DVI (Latvia) - 04.11.2025

From GDPRhub
DVI - 04.11.2025
Authority: DVI (Latvia)
Jurisdiction: Latvia
Relevant Law: Article 5(1)(a) GDPR
Article 6(1) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 04.11.2025
Published:
Fine: 150 EUR
Parties: n/a
National Case Number/Name: 04.11.2025
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Latvian
Original Source: DVI (in LV)
Initial Contributor: lde

The DPA imposed a €150 fine on an inspector of the State Police for unlawfully obtaining a citizen’s personal data from the database of the Ministry of the Interior, and sharing it in a Discord group.

English Summary

Facts

In January 2025, a police inspector accessed the Ministry of Interior’s database outside of working hours, and retrieved personal data of the data subject (name, surname, personal identification number, date of birth, image, declared place of residence). The inspector transferred this personal data to a third party in a Discord group ("Playing Runelite"), publishing the data subject’s image and other personal information.

The data subject then filed a complaint with the DPA. The inspector claimed to have suffered fraud from the data subject, and that he obtained the data to help recover his funds.

Holding

The DPA carried out an analysis of the facts at hand, and in particular whether the police inspector's action adhered to data processing principles. It held that the inspector processed the personal data without any legal basis and for personal purposes, in breach of Article 5(1)(a) and Article 6(1) GDPR.

As a result, the DPA imposed an administrative fine of €150 on the inspector.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Latvian original. Please refer to the Latvian original for more details.

Elijas Street 17, Riga, LV-1050, tel. 67223131, e-mail pasts@dvi.gov.lv, www.dvi.gov.lv

In Case No. [..]

Decision

Riga, November 4, 2025 No. [..]

On the imposition of a penalty

1. Authority (official) making the decision: Data State Inspectorate

(hereinafter – Inspectorate)[..](hereinafter – Official), in accordance with Article 58(2)(i) of the General Data Protection Regulation1

(hereinafter – Data Regulation), Article 5(1)(2), Article 23 of the Law on the Processing of Personal Data

(hereinafter – Data Law) and Article 115(1)(4) of the Law on Administrative Liability

(hereinafter – AAL).
2. Place and date of the hearing of the administrative offence case: Elijas Street 17, Riga,
October 30, 2025, at 1:00 p.m.
3. Information about the participants in the proceedings and their representatives and defenders (if any):

Person held liable: [..], personal identification number [..], declared address of residence: [..],
additional address: [..].
The date, time and process of the hearing of the administrative offence case [..] were notified by
the Official's letter of October 15, 2025. 2
In accordance with Article 137, Part Four of the AAL, an administrative offence case may be heard in a written

proceedings, if the participants in the proceedings agree to it. 3
Taking into account the above in connection with the letter of [..] dated 16 October 2025, in which [..] agrees to the examination of the administrative offence case in written proceedings, on 30 October 2025, at 13:00,
the administrative offence case was examined in written proceedings, without the presence of the person held liable
([..]).

4. Description of the circumstances established in the examination of the case:
4.1. The materials of the administrative offence case (hereinafter – the Case) contain the Official
Report No. 2-5.1/230 dated 7 November 2025 with annexes (hereinafter – the Report) stating that [..],
being an inspector of the State Police (hereinafter – the VP), outside working hours, namely, on 21 January 2025

at 12:30, the Ministry of the Interior Information Centre (hereinafter – IeM IC) mobile application
“MOBAPP” (hereinafter - MOBAPP), not in connection with the performance of official duties in the VP and, possibly,
driven by personal motives, carried out the acquisition of personal data (name, surname, personal
code, date of birth, image, declared residential address), part of which (image,
declared residential address and date of birth) on 21 January 2025 at 16:45 and

1
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to
2the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
3Registered in the Inspectorate under No. 2-4.2/1489-N
Received and registered by the Inspectorate on October 16, 2015 with No. 2-4.2/1594-S 2

at 16:46 were published in the chat program “Discord” (hereinafter - Discord) group “Playing

Runelite” (hereinafter - Group), thus processing the personal data of the Data Subject, in violation of Article 5, Paragraph 1, Subparagraphs a) and b), Article 6, Paragraph 1 of the Data
Regulation.
The annex to the report contains: 1) The Data Subject’s complaint of January 21, 2025 with an attachment;
2) The Ministry of Internal Affairs IC letter No. 14-6-1/5046/25 of May 7, 2025 with an attachment; 3) The State Police
6
letter of June 26, 2025 No. CAnos/42510 with attachments; 4) State Police letter No. 20-CAnos/58812 with attachments dated 17 September 2025. 7
4.2. Based on the information contained in the Report and its attachments and in accordance with the first part of Article 118 of the AAL, by the Official's decision No. [..] of 8 October 2025 on the initiation of administrative violation

proceedings, an administrative violation procedure case No. [..] has been initiated regarding[..] actions, using the user access granted to the MOBAPP for the performance of the VP's work duties, without legal grounds, possibly for personal interests.
4.3. The case materials contain an explanation dated [..] 8 October 2025, in which [..] the following is indicated

: [..] does not remember the events that occurred more than six months ago, but confirmed that the legal basis for the action referred to in paragraph [4.1] does not exist. At the same time, [..] explained that the Data Subject had defrauded [..] of several hundred euros for a service that was not actually provided and, in order to help recover the defrauded funds, [..] obtained the Data Subject's personal identification number, declared residential address, picture from MOBAPP and transferred it to [..] (a third party), who is also a Discord profile user under the name [..], for further processing, after which the Data Subject's picture was deleted and was not further processed.
[..] contacted [..] and clarified that the conflict had been resolved and the Data Subject's data had also been deleted from [..]

the [..]
party.

5. Regulatory act providing for liability for an administrative violation: Article 83(5)(a) of the Data Regulation.
5.1. In accordance with Article 132 of the AAL, when examining an administrative offence case, it shall be established whether an administrative offence has been committed, whether the person concerned is guilty of committing it, whether this person can be held administratively liable, whether there are mitigating and aggravating circumstances, and other circumstances that are important for the correct decision of the case shall be established.
5.2. The first part of Article 5 of the AAL stipulates that an administrative offence shall be deemed to be an unlawful, culpable act (action or omission) for which administrative liability is provided for by law or by the binding regulations of local governments.
5.3. Article 83(5)(a) of the Data Regulation provides for administrative liability for violations of the fundamental principle of processing, including the condition of consent, in compliance with Articles 5, 6, 7 and 9 of the Data Regulation.

5.4. Thus, in order to establish whether [..] has committed an administrative offence as provided for in Article 83(5)(a) of the Data
Regulation, the Official needs to establish that [..], in disregard of the basic principles of personal data processing set out in Article 5(1) of the Data
Regulation and without the legal basis set out in Article 6(1) of the Data
Regulation, processed (obtained, transferred to a third party) the personal data of the Data Subject when making a request for information to MOBAPP.
5.5. The legal framework for the processing of personal data of natural persons is determined by the Data
Regulation, the Data Law and other normative acts.

4Registered by the Inspectorate on 22 January 2025 under No. 2-4.2/92-S
5
6Received and registered by the Inspectorate on 8 May 2025 under No. 1-6.1.1/26-S
7Received and registered by the Inspectorate on June 26, 2025 with No. 2-4.2/931-S
8Received and registered by the Inspectorate on September 17, 2025 with No. 1-6.1.1/63-S
Received and registered by the Inspectorate on October 8, 2025 with No. 2-4.2/1522-S 3

5.6. According to Article 4(1) and (2) of the Data Regulation, “personal data” means any information relating to an identified or identifiable natural person, while “processing” means any operation or set of operations which is performed upon personal data or upon sets of personal data, whether or not carried out wholly or partly by automated means, as well as any operation which is performed upon personal data which constitutes or is intended to constitute a filing system. Thus, the name, surname, personal identification number, date of birth, declared address, image and other information by which a natural person can be identified shall be considered personal data, while any operation or set of operations which is performed upon such personal data, including the collection through MOBAPP and the transfer to third parties, shall constitute processing of personal data within the meaning of Article 4(1) and (2) of the Data Regulation. 5.7. Article 4(7) of the Data Protection Regulation stipulates that the controller is responsible for the compliance of the processing of personal data with the Data Protection Regulation. The official establishes that in relation to the processing of personal data (acquisition, transfer to third parties) carried out by [..] for personal purposes, not related to the performance of the duties of the VP, the controller is [..].
5.8. Article 5 of the Data Protection Regulation sets out the basic principles of the processing of personal data, and

Article 6 – the lawfulness of the processing. In accordance with Article 5(1)(a) of the Data Protection Regulation, personal data shall be processed lawfully, fairly and in a manner transparent to the data subject, while Article 5(1)(b) stipulates that the data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes.

According to Article 6(1) of the Data Protection Regulation, processing is lawful only to the extent and only if at least one of the following grounds applies: consent of the data subject, conclusion or performance of a contract, legal obligation of the data controller, performance of a task based on official authority or in the public interest, protection of the vital interests of the data subject or a third party and legitimate interests of the controller or a third party. If the aforementioned conditions are not met, the processing of personal data is not in accordance with the Data Protection Regulation and may not be carried out. In view of the above, [..] would be entitled to make a request on 21 January 2025 at 12:30 to MOBAPP using the Data Subject’s first and last name “[..]” and to obtain and on 21 January 2025 at 16:45 and at 16:46 to transfer the information available in this national information system for further processing, if such action would have a legal purpose in accordance with Article 5(1)(a) and (b) of the Data Protection Regulation and a legal basis specified in Article 6(1)(a) of the Data Protection Regulation.
5.9. Having assessed the Case materials in conjunction with the explanation provided by [..], the Official
does not establish the lawfulness of the personal data processing carried out by [..], therefore, the Official concludes that the processing of personal data of natural persons (acquisition, transfer to a third party) was carried out in accordance with Article 5(1)(a) and (b) and Article 6 of the Data Protection Regulation.
Namely, in accordance with the explanation provided by [..], the Official concludes that on January 21, 2025
at 12:30 [..], using the user access granted to the VP for the performance of his/her work duties in MOBAPP,

9
An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, surname, identification number, location data, online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
10data subject
11 For example, collection, registration, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
12The processing of personal data by automated means includes the processing of data in information systems where it is possible to select a person by specific identifiers, for example by using information technology systems.
13Any structured set of personal data which is accessible in accordance with specific criteria, regardless of whether the set of data is centralised, decentralised or dispersed on a functional or geographical basis.
14a natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data [..] 4

for personal purposes outside the scope of its employment, made a request for information about the Data Subject and on 21 January 2025 at 16:45 and at 16:46 part of the data obtained as a result of this request was transferred to [..] (a third party), thus obtaining and transferring personal data for further processing contrary to the basic principles of personal data processing set out in Article 5(1)(a) and (b) of the Data Regulation and without the legal basis set out in Article 6(1) of the Data Regulation, thus committing an administrative offence, for which administrative liability is provided for in Article 83(5)(a) of the Data Regulation.
5.10. The official concludes that [..] guilt in committing the administrative offence set out in Article 83(5)(a) of the Data Regulation has been proven by: the Report and its annexes, [..]
explanations.

6. Penalty applied by the Authority (Official) that examined the administrative offence case:
6.1. Article 83(5)(a) of the Data Regulation provides that infringements of the fundamental principles of processing, including the conditions for consent, in accordance with Articles 5, 6, 7 and 9 of the Data Regulation may be subject to administrative fines of up to EUR 20,000,000. Recital (148) of the Data Regulation explains that in order to strengthen compliance with the provisions of the Data Regulation, in addition to or instead of appropriate measures taken by the supervisory authority under the Data Regulation, sanctions, including administrative fines, should be imposed for infringements of the Data Regulation. In the case of minor infringements or where the fine that could be imposed would cause disproportionate harm to the natural person, a reprimand may be imposed instead of a fine. However, due account should be taken of the nature, gravity and duration of the infringement, whether the infringement was committed intentionally, actions taken to mitigate the damage suffered, the degree of responsibility or any relevant previous infringements, the manner in which the supervisory authority became aware of the infringement, compliance with the measures taken against the controller or processor, compliance with the code of conduct and any other aggravating or mitigating circumstances. 

6.2. In accordance with Article 23 of the Data Law, the Inspectorate, when adopting the decisions provided for in Article 58 of the Data Law, shall apply the Administrative Procedure Law with regard to the imposition of a legal obligation and, with regard to administrative penalties, the regulatory enactments regulating the record-keeping (proceedings) of administrative infringements, to the extent that the Data Law and the Data Regulation do not provide otherwise. The provisions of the Data Regulation on the issue of the application of an administrative fine and its amount differ from the provisions contained in the GDPR, i.e. the Data Regulation provides otherwise on the relevant issue, therefore, when determining the amount of the fine, the Official shall apply the provisions contained in the Data Regulation, and the penalty shall be applied in accordance with the provisions of the Data Regulation. In accordance with Article 83(1) of the Data Regulation, the supervisory authority is obliged to ensure that the application of administrative fines for the violations of the Data Regulation referred to in paragraphs 4, 5 and 6 in accordance with the Data Regulation is effective, proportionate and dissuasive in each specific case. Article 13 of the GDPR stipulates that an administrative penalty is a means of influence that is applied to a person who has committed an administrative offence in order to protect public order, restore justice, punish the person who committed the administrative offence and other persons from further committing administrative offences. According to Article 14 of the AAL, the following penalties may be imposed for an administrative violation:
warning, fine, deprivation of rights and prohibition of the use of rights.
The second part of Article 19 of the AAL stipulates that when determining the type and amount of an administrative penalty, the
nature of the violation committed, the personality of the person held liable (for a legal person –
reputation), financial situation, circumstances under which the violation was committed, mitigating and

aggravating circumstances shall be taken into account.
6.3. When determining the penalty, the Official shall take into account the nature, gravity and duration of the violation, taking into account the type, extent or purpose of the relevant data processing, as well as the number of data subjects affected – in the specific case, the violation (obtaining) was committed [..] using the status of an inspector of the VP [..] and the user access to MOBAPP granted for the performance of work 5 duties, while the violation (transfer) was committed by taking a screenshot from MOBAPP with the image of the Data Subject and simultaneously sending the personal data (date of birth and declared address of residence) of the Data Subject obtained from MOBAPP to [..] (a third party) for further processing, as a result of which the image of the Data Subject and personal data were published in the Group. The Official shall also take into account that the violation was committed outside [..] working hours, not related to the performance of work tasks and for personal purposes; whether the violation was committed intentionally or due to negligence - there is sufficient ground to conclude that the violation was committed intentionally. Namely, the VP has issued several orders and developed various internal regulations regarding the VP, including the processing of personal data by VP police officers. It is evident from the documents in the Case that [..] has certified with his signature that he has read the relevant VP documents and that their content was known to him. Consequently, [..] was aware of the harmfulness of his actions and committed the violations intentionally; any action of the controller or processor to mitigate the damage caused to the data subjects - there is no information in the Case about the damage caused to the Data Subject and there are no victims in the Case; the category of personal data affected by the violation – The evidence obtained in the Case confirms that the personal data of the Data Subject (name, surname, personal identification number, date of birth, image, declared residence addresses) were processed (obtained), part of which (image, declared residence address and date of birth) was transferred to a third party who published them in the Group; previous violations of the Controller – [..] has not previously been administratively punished for committing the violation examined in this decision; the degree of cooperation with the supervisory authority – [..] cooperated with the Inspectorate, providing the information necessary for examining the Case; the manner in which the Inspectorate learned about the violation – upon receiving information through the Data Subject’s complaint – [..] did not himself report the violation to the VP or the Inspectorate; any other aggravating or mitigating circumstances applicable to the circumstances of the case – The Official has not established any mitigating or aggravating circumstances.
6.4. Taking into account the above, based on Article 5, Part 1, Paragraph 2, Article 23,

Article 58, Part 2, Point i) of the Data Regulation, Article 14, Part 1, Paragraph 2, Article 115, Part 1, Paragraph 4, Article 151, Part 1, Paragraph 1, Article 157, Part 2 and 3, Article 166, Part 1 and Article 168 of the AAL, the Official,
decides:

to declare that [..], personal identification number [..], has committed an administrative offence provided for in Article 83, Part 5, Point a) of the Data
Regulation, and to impose a fine of 150 (one hundred fifty) euros
(30 fine units).

The fine shall be paid in full no later than one month from the date of entry into force of this decision at any banking institution or after the expiry of the period for voluntary execution of the fine.

This decision will be immediately transferred to a sworn bailiff for compulsory execution.

Details for payment of the fine:
Beneficiary: State Treasury
Registration No.: 90000050138
Account No.: LV69TREL1060191019200

Beneficiary BIC code: TRELLV22
Notes: Indicate the date and number of this decision.

In accordance with the first paragraph of Article 166 of the AAL, this decision may be appealed by submitting a complaint to the Director of the Inspectorate, Elijas Street 17, Riga, LV-1050, within 10 (ten) business days from the date of notification (receipt) of this decision. 6

In accordance with Article 262 of the AAL, the deadline for voluntary execution of the fine specified in the decision in full is set at 1 (one) month from the date the decision has entered into legal force. The procedure for voluntary execution of the fine is set out in Article 263 of the AAL.

In the event that the fine is not paid voluntarily within the period specified in this decision, then, in accordance with Article 269, Part One of the AAL, the institution shall immediately transfer the decision on the penalty for compulsory execution to a sworn bailiff after the expiry of the period for voluntary execution of the fine.

Please note that, in accordance with Article 568 of the Civil Procedure Law, voluntary execution of the decision after the enforcement document has been submitted for compulsory execution shall not exempt from the obligation to reimburse the enforcement costs to the bailiff.

Within the period of voluntary execution of a fine, a request may be made for the suspension of the execution of the fine or for the division of the fine into parts by submitting a written application for the suspension of the execution of the fine or for the division of the fine into parts to the institution (Inspection). The procedure for the suspension of the execution of the decision on the fine or the division of the fine into parts is set out in Article 266 of the AAL.

The fine, compulsory payment, recoverable procedural expenses and losses to natural resources imposed in the administrative violation proceedings can be paid on the portal www.latvija.lv,
using the e-service Administrative Penalties Verification and Payment.

Inspectorate official S. Kuļčuka