Latvia - Data Governance Strategy
National Data Governance Strategy
Nacionālā datu pārvaldības stratēģija
Latvia
RAI-LV-NA-NDGSNXX-2024A national-level strategy to establish a coherent data governance framework in Latvia, currently in draft/development. The strategy aims to create institutional arrangements, technical infrastructure (including the DAGR platform), legal instruments and oversight mechanisms to enable secure, privacy-preserving data sharing across the public sector and with the economy, aligned with EU data policy.
Summary
The National Data Governance Strategy (Nacionālā datu pārvaldības stratēģija) is a draft strategic policy framework that sets out Latvia's vision, principles and high-level measures for managing, sharing and governing public-sector and high-value datasets at national scale. The Strategy builds on Latvia’s Digital Transformation Guidelines 2021–2027 and the associated Implementation Plan (Ministerial Cabinet act, 13 December 2023) that identifies the Datu izplatīšanas un pārvaldības platforma (DAGR — national data distribution and governance platform) as a central instrument to enable data re-use, auditability and personal data control. The draft strategy (in development) scopes institutional responsibilities — designating the Ministry of Environmental Protection and Regional Development (VARAM) as a coordinating body for data governance policy measures and identifying implementing agencies (for example the Valsts reģionālās attīstības aģentūra (VRAA) as the DAGR operator) and supervisory bodies such as the Data State Inspectorate (Datu valsts inspekcija, DVI).
Core aims include: (1) establishing a national data governance model and legal framework (including consideration of a Data Governance Act or amendments to existing legislation); (2) defining high-value dataset lists and metadata/format standards to improve interoperability; (3) creating technical and organisational safeguards for personal data, including audit trails, logging and consent/permission mechanisms within the DAGR; (4) strengthening cybersecurity and federated cloud infrastructure to host and process data; (5) improving the public sector’s data capabilities and workforce; and (6) aligning national rules with EU instruments (Data Governance Act, GDPR, NIS2, Digital Decade objectives and EU data spaces initiatives).
The Implementation Plan adopted by the Cabinet sets concrete tasks and timelines (for example the DAGR technical and audit features were listed for delivery in 2023–2026 planning documents, and wider platform interoperability tasks are scheduled through 2027). The draft Strategy emphasises privacy-by-design, human-rights safeguards and transparent accountability — requiring data stewardship roles within agencies, DPIA-like assessments for high-risk processing, logging and monitoring of dataset access, and public reporting on data uses.
Although not a binding law itself, the Strategy is intended to serve as the basis for subsequent regulatory and secondary-norm measures: new Cabinet rules, ministerial regulations, model contracts, and possible legislative proposals (a “Data Governance Act” or targeted amendments to information governance and open-data legislation). Key stakeholder groups include central ministries, data-holding authorities, supervisory and oversight bodies (DVI, CERT.LV), local governments and the private sector. The Strategy as drafted explicitly references and seeks alignment with the Digital Transformation Implementation Plan and DAGR project documents and will be subject to public consultation and ministerial approval processes before formal adoption.
Full article
Read full text ↗Overview
The draft National Data Governance Strategy (Nacionālā datu pārvaldības stratēģija) is a policy-level instrument under development that aims to create a unified, principled and practical framework for managing, sharing and securing government-held data in Latvia. The Strategy is positioned as the national umbrella for operational measures already signalled in the Cabinet-approved Digital Transformation Implementation Plan 2023–2027 and the broader Digital Transformation Guidelines 2021–2027. At its core the Strategy promotes: interoperability and standards for high-value datasets; trustworthy technical infrastructure (notably the DAGR platform); clear institutional roles for coordination and oversight; and privacy and rights protections for individuals. The Strategy is being developed to align Latvia’s national data governance with EU-level instruments such as the Data Governance Act and related Digital Decade targets, and to enable secure data sharing for public administration efficiency, innovation and research while protecting fundamental rights and data subjects’ control.
Definitions
The Strategy defines principal terms used across the governance model. Key definitions include: "data holder" (an authority or body that legally collects and maintains a dataset); "data steward" (an appointed role responsible for dataset quality, access policies and compliance); "high-value dataset" (datasets designated for priority availability, interoperability and re-use); "DAGR" (Datu izplatīšanas un pārvaldības platforma — the national data distribution & governance platform); "personal data" (as defined under the Personal Data Processing Law and GDPR); "depersonalised data" (data processed so re-identification is not reasonably possible under specified safeguards); and "data use audit trail" (automated logging and journaling of dataset access and processing activities). The Strategy recommends standardized metadata taxonomies, machine-readable access rules and the use of Data Management Plans for major datasets, reflecting principles already set out in sectoral documents.
Governance and Institutional Framework
The Strategy envisions a multi-layered governance structure with defined responsibilities: the Cabinet (Ministru kabinets) provides strategic oversight and adoption authority; VARAM (Ministry of Environmental Protection and Regional Development) is the coordinating ministry for digital transformation and national data policy; the Valsts reģionālās attīstības aģentūra (VRAA) is identified as the initial operator/manager for the DAGR implementation; sectoral ministries and agencies remain data holders and are required to appoint internal data stewards and implement agency-level governance. Supervisory and control functions reside with independent oversight bodies — most notably the Data State Inspectorate (DVI) for personal data protection compliance and with CERT.LV for security incident coordination. The Strategy establishes a National Data Governance Board (or similar body) as a cross-sector coordinating forum for policy, standard-setting and dispute resolution; the Board would include representatives from ministries, DVI, VRAA, national research bodies and civil-society experts. Implementation phases call for legal gap analysis, designation of high-value datasets and promulgation of standard operating procedures and harmonised access agreements. The model references technical and legal tasks already recorded in official planning documents and project annotations that underpin the DAGR project and digital transformation activities (Ministerial project annotations).
Key Focus Areas
The Strategy organises action areas to deliver the national data governance vision: (1) Legal and policy instruments — preparing a coherent set of legal texts and ministerial regulations that enable lawful, auditable data re-use while ensuring GDPR compliance and rights protection; (2) Technical infrastructure — implementing the DAGR with secure federated cloud hosting, standardized APIs, provenance metadata and a journaling/audit subsystem to record access and processing (technical tasks and timelines are specified in the Digital Transformation Implementation Plan); (3) Standards and interoperability — adopting common metadata schemes, open data formats for designated high-value datasets and sector-specific harmonisation (statistical, geospatial, health); (4) Access models and consent — enabling both public-interest and individually consented controlled access to data, including mechanisms for individuals to manage permissions (digital "wallets" and e-address integration are signalled in planning documents); (5) Data stewardship and skills — appointing data stewards at agency level, creating training programmes for analytics and data management; (6) Privacy, security and risk management — integrating DPIA-like assessment processes, anonymisation/pseudonymisation toolkits and cybersecurity requirements; (7) Transparency and public accountability — requiring public reporting on dataset uses, published access registers and impact assessments; and (8) Economic and research uses — facilitating reuse for economic development, innovation and public-interest research while specifying restrictions on unlawful uses. These areas align with the Cabinet's Digital Transformation priorities and DAGR delivery milestones described in official sources.
Implementation Framework
Implementation is staged and relies on coordination between central institutions and data holders. Early actions include: a legal gap analysis and regulatory drafting schedule; pilot implementation of the DAGR audit and access-control features; preparation of a high-value dataset inventory; appointment of data stewards across central agencies; and rollout of common metadata and API standards. Project governance will use project management offices under VARAM and the DAGR operator to coordinate procurement, security accreditation and integration with national authentication (eID) and e-address services. The Strategy recommends modular deployment, beginning with public administration datasets that reduce administrative burden and deliver quick wins (e.g., registries integration) while preserving gradual scope expansion into research and private-sector data sharing. Funding is expected to combine national budget allocations and EU instruments (Recovery & Resilience Facility, ERDF) as already evidenced in the Implementation Plan and project annotations.
Monitoring and Evaluation
The Strategy prescribes an annual monitoring cycle: agencies submit implementation reports (progress on dataset publication, access requests, incidents and audits) and an aggregated national progress report is prepared for the Cabinet-level oversight board. Key performance indicators include number of interoperable datasets published, API availability, measured reductions in administrative burden, number of data requests processed through DAGR, security incidents resolved and compliance findings from DVI. The Digital Transformation Implementation Plan establishes timelines and milestones (with review points through 2027) that the Strategy would adopt as monitoring anchors. Independent evaluation and public reporting are proposed to ensure transparency and public trust in data governance outcomes.
Penalties, Liability, and Appeals
Although principally a strategic document (non-binding), the Strategy outlines enforcement and remediation pathways: (1) administrative accountability for agencies failing to appoint stewards or implement baseline safeguards; (2) referral mechanisms to DVI where personal data protection breaches occur (DVI retains competence to investigate and impose sanctions under national Personal Data Processing Law and GDPR); (3) cybersecurity incident procedures coordinated with CERT.LV and law enforcement for serious incidents; (4) recommended contractual liabilities for third-party data processors using DAGR services; and (5) user-facing appeals channels for data subjects, including escalation to DVI and administrative courts. The Strategy recommends incorporation of sanctioning mechanisms into subsequent regulatory acts and model agreements to ensure effective redress and deterrence.
Relationship to Other Instruments
The Strategy is explicitly designed to operate in the policy ecosystem alongside the Digital Transformation Guidelines and Implementation Plan, sectoral strategies (digital health strategy, open science and geospatial strategies), and EU-level instruments (GDPR, Data Governance Act, NIS2, eIDAS). It does not replace data protection law — instead it proposes enabling regulatory and technical measures that must conform with DVI guidance and GDPR principles. The Strategy proposes cross-references to national procurement rules, the Personal Data Processing Law and specific sectoral enactments where dataset-specific rules apply (e.g., health data access). It also signals the need for alignment with EU data spaces (e.g., research, health, environment) and with national cloud and cybersecurity strategies to ensure secure and compliant data flows.
International Alignment
International alignment is a central principle. The Strategy commits to compliance with EU legislation (GDPR, Data Governance Act), to interoperability with EU data-sharing initiatives (European data spaces and EOSC for research data), and to adopting internationally-recognised technical standards for metadata, APIs and security. It encourages bilateral/regional coordination (Baltic cooperation on digital infrastructure was highlighted in government communications) and aims to ensure that Latvia's DAGR and data governance practices facilitate cross-border data reuse while preserving legal safeguards. References in official materials show active alignment efforts with EU reporting frameworks and Digital Decade objectives.
Implementation Timeline
| Phase | Milestone | Target date |
|---|---|---|
| Initiation | Legal gap analysis and stakeholder consultation | 2024 Q4–2025 Q2 |
| Pilot | DAGR audit/journaling pilot, high-value dataset inventory | 2025–2026 (DAGR Q1 2026 delivery window) |
| Scale | National roll-out of APIs, metadata standards, data steward network | 2026–2027 |
| Consolidation | Regulatory instruments (ministerial rules/acts), full monitoring reporting | 2027 onward |
Sources and References
| Source | Type |
|---|---|
| Digital Transformation Implementation Plan 2023–2027 (Ministru kabinets, 13 Dec 2023) | Primary Source |
| DAGR project annotation and ministerial notes (tapportals.mk.gov.lv) | Primary Source |
| Valsts reģionālās attīstības aģentūra (VRAA) | Primary Source |
Requirements for a company
What an organisation has to do under Latvia - Data Governance Strategy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
11- Appoint internal data stewards within your agency.Sectoral ministries and agencies (data holders)
- Implement agency-level data governance frameworks and procedures.Sectoral ministries and agencies (data holders)
- Ensure all data processing activities comply with GDPR and national data protection law.All data holders and processors
- Integrate Data Protection Impact Assessment (DPIA)-like processes for high-risk datasets.Data holders
- Implement anonymisation and pseudonymisation toolkits for data processing.Data holders
- Meet specified cybersecurity requirements for data infrastructure and processing.Data holders and DAGR operators
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
1- Use Data Management Plans for all major datasets.Data holders
Should not do
0Nothing in this category.
Who must do what
The obligations under Latvia - Data Governance Strategy, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Sectoral ministries and agencies (data holders) | Appoint internal data stewards within your agency. “sectoral ministries and agencies... are required to appoint internal data stewards” | By 2027 | Governance and Institutional Framework | Critical |
| 2 | Sectoral ministries and agencies (data holders) | Implement agency-level data governance frameworks and procedures. “sectoral ministries and agencies... are required to... implement agency-level governance.” | By 2027 | Governance and Institutional Framework | Critical |
| 3 | All data holders and processors | Ensure all data processing activities comply with GDPR and national data protection law. “DVI retains competence to investigate and impose sanctions under national Personal Data Processing Law and GDPR” | Ongoing | Penalties, Liability, and Appeals | Critical |
| 4 | Data holders | Integrate Data Protection Impact Assessment (DPIA)-like processes for high-risk datasets. “integrating DPIA-like assessment processes” | By 2027 | Key Focus Areas | Critical |
| 5 | Data holders | Implement anonymisation and pseudonymisation toolkits for data processing. “anonymisation/pseudonymisation toolkits” | By 2027 | Key Focus Areas | Critical |
| 6 | Data holders and DAGR operators | Meet specified cybersecurity requirements for data infrastructure and processing. “cybersecurity requirements” | By 2027 | Key Focus Areas | Critical |
| 7 | Data holders | Adopt common metadata schemes and open data formats for designated high-value datasets. “adopting common metadata schemes, open data formats for designated high-value datasets” | By 2027 | Key Focus Areas | Important |
| 8 | Data holders | Register your organization as a data holder within the national framework. “register data holders” | By 2027 | Compliance Checklist | Important |
| 9 | Data holders | Publicly report on the uses of datasets held by your organization. “requiring public reporting on dataset uses” | By 2027 | Key Focus Areas | Important |
| 10 | Data holders | Publish a dataset registry and summary access logs for transparency. “Publish dataset registry and access logs (summary form)” | By 2027 | Compliance Checklist | Important |
| 11 | Agencies | Submit annual reports on implementation progress, access requests, and incidents. “agencies submit implementation reports (progress on dataset publication, access requests, incidents and audits)” | Annually | Monitoring and Evaluation | Important |
| 12 | Data holders | Use Data Management Plans for all major datasets. “The Strategy recommends standardized metadata taxonomies, machine-readable access rules and the use of Data Management Plans for major datasets” | — | Definitions | Recommended |
Related Regulations
National Data Strategy (aligned with the national AI and quantum strategies — 'Accelerating Digital Sovereignty 2030')
Luxembourg90% similar
Datenstrategie für Österreich (Data Strategy for Austria)
Austria90% similar
Developing Artificial Intelligence Solutions (National AI Strategy)
Latvia89% similar
Digital Transformation Guidelines 2021–2027 (Digitālās transformācijas pamatnostādnes 2021.–2027.)
Latvia88% similar
Informative Report 'On the Development of Artificial Intelligence Solutions' (Informatīvais ziņojums 'Par mākslīgā intelekta risinājumu attīstību')
Latvia88% similar
© Regulations.AI · updated on 13-Jun-2026