Data Security as a Test of Public Trust

Recent cyber incidents affecting AS “Latvijas valsts meži” and the Road Traffic Safety Directorate (CSDD), which resulted in significant data breaches, have brought back memories of another incident that occurred not so long ago — in October 2024 — when personal data was leaked from almost all Latvian municipalities.¹ One major data breach might still be perceived as an isolated emergency. But several incidents occurring within a short period raise a much more serious question: can citizens still trust the state to safeguard their data?

Why Trust Is a Prerequisite for a Digital State

Photo: magnific.com

According to the Organization for Economic Co-operation and Development (OECD) data from 2023, Latvia has a relatively strong digital government profile:

  • it performs above the OECD average in the adoption of a “digital by default” approach to government, policymaking and service delivery;
  • it is also above the OECD average in terms of openness, transparency, access to data and the reuse of government data;
  • Latvia is also among the countries that have implemented all six components of the OECD’s digital public infrastructure framework: digital identity, digital payments, data exchange systems, digital post, digital notifications and core registries.

However, a digital state cannot be built on convenient operational platforms alone. It depends on public trust in those platforms.

What is particularly important is that citizens often have no real choice in these relationships. To receive healthcare, they must entrust the state with their health data. For a child to attend school, educational data must be entered into government systems. When using government or municipal services, people provide information about their place of residence, property, vehicles, payments and other sensitive aspects of their lives.

The state therefore has a far greater responsibility to protect data than a private company does.

In this context, trust means citizens’ confidence that the state will act responsibly. When that confidence begins to erode, the damage goes beyond the reputation of an individual organization or institution — it affects trust in the public sector as a whole.

This is especially true when incidents recur and begin to look like serious “cracks” in governance culture, risk management, supplier oversight and accountability at the leadership level.

OECD Insight: Data Trust Is a Matter of National Reputation

OECD survey data from 2025 shows that only 27% of people in Latvia report high or moderately high trust in the national government.² This is even lower than in 2023, when the figure stood at 29%. Trust in parliament has also declined, from 25% to 23%; trust in political parties has fallen from 13% to 12%; and trust in the national civil service from 39% to 37%.³

This means that data breaches are not taking place in an environment of high public trust. They are happening against a backdrop of already fragile and declining confidence in government and public administration.

OECD data also shows that trust in government data governance is not a secondary issue. A 2026 OECD document states that “52% of people in OECD countries and 38% of people in participating OECD accession countries believe that government institutions would use their data only for legitimate purposes.”

When a data breach makes people question whether this principle can be relied upon, the damage extends far beyond a particular e-service. It affects the reputation of the state as a whole and its credibility as a custodian of citizens’ data.

OECD research on trust in government shows that public confidence in national government is influenced not only by the quality of everyday public services, but also by perceptions of the state’s ability to make, explain and implement complex, long-term decisions. Data security is precisely such an issue. It involves risk mapping, data minimization, supplier oversight, incident preparedness, independent audits and regular public accountability.⁴

A data breach is therefore not merely a technical failure. It is a test of the state’s ability to manage a complex risk that is difficult for the public to see or assess.

This issue becomes even more important in the age of artificial intelligence (AI). The OECD’s 2026 report notes that people are increasingly positive about AI’s potential to improve the quality and efficiency of public services, but are much more cautious about whether governments will use AI transparently and fairly and protect personal information. Latvia is also among the countries where more than 40% of people express low confidence in the government’s potential use of AI in the public sector.⁵

This means that if the state cannot convincingly demonstrate today that it knows how to protect data in existing systems, it will struggle to persuade the public that it can safely manage the next layers of the digital state.

Research: Data Breaches Make People Question Whether the State Can Protect Them

Photo: magnific.com

Academic research on the impact of cyberattacks also confirms that the damage caused by such incidents does not end when the technical problem is resolved. Cyberattacks can have lasting consequences and undermine trust in government.

In a 2022 study, Ryan Chandler and Miguel Alberto Gomez conclude that one of the less visible but more enduring risks of cyberattacks is a decline in public trust in government. The authors argue that cyberattacks can “erode social cohesion and trust in government institutions”, even when they do not result in catastrophic physical consequences.⁶

The psychological response described in the study is particularly important. Cyberattacks generate not only anger, but also a sense of insecurity and vulnerability. The authors point out that it is precisely this feeling — that the threat is difficult to understand, hard to control and potentially repeatable — that can significantly weaken confidence in the government’s ability to protect society.

In other words, reputational damage is caused not only by the data breach itself, but also by the thought that follows it: “If it happened this time, what is to stop it from happening to my health, education, financial or other data next time?”

That is why simply announcing that systems are operational again is not enough after an incident of this kind. Chandler and Gomez emphasize that governments cannot assume that a cyberattack will automatically rally society around the state. Quite the opposite: people may begin to perceive public institutions as incapable of protecting them against future threats.

In Latvia’s case, this means that transparent communication, public education, detailed risk management and demonstrable action are not merely elements of crisis communications. They are the foundation for rebuilding trust.

What Should Be Done After a Crisis Like This?

At times like these, one thing needs to be understood clearly: the shadow of doubt no longer falls on just one organization. It falls on the public sector as a whole and on its ability to manage citizens’ data.

That is why simply “patching the hole” in one system or at one organization will not be enough to restore public trust. People need to see that the risk is being addressed more broadly — across all systems that store sensitive citizen data.

The first step should be an independent audit, not only of the organization directly affected, but also of similar systems. The audit should assess not only technical security, but also data storage practices, access rights, incident preparedness, supplier oversight and accountability at the management level.

In any reputational crisis, open and action-oriented communication is essential. Communication should not merely reassure people; it should demonstrate that things are being changed, fixed and independently verified.

It is no longer enough to tell the public that an incident is under investigation. People need to see a public action plan with clear deadlines, named responsibilities and regular progress updates: what has been done immediately, what control mechanisms have been introduced, how often systems will be tested, and how the results of those tests will be reported to the public.

That is precisely why accountability needs to be visible all the way to the level of the supervisory board, management board and shareholder. Data security is not simply an IT department’s responsibility. It is a measure of the quality of governance.

If an organization asks people to entrust it with their data, it must be able to demonstrate that the necessary controls are in place, risks are being actively managed and that, following an incident, the system is genuinely being improved.

Trust cannot be rebuilt through promises alone. It requires real action and tangible results.

A digital state cannot expect to earn trust through words alone. It must substantiate that trust through high-quality governance, transparency, demonstrable security and regular public accountability.

If it succeeds, its reputation can be rebuilt after a crisis. If it fails, every subsequent incident will be more than just another cybersecurity event. It will become further evidence that public trust in the state is being lost faster than the state can rebuild it.

References

 

  1. Datu valsts inspekcija, Inspekcija noslēgusi pārbaudi par personas datu aizsardzības pārkākumiem: https://www.dvi.gov.lv/lv/jaunums/inspekcija-noslegusi-parbaudi-par-personas-datu-aizsardzibas-parkapumu.
  2. OECD (2026), OECD Survey on Drivers of Trust in Public Institutions 2026 Results: Navigating Rising Expectations and New Horizons, OECD Publishing.
  3. OECD (2026), Governmentat at a Glance 2025,OECD Publishing.
  4. OECD (2026), OECD Survey on Drivers of Trust in Public Institutions 2026 Results: Navigating Rising Expectations and New Horizons, OECD Publishing, Paris, Chapter 1, sections 1.4 and 1.6.
  5. OECD (2026), OECD Survey on Drivers of Trust in Public Institutions 2026 Results: Navigating Rising Expectations and New Horizons, OECD Publishing, Paris, Chapter 5, especially Figures 5.1, 5.2 and section 5.4.3.
  6. Ryan Shandler, Miguel Alberto Gomez, The hidden threat of cyber-attacks – undermining public confidence in government, 2022, DOI: https://doi.org/10.1080/19331681.2022.2112796.