The cyberattack on CSDD's IT system took place in early August. It resulted in the theft of personal data belonging to roughly 1.2 million individuals, as well as data on around 200,000 legal entities, covering payments made to CSDD over an 18-year period. Following the incident, both CSDD's board and supervisory council resigned. An investigation into the circumstances of the attack and possible liability is ongoing.
/nginx/o/2026/09/04/17895131t1h279b.jpg)

/nginx/o/2026/09/04/17895895t1hb241.jpg)