Law note · Estonia

GDPR Articles 33-34, Breach Notification in Estonia

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2019-01-15 reviewed 2026-08-24

A controller must notify the Estonian Data Protection Inspectorate (AKI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Estonia-specific narrowing of this timeline was independently confirmed this pass.

What it asks of an app

  • Notify the Estonian Data Protection Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679

← Back to the example  ·  Lint your app →