Law note · Estonia

GDPR Article 22 and Data Subject Rights as Applied in Estonia

cite Regulation (EU) 2016/679, Arts. 15-22; Isikuandmete kaitse seadus stage In effect since 2019-01-15 reviewed 2026-08-24

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect, applied in Estonia through the Personal Data Protection Act.

The public sector's access right is distinctively implemented as unified infrastructure through RIA's Data Tracker service, letting a citizen see which public-sector systems have processed their data in one place rather than requesting this separately from each controller. No Estonia-specific derogation narrowing these rights was independently confirmed this pass.

What it asks of an app

  • Honor a person's request to access, rectify, erase, restrict, port, or object to processing of their personal data in Estonia within one month of receipt.
  • Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Estonia, under General Data Protection Regulation (GDPR) Article 22.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, high_risk_decisions

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
RIA Data Tracker service page, fetched and read directly

← Back to the example  ·  Lint your app →