Basic information on SIS

 

  • The Schengen Information System (SIS) is the most widely used and largest information sharing system for security and border management in Europe. As there are no internal borders between Schengen countries in Europe, SIS compensates for border controls and is the most successful cooperation tool for border, immigration, police, customs and judicial authorities in the EU and the Schengen associated countries. Competent national authorities (including the State Border Guard) are able to enter and consult alerts on people and objects in one common database.
  • The country entering the alert and related data in SIS is the “data owner”. This means that only this country is allowed or able to update and delete the alert.
  • In 2013, the second generation SIS (SIS II) was rolled out, with additional functionalities, such as the possibility of adding fingerprints and photographs to alerts. Since March 2023, DNA profiles of persons declared lost or their parents, grandparents or brothers and sisters have been stored in SIS in order to confirm their identity.
  • Information Centre of the Ministry of the Interior performs the functions of the system manager in relation to the SIS National Unit. It shall ensure the technical functioning of the NSIS and shall monitor compliance with the technical requirements laid down in the laws and regulations governing the functioning of the SIS.

 

SIS legal framework

 

  • Regulation (EU) 2018/1860 on the use of the Schengen information system for the return of illegally staying third-country nationals;
  • Regulation (EU) 2018/1861 on the establishment, operation and use of the Schengen information system (SIS) in the field of border checks;
  • Regulation (EU) 2018/1862 on the establishment, operation and use of the Schengen information system (SIS) in police cooperation and judicial cooperation in criminal matters.

 

In the Republic of Latvia, the procedures for the maintenance and use of SIS shall be determined by:

  • Law on the Operation of the Schengen Information System (adopted on 14.6.2007)
  • Procedures for the Entering, Correction and Deletion of Alerts in the Schengen Information System, as well as Ensuring Accessibility of Supplementary Information between the SIRENE Latvia Bureau and Procedures for the Exchange of Supplementary Information of Institutions and Authorities (Cabinet Regulation No. 639 of 18.09.2007);
  • Procedures for the Request and Issue of Information Regarding a Data Subject that is Kept in the Schengen Information System and the SIRENE Information System (Cabinet Regulation No. 622 of 11.09.2007).

 

Operational objectives of SIS and purposes of processing of personal data

 

  • ensuring the security of the Schengen area without carrying out checks at internal borders;
  • strengthening public order and Schengen area on national territory;
  • contribute to the fight against terrorism, cross-border crime and illegal migration;
  • serve as a cooperation tool for border, immigration, police, customs and judicial authorities in the EU and Schengen associated countries;
  • searching for criminals, missing persons, third-country nationals who are denied access to Schengen countries, persons who need to know their actual place of residence, persons and objects of operational interest for judicial purposes, as well as identifying offenders on the basis of fingerprints and fingerprints;
  • prevent the abduction or disappearance of persons, including children, to protect vulnerable persons (adults or children) from illegal removals abroad.

 

Data subjects

(persons, covered by alert messages in SIS)

 

  • third-country nationals subject to return decisions;
  • third-country nationals who do not have the right to enter or stay in the Schengen area;
  • persons wanted for arrest;
  • missing persons;
  • vulnerable persons whose travel must not be allowed;
  • children who could be abducted by their parents, relatives or guardians;
  • persons sought to assist in judicial proceedings (e.g. witnesses to criminal proceedings);
  • persons and objects subject to discreet, investigative or special checks:
  • unknown persons wanted (fingerprints and palm marks discovered at the scene of terrorist offences or other serious crimes);

 

Categories of data

 

  • identification of the wanted persons (at least given name and surname; year of birth);
  • photographs of the wanted persons *;
  • fingerprints and/or palm prints of the wanted person *;
  • information on the objects related to the person sought, such as the vehicle used by the person sought;
  • a description or a copy of the identification document of the wanted persons;
  • dactyloscopic data (fingerprints and/or palm marks *) detected at crime scenes;
  • DNA profile of the wanted person or of the members of his family * (only in the case of missing persons to be protected);
  • the European arrest warrant (EAW) (if a person is wanted for arrest);
  • the data on victims of identity theft.

 

Other data entered in SIS alerts:

  • a reference to the decision on which the alert is based;
  • the action to be taken.

 

* Biometric data allows to ascertain the identity and to avoid misidentification.

 

Access to SIS data

 

The authorities specified in Section 14 of the Law on the Operation of the Schengen Information System, including the State Border Guard, shall have access to the information included in the system in accordance with the competence specified in the regulatory enactments regulating the operation of the SIS.

 

 

 

Retention period for SIS data

Data recorded in SIS may only be stored in the system for as long as is necessary to achieve the purpose of the alert. Once the purpose of the alert is achieved, the data is deleted immediately.

More details on the storage of SIS data you can find on the website of European Commission:

https://home-affairs.ec.europa.eu/policies/schengen-borders-and-visa/schengen-information-system/questions-and-answers_en

 

Rights of data subjects in relation to SIS:

  • the right to access personal data stored in SIS;
  • the right to correct inaccurate personal data or have unlawfully stored personal data be erased;
  • the right to bring proceedings before the courts or competent authorities to correct or erase personal data or to obtain compensation for any damages resulting from breaches of data protection law.

How to enforce rights?

 

The data subject may exercise the right of access and receive information regarding the right to rectification and deletion of data by submitting a written request signed in person or with a secure electronic signature:

  • to the State Police (SIRENE Latvia National Unit[1], Riga, Čiekurkalna line 1, 4, telephone + 371 67219053, e-mail: ssp@vp.gov.lv),
  • or according to his or her place of residence in a police unit,
  • or in diplomatic missions of the Republic of Latvia.

Contact details of diplomatic or consular missions of the Republic of Latvia are available at: https://www.mfa.gov.lv/en 

 

A written request shall specify:

  • information regarding the submitter: given name (names), surname, date of birth, personal identity number (if any), place of birth, nationality, type, number of the personal identification document (if any), name of the issuing authority, date of issue and term of validity;
  • the amount of information to be requested (information regarding the data subject, information regarding the recipients of personal data of the data subject);
  • type of receipt of information (by visiting the State Police institution or representation in person or sending information to the indicated address);

When submitting an on-site request, the data subject shall prove his or her identity by presenting a personal identification document. If an authorized person submits the request, they present a notarized authorization confirming the right to receive information regarding the data subject or a document confirming the rights of parents, adopters, guardians or trustees.

 

Receiving of information is free of charge. The response time may be a maximum 1 month.

 

Persons may make requests in Latvian and English. Model requests are available on the official website of the State Police: https://www.vp.gov.lv/lv/sengenas-informacijas-sistema

 

If the reply provided by SIRENE Latvia National Unit of the State Police refuses to provide information or refuses to correct or delete data, the data subject has the right to submit a complaint to the national supervisory authority of the Member State. Persons may make applications to the Data State Inspectorate in Latvian and English.

Contact details: Data State Inspectorate

dvi.gov.lv

Email pasts@dvi.gov.lv

Address: Elijas Street 17, Riga, Latvia, LV-1050

 

Additional information and sample complaints (in Latvian and English languages) are available on the official website of the Data State Inspectorate: https://www.dvi.gov.lv/en/schengen-information-system

 

 


[1]SIRENE Latvia National Unit:

  • ensure the exchange of information between the law enforcement authorities of the Member States on persons or objects for which a report is included in the Schengen Information System;
  • ensure the promulgation of wanted criminals in international search systems;
  • ensure the quality and legal soundness of the messages to be included in SIS — compliance with the requirements of the Schengen acquis;
  • co-ordinate the search activities of foreign law enforcement institutions for criminals and missing persons in Latvia.
  • is the only authority in a country empowered to examine applications by natural persons and to respond to the maintenance of the applicant's data in the SIS and SIRENE information system (a data processing system in which additional information is processed and by which warning messages are processed).

 

Basic VIS information

  • The Visa information system (VIS) is intended for the exchange of data between Schengen Member States on short-stay visa applications and related decisions. The VIS shall contain information, including biometric data, on third-country nationals applying for a Schengen visa;
  • Visa applications and issued, refused, extended, annulled and revoked visas of the competent authorities of Latvia shall be registered in the national Visa information system (NVIS);
  • Personal data, together with biometric data submitted with the visa application, shall be processed and stored in the central VIS system.

Legal framework for VIS

  • Council Decision establishing the Visa information system (VIS) 2004/512/EC;
  • Regulation 767/2008 of the European Parliament and of the Council concerning the Visa information system (VIS) and the exchange of data between Member States on short-stay visas (VIS Regulation);
  • Regulation (EC) No 810/2009 of the European Parliament and of the Council establishing a Community Code on visas (Visa Code).

In the Republic of Latvia the procedures for the use of VIS and NVIS shall be determined by Cabinet Regulation No. 676 of 30 August 2011, “Visa Regulations”, which have been issued in accordance with Section 3, Paragraph three, Section 12, Paragraph one, Clause 3, Section 13, paragraphs three and four of the Immigration Law.

Operational objectives of the VIS and purposes of the processing of personal data

  • examine visa applications and related decisions;
  • verify the identity of the visa holder and/or the validity of the visa by carrying out checks at the external borders and within the Member States;
  • verify that the conditions for legal entry into and residence on the territory of the Member States are met and identify persons who do not or no longer fulfil those conditions, including the identification of persons who do not hold or have fraudulent documents (in the fight against illegal immigration);
  • preventing “visa trade”;
  • prevent the use of false documents and attempts to provide false information;
  • protect travelers from identity theft;
  • allows the determination of the Member State responsible for examining an asylum application; facilitates the exchange of data between Schengen States on visa applications;
  • contribute to the prevention, detection and investigation of terrorist threats and other serious criminal offences.

Personal data stored in the VIS may be transferred to a third country or international organisation in accordance with Article 31 of the VIS Regulation and to Schengen Member States in accordance with Council Decision (EU) 2017/1908.

Data subjects

Persons whose data are processed in the VIS system.

Categories of data

  • alphanumeric data on the applicant, visas applied for, visas issued, visas refused;
  • visas annulled, revoked or extended;
  • photographs *;
  • fingerprint data *;
  • links to previous visa applications and application files of persons travelling together;
  • information about the inviter.

The scope of the information to be included in the NVIS is governed by Article 53 of the Visa Regulations.

* The use of biometric data to confirm the identity of the visa holder allows faster, more accurate and more secure checks to be carried out.

Responsible authorities for data processing

  1. Office of Citizenship and Migration Affairs (State Visa information system (NVIS) manager):

contact information: pmlp.gov.lv, email: pasts@pmlp.gov.lv

more information on https://www.pmlp.gov.lv/en/visas-and-invitations

  1. State Border Guard

Officials of the State Border Guard shall issue single uniform visas and visas with limited territorial validity at the border crossing points specified in Annex 1 to Cabinet Regulation No. 676 of 30 August 2011 “Visa Regulations”. The officials of the State Border Guard shall issue visas with the endorsement “Diplomatic Visa” or “Service Visa” only upon the request of the Consular Department.

contact information: rs.gov.lv, email: pasts@rs.gov.lv

Access to VIS data

  • Officials of the State Border Guard shall have the right of access to information when it is necessary to verify the identity of a person, to verify that a visa is genuine, or to verify that a person fulfils the requirements for entry and/or stay in one of the Schengen States.
  • Asylum authorities have access to information when they have to determine which EU/EEA country is responsible for examining an asylum application.
  • Other national authorities and Europol may request access to information in specific circumstances for the purposes of the prevention, detection and investigation of terrorist offences and serious criminal offences.

Period of storage of VIS data

Data shall be stored in the VIS for a maximum period of five years.

This period shall begin:

(a) the date on which the visa expires, if the visa has been issued;

(b) the date on which the new validity of the visa expires, if the visa has been extended;

(c) the date on which the application file was created in the VIS, where the application was withdrawn, closed or terminated;

(d) on the date of the decision of the visa authority, if the visa was refused, annulled or revoked.

Data subjects' rights in relation to the VIS:

  • the right to be informed of itself and of the Member State which transmitted the data to the VIS;
  • the right to receive information on the recipients of personal data, unless the disclosure of such information is prohibited by law in the field of national security, defence and criminal law;
  • the right to request that his or her personal data be supplemented or corrected, as well as to suspend the processing thereof or destroy them if the personal data are incomplete, obsolete, false, illegally acquired or they are no longer necessary for the purpose of collection;
  • the right to submit a complaint to the state supervisory authority or to file a lawsuit in court.

How to enforce rights?

The data subject may exercise the rights by addressing the NVIS manager:

Contact details: Office of Citizenship and Migration Affairs

pmlp.gov.lv

Email: pasts@pmlp.gov.lv

Where the data subject considers that his or her personal data are being processed contrary to the applicable law, the data subject shall first have the possibility to lodge a complaint with the data controller:

Contact details: Office of Citizenship and Migration Affairs

pmlp.gov.lv

Email: pasts@pmlp.gov.lv

If the data controller did not provide a satisfactory reply, the data subject shall have the possibility to lodge a complaint with the national supervisory authority of a Member State. Applications may be submitted to the Data State Inspectorate in Latvian and English.

Contact details: Data State Inspectorate

dvi.gov.lv

Email pasts@dvi.gov.lv

address: Elijas Street 17, Riga, Latvia, LV-1050

In accordance with Article 40(1) and (2) of the VIS Regulation, each data subject has the right to bring an action before the competent authorities or courts of the Member State concerned if the data subject considers that the Member State concerned has refused to exercise the right.

General Information

The Entry/Exit System (hereinafter – EES) contains personal data records relating to third-country nationals entering the territory of the Member States of the European Union (hereinafter – Member States) for the purpose of a short stay (no more than 90 days within any 180-day period).

The system became operational on 12 October 2025. From that date, information on the entry into and exit from the territory of Member States, as well as information on refusals of entry, has been recorded in the Entry/Exit System.

More information: https://travel-europe.europa.eu/ees/what-is-the-ees

Data Subjects

The EES applies to third-country nationals who are authorised to stay for a short period, including:

holders of short-stay visas; and visa-exempt third-country nationals. 

Purposes of Personal Data Processing

The purposes of processing personal data are laid down in Article 6 of Regulation (EU) 2017/2226, establishing an Entry/Exit System (EES) to register entry and exit data and refusal of entry data of third-country nationals crossing the external borders of the Member States, determining the conditions for access to the EES for law enforcement purposes, and amending the Convention implementing the Schengen Agreement and Regulations (EC) No 767/2008 and (EU) No 1077/2011.

The purposes are to:

  • improve the efficiency of border checks by calculating and monitoring the authorized duration of stay of third-country nationals admitted for short stays; 
  • assist in identifying third-country nationals who do not, or no longer, fulfil the conditions for entry or short stay within the territory of the Member States; 
  • identify and detect persons who have exceeded the authorized period of stay and enable the competent national authorities of the Member States to take appropriate measures; 
  • enable electronic verification of refusals of entry through the EES; 
  • facilitate the automation of border checks for third-country nationals; 
  • enable visa authorities to access information on the lawful use of previous visas; 
  • inform third-country nationals of the remaining duration of their authorized stay; 
  • compile statistics on entries, exits, refusals of entry and overstays of third-country nationals in order to improve the assessment of overstay risks and support evidence-based Union migration policy; 
  • combat identity fraud and the misuse of travel documents. 

Purpose of Access to Personal Data

In accordance with Article 23(1) of Regulation (EU) 2017/2226, border authorities have access to the EES in order to:

  • verify the identity and previous registration of a third-country national; 

  • update EES records where necessary; and 

  • consult data to the extent necessary for carrying out border checks, preventing irregular immigration, and facilitating the management of migration flows.

Processing of Personal Data in the EES in Latvia

  • To ensure that the above purposes are achieved Personal data are processed by the State Border Guard of the Republic of Latvia. Please see the contact information below.

  • Ministry of the Interior Digital Centre ensures the technical operation of the EES and provides access to it in accordance with Article 38(2) of Regulation (EU) 2017/2226 and Section 9.³(3) of the State Border Law. 

  • Personal data processing within the EES is independently supervised by the Data State Inspectorate in accordance with applicable data protection legislation. 

  • All processing of personal data in the EES is carried out in compliance with applicable data protection rules and safeguards.

More information: https://travel-europe.europa.eu/ees/data-held-by-ees

Legal Framework Applicable to the Processing of Personal Data in the Entry/Exit System (EES)

The processing of personal data in the Entry/Exit System (EES) is governed by the following legal acts:

  • Regulation (EU) 2017/2226 of the European Parliament and of the Council establishing an Entry/Exit System (EES) to register entry and exit data and refusal of entry data of third-country nationals crossing the external borders of the Member States, determining the conditions for access to the EES for law enforcement purposes, and amending the Convention implementing the Schengen Agreement; 

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR) (Text with EEA relevance); 

  • Regulation (EU) 2016/399 of the European Parliament and of the Council on a Union Code on the rules governing the movement of persons across borders (Schengen Borders Code); 

  • Regulation (EC) No 767/2008 of the European Parliament and of the Council concerning the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas; 

  • In the Republic of Latvia, the operation of the Entry/Exit System (EES) is regulated by Section 9.³ of the State Border Law

What Personal Data Are Processed?

When carrying out checks at the external borders of the Member States, Article 50 of Regulation (EU) 2017/2226 requires the processing of personal data as a mandatory condition for assessing compliance with the entry conditions.

Pursuant to Article 16 of Regulation (EU) 2017/2226, the following personal data are processed:

  • surname; first name(s); date of birth; nationality or nationalities; sex; 

  • type and number of the travel document(s); three-letter code of the issuing country of the travel document(s); 

  • expiry date of the travel document(s); 

  • facial image referred to in Article 15 of Regulation (EU) 2017/2226. 

What Are the Consequences of Not Providing the Requested Data?

In accordance with Article 50(1)(e) of Regulation (EU) 2017/2226, entry shall be refused where the data subject refuses to provide the biometric data required for registration, verification, or identification in the Entry/Exit System (EES).

Who Has Access to Personal Data?

Only the competent authorities of the Member States may access personal data for the purposes of border management, facilitation of border crossings, immigration, and law enforcement.

  • In the Republic of Latvia, access to the EES is granted to competent public authorities in accordance with Regulation (EU) 2017/2226 and Section 9.³ of the State Border Law.

  • The following authorities are authorized to enter, amend, delete, and consult EES data:
  1. State Border Guard; 
  2. Office of Citizenship and Migration Affairs; 
  3. Diplomatic and Consular Missions of the Republic of Latvia. 

  • The following operational units of the Republic of Latvia are authorized to request access to data stored in the central EES database:
  1. State Security Service; 
  2. State Police; 
  3. State Border Guard; 
  4. Internal Security Bureau; 
  5. Corruption Prevention and Combating Bureau; 
  6. Military Police; 
  7. Military Intelligence and Security Service; 
  8. Constitution Protection Bureau; 
  9. State Revenue Service. 

How Long Are Personal Data Stored in the EES?

  • A personal file containing personal data shall be stored for three years and one day from the date of the last exit record or the last refusal of entry record, provided that no new entry record has been created during that period. 
  • If no exit is recorded after the authorized period of stay has expired, the personal data shall be stored for five years, starting from the date on which the authorized period of stay expired. 
  • Data relating to third-country nationals who are family members of European Union citizens (without a residence permit) shall be stored for no longer than one year following the recorded exit. Where no exit record exists, the data shall be stored for five years from the date of the last entry record. 
  • Upon expiry of the applicable retention period, all personal data shall be automatically deleted. 

Remaining Authorized Period of Stay and Overstay

  • Every person has the right to obtain information from a border guard regarding the maximum remaining authorised period of stay within the territory of the Member States. This information is available through the Visa Calculator at:

https://ec.europa.eu/assets/home/visa-calculator/calculator.htm?lang=en

Where available, travellers may also check their remaining authorised period of stay using self-service equipment installed at border crossing points.

  • If the authorised period of stay is exceeded, the person's data will automatically be included in the list of identified overstayers. This list is accessible only to the competent national authorities. Where a person has been identified as an overstayer, the competent authorities may decide to take further measures in accordance with the legislation of the Republic of Latvia, including issuing a return decision or imposing an entry ban.

However, if the person is able to provide the competent authorities with credible evidence demonstrating that the overstay resulted from unforeseen and serious circumstances, the competent authorities may correct or supplement the person's status in the EES and remove the individual from the list of identified overstayers.

Data Subject Rights Regarding the Processing of Personal Data

In accordance with Regulation (EU) 2016/679, the data subject has the right to:

  • request access from the data controller to their personal data; 
  • request the rectification or completion of inaccurate or incomplete personal data; 
  • request the erasure of personal data that have been processed unlawfully or request the restriction of their processing. 

How to enforce rights?

In Latvia, a data subject may exercise their rights by submitting a request to the data controller (the competent authority responsible for processing the data). Such a request may be submitted in any Member State operating the Entry/Exit System (EES).

Contact Information

State Border Guard of the Republic of Latvia

Address: 5 Rūdolfa Street, Riga, LV-1012, Latvia

E-mail: pasts@rs.gov.lv

Telephone: +371 67075601, +371 67075616 (24/7 hotline)

Website: https://www.rs.gov.lv/en

Data Protection Officer of the State Border Guard

E-mail: das@rs.gov.lv

Telephone: +371 67075676

If a request (for example, concerning access to, rectification, or erasure of personal data) is refused or if the response is considered unsatisfactory, the data subject has the right to lodge a complaint with the Data State Inspectorate concerning an alleged infringement of their rights.

To enable the competent authority to examine the request, the application should include the following information:

  • first name and surname; 
  • date of birth; 
  • nationality; 
  • type and number of the travel document; 
  • contact details; 
  • the subject matter of the request; and 
  • any information that will assist in identifying the relevant personal data. 

Lodging a Complaint

In accordance with the division of responsibilities between the authorities of the Member States and the relevant European Union agencies, complaints may be submitted:

  • to the national supervisory authority responsible for personal data protection in the relevant Member State (in Latvia, the Data State Inspectorate), for example, where you believe that your personal data have been incorrectly recorded or processed; 

  • to the European Data Protection Supervisor (EDPS) in matters relating to the processing of personal data by European Union agencies, including Frontex, eu-LISA, and Europol. 

Contact Information

Data State Inspectorate

Address: 17 Elijas Street, Riga, LV-1050, Latvia

E-mail: pasts@dvi.gov.lv

Website: https://www.dvi.gov.lv/en

European Data Protection Supervisor (EDPS)

Address: Rue Wiertz 60, B-1047 Brussels, Belgium

E-mail: edps@edps.europa.eu

Website: https://edps.europa.eu

Further information on the processing of personal data by the State Border Guard of the Republic of Latvia and on the rights of data subjects is available on the official website of the State Border Guard under the section https://www.rs.gov.lv/en/privacy-policy