Law note · Estonia

GDPR Articles 82-83 and AKI Enforcement in Estonia

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2019-01-15 reviewed 2026-08-24

The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.

Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; AKI imposes a General Data Protection Regulation (GDPR) fine through misdemeanor proceedings, a criminal-procedure-adjacent track, under the Penal Code, per secondary commentary (not independently confirmed against primary legislative text this pass), with amendments reported effective 1 November 2023 that extended the limitation period and applied the GDPR's own EUR 20 million or 4 percent ceiling as controlling.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

  • Expect AKI to pursue a General Data Protection Regulation (GDPR) fine against your processing of personal data of a person in Estonia through a misdemeanor proceeding rather than a direct administrative sanction.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, high_risk_decisions, processes_biometrics, processes_voice

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
secondary commentary on Estonia's misdemeanor-track fine mechanism, not independently confirmed against primary legislative text

← Back to the example  ·  Lint your app →