Law note · Estonia
GDPR Articles 82-83 and AKI Enforcement in Estonia
The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.
Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; AKI imposes a General Data Protection Regulation (GDPR) fine through misdemeanor proceedings, a criminal-procedure-adjacent track, under the Penal Code, per secondary commentary (not independently confirmed against primary legislative text this pass), with amendments reported effective 1 November 2023 that extended the limitation period and applied the GDPR's own EUR 20 million or 4 percent ceiling as controlling.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app
- Expect AKI to pursue a General Data Protection Regulation (GDPR) fine against your processing of personal data of a person in Estonia through a misdemeanor proceeding rather than a direct administrative sanction.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, high_risk_decisions, processes_biometrics, processes_voice
Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
secondary commentary on Estonia's misdemeanor-track fine mechanism, not independently confirmed against primary legislative text