All systems operational Your IP: 18.97.14.87 info@cloudhosting.lv +371 66 66 29 69 Client area
Data protection · CloudHosting

Personal data protection without the headache

GDPR and the Latvian Personal Data Processing Law apply to every company that handles personal data. Our certified specialist organizes and supervises your data processing: records, policies, training and breach response, so an inspection finds order instead of gaps.

  • Certified specialist
  • Art. 30 records included
  • Fixed monthly retainer
Data protection

What you get out of it

Compliance you can prove

A processing inventory and an Article 30 register show an inspector exactly what personal data you process, why and on what legal basis.

Documents that fit Latvian law

Privacy policies, consent texts and internal security regulations written for your company, with Latvian-law specifics handled in Latvian language documents.

Staff that know the rules

Training and clear breach response guidance, so your employees do not become your biggest data protection risk.

DPO without a full-time hire

Where the law requires a data protection officer, our specialist takes the duty on an outsourced retainer instead of a new position on your payroll.

What the service includes

  • Processing inventory and Article 30 records
  • Privacy policies and consent texts
  • Video surveillance registration and signage
  • Internal security regulations for information systems
  • Staff training and breach response guidance
  • Ongoing outsourced DPO duty where the law requires one

Price on request: a one-off project or a fixed monthly retainer, sized to your processing.

How it works

  1. 1

    Inventory

    We map what personal data you process, where it lives and on what legal basis, for companies and public institutions alike.

  2. 2

    Documents and training

    We prepare the Article 30 register, policies, consent texts, signage and internal regulations, then train your staff.

  3. 3

    Ongoing supervision

    The specialist supervises processing, guides you through incidents and covers the DPO duty on a monthly retainer.

Data protection questions

When does a company need a data protection officer?

GDPR makes a data protection officer mandatory in three situations: you are a public authority, your core activities involve large-scale regular monitoring of people, or you process special category data such as health data on a large scale. The regulation does not define large scale precisely, so borderline cases need an honest assessment of what you actually process and why. Even when no DPO is required, every GDPR duty still applies: records, legal bases, security and breach handling. Our certified specialist covers both situations, taking the mandatory DPO duty as an outsourced role or supervising compliance voluntarily. If you are unsure which side you fall on, describe your processing to us and we will assess it.

How large can GDPR fines be?

The legal maximums for the most serious violations are up to 20 million EUR or 4% of worldwide annual turnover, whichever is higher. In practice a supervisory authority weighs the gravity and duration of the violation, how many people were affected, whether you cooperated and what safeguards you already had in place, so documented compliance work directly influences the outcome. A fine is also not the only consequence: the authority can order you to change or stop specific processing, and the case becomes public, which clients and partners notice. For most companies the realistic comparison is simple: keeping records, policies and training in order costs a fraction of even a modest enforcement case.

What is the Article 30 register?

The Article 30 register is your formal record of processing activities: which categories of personal data you handle, for what purposes, on what legal basis, who receives the data and how long you keep it. GDPR obliges most organizations to maintain it, and the exemptions are narrow enough that relying on them is rarely wise. It matters because it is the first document a supervisory authority requests, and because everything else, from privacy policies to retention rules, is built on top of it. A register is only useful while it reflects reality, so it must be updated whenever a process, system or vendor changes. We create yours during the processing inventory and keep it current as part of the service.

What are the video surveillance rules in Latvia?

Video surveillance counts as personal data processing, so the general GDPR logic applies alongside Latvian specifics. Cameras must serve a defined lawful purpose, typically the protection of property or people, and must not cover more than that purpose justifies, which is why pointing them at neighboring property or areas where people expect privacy causes problems. Monitored areas need signage that names the operator and the purpose, so visitors know who is filming and why. You must also document how long footage is stored, who may access it and on what grounds, and the surveillance itself belongs in your Article 30 register. We handle the registration and signage requirements and prepare the documentation, in Latvian where Latvian law requires it.

How does the monthly retainer work?

You pay a fixed monthly fee and our certified specialist works as your standing data protection function instead of a one-off consultant. Month to month that means keeping the Article 30 register current, reviewing every new processing activity before you launch it, such as a new tool, vendor or marketing campaign, running staff training and guiding you through incidents. Where the law requires a DPO, the retainer covers that duty as well, including being the named contact for the supervisory authority. Compliance is not a document you finish once, because your processing keeps changing, and the retainer exists to absorb that change. The fee is quoted per company once we have seen the scope of your processing.

How is this different from your NIS2 service?

The two services answer different laws with different scopes. NIS2 is about the cybersecurity of critical services: whether your infrastructure is resilient, whether incidents are reported on time and whether technical controls are in place. It applies only to organizations in the sectors the directive covers. Data protection is about personal data and GDPR duties: records, legal bases, policies and people's rights, and it applies to essentially every company, regardless of sector or size. The overlap is security: both expect you to protect the data you hold, so work done for one often supports the other. Many clients need both, and together with our IT audit the services complement each other. If you are unsure which applies, ask us.

How fast can you set everything up?

There is no honest universal deadline, because the timeline depends on how many processing activities you have and how much documentation already exists. We always start with the inventory, since everything else depends on knowing what you actually process. After that we agree a document and training plan with clear deadlines, prioritizing the gaps that carry the most risk, such as missing mandatory records or consent texts. A small company with a handful of processes gets the base set quickly, while larger organizations are handled in stages so daily work is not disrupted. You can shorten the timeline by naming one contact person and collecting your existing contracts and policies before we start.

Do you work with public institutions?

Yes, the service covers both private companies and public institutions in Latvia. Public bodies are in a specific position: GDPR obliges them to appoint a data protection officer regardless of size, and the officer must be able to act without a conflict of interest, which is difficult to arrange internally in a small institution where the same people run the systems being supervised. An outsourced DPO solves that: our certified specialist takes the duty on a retainer, keeps the required records, advises management and handles communication in data protection matters. All documents that Latvian law requires in Latvian are prepared in Latvian.

Ready to start?

Deploy in minutes or talk to an engineer about what fits your project.