EU judge says CSDD data breach victims deserve compensation
Wednesday 26th August 2026 on 08:15 in
Latvia
All 1.2 million people whose data was stolen in a cyberattack on Latvia’s Road Traffic Safety Directorate have the right to compensation for moral harm, European Union Court of Justice Judge Ineta Ziemele told Latvian Television’s Rīta Panorāma, LSM reported.
Ziemele said people’s human rights had already been violated and that they did not need to wait for anyone to misuse the stolen data. She said the responsible institutions, rather than individual residents, should decide how compensation is provided.
“The right to protection of personal data is one of the central values of the European Union, including Latvia. Data is part of our identity,” Ziemele said, adding that those who obtained the information had gained enormous value.
She said that because the incident could have been avoided by the Road Traffic Safety Directorate, residents had the right to receive information about what data had been stolen, rather than having to request it individually.
“We all have the right to claim compensation for moral harm, without yet discussing compensation for losses. If we consider a name, surname and personal identity number elements of our identity, then harm has already been caused to us,” Ziemele said.
However, she said the state would not have enough resources to handle the volume of cases if everyone turned to the administrative courts. She urged the responsible institutions to consider creative ways of addressing the issue, such as waiving technical inspection fees now and in the future.
“I am somewhat surprised by how calm we are in cases when citizens’ rights are violated,” Ziemele said.
In the first half of August, hackers gained unauthorised access to the personal data of 1.2 million people and the registration numbers of about 150,000 legal entities through a cyberattack on the directorate’s information technology system. The data came from payments made to the directorate over the previous 18 years.
Latvia’s cyber-incident prevention institution Cert.lv said the attack exploited a vulnerability in the directorate’s internet-accessible system and that several mandatory cybersecurity requirements had not been followed. The incident was reported late.
Latvia’s State Police has opened criminal proceedings over the cyberattack. The State Chancellery’s Crisis Management Centre, working with Cert.lv, has been tasked with creating a working group to address the consequences of the incident.