Utilizziamo cookie tecnici per personalizzare il sito web e offrire all’utente un servizio di maggior valore. Chiudendo il banner e continuando con la navigazione verranno installati nel Suo dispositivo i cookie tecnici necessari ai fini della navigazione nel Sito. L’installazione dei cookie tecnici non richiede alcun consenso da parte Sua. Ulteriori informazioni sono contenute nella nostra Cookie Policy.



Citizen data leak from the municipality system in Latvia

PrintMailRate-it

​​​​​​published on 15 January 2025 | reading time approx. 4 minutes


In autumn of 2024 in Latvia a citizens personal data leak from the Unified municipality information system was found. In the time period from 29th of October to 2nd of November unauthorised persons had the ability to access a search index which had partly duplicated municipality data. This data included personal information about citizens and municipality employees, including their names, surnames, personal identification numbers and residential addresses, as well as, in the case of municipality employees, their job titles and email addresses. 

This municipality data is maintained and stored in its information system managed and saved by a vendor, private company providing respective services. Director of this company commented on this matter saying that the documents stored in the system were not illegally obtained, corrected or deleted. Immediately after becoming aware of the incident, measures were taken to improve security and remedy the incident, however, at the moment it is not clear for what purposes the data could be used and what damage this could cause to the data subjects. Nevertheless, one of few conclusions indicated that with such data it will be possible to more specifically launch fraud campaigns against citizens, knowing specific personal data about them.

The municipalities have reported the incident to the State Data Inspectorate, which is investigating the incident to establish the circumstances of the case and the causes of the leak. As regards the responsible parties, it should be mentioned that the system developer is only a data processor, therefore, based on the GDPR provisions, the responsibility for choosing a cooperation partner and setting standards to ensure that personal data is processed securely lies with the municipalities where the data leak occurred. Although the investigation of the situation by the State Data Inspectorate is still ongoing, it can be concluded that the personal data of people was not sufficiently protected and that a breach was committed for which liability will be incurred.

In February 2024, the Norwegian Data Protection Authority also faced a data breach by a municipality. In this case, personal data was made available to unauthorised persons in the municipality's public mail log.

The leak resulted in the publication of individual decisions of pupils of Grue municipality, which contained information such as pupils' names, dates of birth, personal identification number, as well as the telephone numbers and addresses of the parents of the pupils. In total, 14 pupils and their parents were affected by this infringement. The Norwegian Data Protection Authority, taking into account the circumstances of the case and the fact that the municipality informed the Data Protection Authority as soon as possible about the infringement as well as the persons affected, decided to fine the municipality EUR 20 800,00. This is not the only case of a Norwegian municipality being fined for insufficient data protection of student data. 

In March 2019, the Norwegian Data Protection Authority imposed an administrative fine of EUR 170 000,00 on the municipality of Bergen in connection with the publication of the municipality's student data. The data released included usernames, passwords, dates of birth, addresses, as well as schools and classes of the persons concerned. School work and teachers' evaluations of pupils were also available. The breach described affected 35 000 persons.

On the basis of the cases reviewed and those already closed, it can be concluded that also in the case of the Latvian 2024 personal data leak, a decision is expected which will provide for an monetary penalty for the GDPR infringements committed, the penalty being of course determined taking into account the circumstances of the specific case, but at the same time, considering that this leak concerns all Latvian municipalities, except capital city Riga, then the number of affected persons could potentially exceed 1 million people. This, in turn, indicates a possible new imposition of the largest penalty in Latvian history.

DATA PROTECTION BITES

AUTHOR

Contact Person Picture

Staņislavs Sviderskis

Assistant Attorney at law, Cyber & Information Security Expert

Senior Associate

+371 6733 8125

Invia richiesta

RÖDL & PARTNER LATVIA

Discover more about our offices in Latvia. 
Skip Ribbon Commands
Skip to main content
Deutschland Weltweit Search Menu