Latvia - Data Governance Strategy

National Data Governance Strategy

Nacionālā datu pārvaldības stratēģija

Latvia

RAI-LV-NA-NDGSNXX-2024
Draft(Being written or scoped)
PolicyGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

A national-level strategy to establish a coherent data governance framework in Latvia, currently in draft/development. The strategy aims to create institutional arrangements, technical infrastructure (including the DAGR platform), legal instruments and oversight mechanisms to enable secure, privacy-preserving data sharing across the public sector and with the economy, aligned with EU data policy.

Summary

The National Data Governance Strategy (Nacionālā datu pārvaldības stratēģija) is a draft strategic policy framework that sets out Latvia's vision, principles and high-level measures for managing, sharing and governing public-sector and high-value datasets at national scale. The Strategy builds on Latvia’s Digital Transformation Guidelines 2021–2027 and the associated Implementation Plan (Ministerial Cabinet act, 13 December 2023) that identifies the Datu izplatīšanas un pārvaldības platforma (DAGR — national data distribution and governance platform) as a central instrument to enable data re-use, auditability and personal data control. The draft strategy (in development) scopes institutional responsibilities — designating the Ministry of Environmental Protection and Regional Development (VARAM) as a coordinating body for data governance policy measures and identifying implementing agencies (for example the Valsts reģionālās attīstības aģentūra (VRAA) as the DAGR operator) and supervisory bodies such as the Data State Inspectorate (Datu valsts inspekcija, DVI).

Core aims include: (1) establishing a national data governance model and legal framework (including consideration of a Data Governance Act or amendments to existing legislation); (2) defining high-value dataset lists and metadata/format standards to improve interoperability; (3) creating technical and organisational safeguards for personal data, including audit trails, logging and consent/permission mechanisms within the DAGR; (4) strengthening cybersecurity and federated cloud infrastructure to host and process data; (5) improving the public sector’s data capabilities and workforce; and (6) aligning national rules with EU instruments (Data Governance Act, GDPR, NIS2, Digital Decade objectives and EU data spaces initiatives).

The Implementation Plan adopted by the Cabinet sets concrete tasks and timelines (for example the DAGR technical and audit features were listed for delivery in 2023–2026 planning documents, and wider platform interoperability tasks are scheduled through 2027). The draft Strategy emphasises privacy-by-design, human-rights safeguards and transparent accountability — requiring data stewardship roles within agencies, DPIA-like assessments for high-risk processing, logging and monitoring of dataset access, and public reporting on data uses.

Although not a binding law itself, the Strategy is intended to serve as the basis for subsequent regulatory and secondary-norm measures: new Cabinet rules, ministerial regulations, model contracts, and possible legislative proposals (a “Data Governance Act” or targeted amendments to information governance and open-data legislation). Key stakeholder groups include central ministries, data-holding authorities, supervisory and oversight bodies (DVI, CERT.LV), local governments and the private sector. The Strategy as drafted explicitly references and seeks alignment with the Digital Transformation Implementation Plan and DAGR project documents and will be subject to public consultation and ministerial approval processes before formal adoption.

Full article

Read full text ↗

Overview

The draft National Data Governance Strategy (Nacionālā datu pārvaldības stratēģija) is a policy-level instrument under development that aims to create a unified, principled and practical framework for managing, sharing and securing government-held data in Latvia. The Strategy is positioned as the national umbrella for operational measures already signalled in the Cabinet-approved Digital Transformation Implementation Plan 2023–2027 and the broader Digital Transformation Guidelines 2021–2027. At its core the Strategy promotes: interoperability and standards for high-value datasets; trustworthy technical infrastructure (notably the DAGR platform); clear institutional roles for coordination and oversight; and privacy and rights protections for individuals. The Strategy is being developed to align Latvia’s national data governance with EU-level instruments such as the Data Governance Act and related Digital Decade targets, and to enable secure data sharing for public administration efficiency, innovation and research while protecting fundamental rights and data subjects’ control.

Definitions

The Strategy defines principal terms used across the governance model. Key definitions include: "data holder" (an authority or body that legally collects and maintains a dataset); "data steward" (an appointed role responsible for dataset quality, access policies and compliance); "high-value dataset" (datasets designated for priority availability, interoperability and re-use); "DAGR" (Datu izplatīšanas un pārvaldības platforma — the national data distribution & governance platform); "personal data" (as defined under the Personal Data Processing Law and GDPR); "depersonalised data" (data processed so re-identification is not reasonably possible under specified safeguards); and "data use audit trail" (automated logging and journaling of dataset access and processing activities). The Strategy recommends standardized metadata taxonomies, machine-readable access rules and the use of Data Management Plans for major datasets, reflecting principles already set out in sectoral documents.

Governance and Institutional Framework

The Strategy envisions a multi-layered governance structure with defined responsibilities: the Cabinet (Ministru kabinets) provides strategic oversight and adoption authority; VARAM (Ministry of Environmental Protection and Regional Development) is the coordinating ministry for digital transformation and national data policy; the Valsts reģionālās attīstības aģentūra (VRAA) is identified as the initial operator/manager for the DAGR implementation; sectoral ministries and agencies remain data holders and are required to appoint internal data stewards and implement agency-level governance. Supervisory and control functions reside with independent oversight bodies — most notably the Data State Inspectorate (DVI) for personal data protection compliance and with CERT.LV for security incident coordination. The Strategy establishes a National Data Governance Board (or similar body) as a cross-sector coordinating forum for policy, standard-setting and dispute resolution; the Board would include representatives from ministries, DVI, VRAA, national research bodies and civil-society experts. Implementation phases call for legal gap analysis, designation of high-value datasets and promulgation of standard operating procedures and harmonised access agreements. The model references technical and legal tasks already recorded in official planning documents and project annotations that underpin the DAGR project and digital transformation activities (Ministerial project annotations).

Key Focus Areas

The Strategy organises action areas to deliver the national data governance vision: (1) Legal and policy instruments — preparing a coherent set of legal texts and ministerial regulations that enable lawful, auditable data re-use while ensuring GDPR compliance and rights protection; (2) Technical infrastructure — implementing the DAGR with secure federated cloud hosting, standardized APIs, provenance metadata and a journaling/audit subsystem to record access and processing (technical tasks and timelines are specified in the Digital Transformation Implementation Plan); (3) Standards and interoperability — adopting common metadata schemes, open data formats for designated high-value datasets and sector-specific harmonisation (statistical, geospatial, health); (4) Access models and consent — enabling both public-interest and individually consented controlled access to data, including mechanisms for individuals to manage permissions (digital "wallets" and e-address integration are signalled in planning documents); (5) Data stewardship and skills — appointing data stewards at agency level, creating training programmes for analytics and data management; (6) Privacy, security and risk management — integrating DPIA-like assessment processes, anonymisation/pseudonymisation toolkits and cybersecurity requirements; (7) Transparency and public accountability — requiring public reporting on dataset uses, published access registers and impact assessments; and (8) Economic and research uses — facilitating reuse for economic development, innovation and public-interest research while specifying restrictions on unlawful uses. These areas align with the Cabinet's Digital Transformation priorities and DAGR delivery milestones described in official sources.

Implementation Framework

Implementation is staged and relies on coordination between central institutions and data holders. Early actions include: a legal gap analysis and regulatory drafting schedule; pilot implementation of the DAGR audit and access-control features; preparation of a high-value dataset inventory; appointment of data stewards across central agencies; and rollout of common metadata and API standards. Project governance will use project management offices under VARAM and the DAGR operator to coordinate procurement, security accreditation and integration with national authentication (eID) and e-address services. The Strategy recommends modular deployment, beginning with public administration datasets that reduce administrative burden and deliver quick wins (e.g., registries integration) while preserving gradual scope expansion into research and private-sector data sharing. Funding is expected to combine national budget allocations and EU instruments (Recovery & Resilience Facility, ERDF) as already evidenced in the Implementation Plan and project annotations.

Monitoring and Evaluation

The Strategy prescribes an annual monitoring cycle: agencies submit implementation reports (progress on dataset publication, access requests, incidents and audits) and an aggregated national progress report is prepared for the Cabinet-level oversight board. Key performance indicators include number of interoperable datasets published, API availability, measured reductions in administrative burden, number of data requests processed through DAGR, security incidents resolved and compliance findings from DVI. The Digital Transformation Implementation Plan establishes timelines and milestones (with review points through 2027) that the Strategy would adopt as monitoring anchors. Independent evaluation and public reporting are proposed to ensure transparency and public trust in data governance outcomes.

Penalties, Liability, and Appeals

Although principally a strategic document (non-binding), the Strategy outlines enforcement and remediation pathways: (1) administrative accountability for agencies failing to appoint stewards or implement baseline safeguards; (2) referral mechanisms to DVI where personal data protection breaches occur (DVI retains competence to investigate and impose sanctions under national Personal Data Processing Law and GDPR); (3) cybersecurity incident procedures coordinated with CERT.LV and law enforcement for serious incidents; (4) recommended contractual liabilities for third-party data processors using DAGR services; and (5) user-facing appeals channels for data subjects, including escalation to DVI and administrative courts. The Strategy recommends incorporation of sanctioning mechanisms into subsequent regulatory acts and model agreements to ensure effective redress and deterrence.

Relationship to Other Instruments

The Strategy is explicitly designed to operate in the policy ecosystem alongside the Digital Transformation Guidelines and Implementation Plan, sectoral strategies (digital health strategy, open science and geospatial strategies), and EU-level instruments (GDPR, Data Governance Act, NIS2, eIDAS). It does not replace data protection law — instead it proposes enabling regulatory and technical measures that must conform with DVI guidance and GDPR principles. The Strategy proposes cross-references to national procurement rules, the Personal Data Processing Law and specific sectoral enactments where dataset-specific rules apply (e.g., health data access). It also signals the need for alignment with EU data spaces (e.g., research, health, environment) and with national cloud and cybersecurity strategies to ensure secure and compliant data flows.

International Alignment

International alignment is a central principle. The Strategy commits to compliance with EU legislation (GDPR, Data Governance Act), to interoperability with EU data-sharing initiatives (European data spaces and EOSC for research data), and to adopting internationally-recognised technical standards for metadata, APIs and security. It encourages bilateral/regional coordination (Baltic cooperation on digital infrastructure was highlighted in government communications) and aims to ensure that Latvia's DAGR and data governance practices facilitate cross-border data reuse while preserving legal safeguards. References in official materials show active alignment efforts with EU reporting frameworks and Digital Decade objectives.

Implementation Timeline

PhaseMilestoneTarget date
InitiationLegal gap analysis and stakeholder consultation2024 Q4–2025 Q2
PilotDAGR audit/journaling pilot, high-value dataset inventory2025–2026 (DAGR Q1 2026 delivery window)
ScaleNational roll-out of APIs, metadata standards, data steward network2026–2027
ConsolidationRegulatory instruments (ministerial rules/acts), full monitoring reporting2027 onward

Sources and References

SourceType
Digital Transformation Implementation Plan 2023–2027 (Ministru kabinets, 13 Dec 2023)Primary Source
DAGR project annotation and ministerial notes (tapportals.mk.gov.lv)Primary Source
Valsts reģionālās attīstības aģentūra (VRAA)Primary Source

Requirements for a company

What an organisation has to do under Latvia - Data Governance Strategy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

11
  • Appoint internal data stewards within your agency.Sectoral ministries and agencies (data holders)
  • Implement agency-level data governance frameworks and procedures.Sectoral ministries and agencies (data holders)
  • Ensure all data processing activities comply with GDPR and national data protection law.All data holders and processors
  • Integrate Data Protection Impact Assessment (DPIA)-like processes for high-risk datasets.Data holders
  • Implement anonymisation and pseudonymisation toolkits for data processing.Data holders
  • Meet specified cybersecurity requirements for data infrastructure and processing.Data holders and DAGR operators
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Use Data Management Plans for all major datasets.Data holders

Should not do

0

Nothing in this category.

Who must do what

The obligations under Latvia - Data Governance Strategy, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Sectoral ministries and agencies (data holders)Appoint internal data stewards within your agency.
sectoral ministries and agencies... are required to appoint internal data stewards
By 2027Governance and Institutional FrameworkCritical
2Sectoral ministries and agencies (data holders)Implement agency-level data governance frameworks and procedures.
sectoral ministries and agencies... are required to... implement agency-level governance.
By 2027Governance and Institutional FrameworkCritical
3All data holders and processorsEnsure all data processing activities comply with GDPR and national data protection law.
DVI retains competence to investigate and impose sanctions under national Personal Data Processing Law and GDPR
OngoingPenalties, Liability, and AppealsCritical
4Data holdersIntegrate Data Protection Impact Assessment (DPIA)-like processes for high-risk datasets.
integrating DPIA-like assessment processes
By 2027Key Focus AreasCritical
5Data holdersImplement anonymisation and pseudonymisation toolkits for data processing.
anonymisation/pseudonymisation toolkits
By 2027Key Focus AreasCritical
6Data holders and DAGR operatorsMeet specified cybersecurity requirements for data infrastructure and processing.
cybersecurity requirements
By 2027Key Focus AreasCritical
7Data holdersAdopt common metadata schemes and open data formats for designated high-value datasets.
adopting common metadata schemes, open data formats for designated high-value datasets
By 2027Key Focus AreasImportant
8Data holdersRegister your organization as a data holder within the national framework.
register data holders
By 2027Compliance ChecklistImportant
9Data holdersPublicly report on the uses of datasets held by your organization.
requiring public reporting on dataset uses
By 2027Key Focus AreasImportant
10Data holdersPublish a dataset registry and summary access logs for transparency.
Publish dataset registry and access logs (summary form)
By 2027Compliance ChecklistImportant
11AgenciesSubmit annual reports on implementation progress, access requests, and incidents.
agencies submit implementation reports (progress on dataset publication, access requests, incidents and audits)
AnnuallyMonitoring and EvaluationImportant
12Data holdersUse Data Management Plans for all major datasets.
The Strategy recommends standardized metadata taxonomies, machine-readable access rules and the use of Data Management Plans for major datasets
DefinitionsRecommended

© Regulations.AI · updated on 13-Jun-2026