Cybersecurity Policy Report, Latvian Agency Outlines Common Issues in Tracking Cookies, Consent, (May 11, 2026)
By Tony Foley
Inspections conducted by the Data State Inspectorate (DVI), Latvia’s data protection authority, indicate that citizens are often unaware that they are not obliged to consent to the processing of tracking cookies and are insufficiently informed that ads they see on websites are closely related to previously given consent to cookies.
In a #DVIexplain post last week, the DVI said website operators must ensure that data protection requirements are met when processing cookies and that users are not misled. Despite its best efforts to inform data controllers in various formats about their obligations when processing cookies, the DVI observed that the issue had been addressed only on a superficial level. In addition, the agency’s inspections have revealed that users often have not been provided with a full and free choice to agree to the use of cookies.
The DVI emphasized the following common irregularities in the operation of websites found during its inspections:
Installing cookies before consent is obtained;
Opaque or misleading cookie banner structure that leads to cookie acceptance;
Incomplete information about the use of cookies; and
Nonfunctional cookie banners, as when the user clicks “reject” but optional cookies are still processed.
The DVI called on website operators to assess their cookie management solutions and, where necessary, make improvements to ensure compliance with the European Union’s General Data Protection Regulation (GDPR). The agency emphasized that personal data obtained through fraud or consent obtained without the possibility of opting out of processing was unacceptable under data protection law and that users who browsed the website or closed the cookie banner without making a selection were not considered to have given valid consent.
News: InternationalLegislation DataPrivacy GDPR