Law note · Estonia

Personal Data Protection Act (Isikuandmete kaitse seadus)

cite Isikuandmete kaitse seadus, RT I, 04.01.2019, 11, adopted 12 December 2018 stage In effect since 2019-01-15 reviewed 2026-08-24

The Personal Data Protection Act (PDPA) gives the General Data Protection Regulation (GDPR) domestic effect in Estonia and is enforced by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI). Estonia's official gazette serves the Act's own text as a client-rendered page that could not be extracted through crawler infrastructure this pass, so the Act's specific derogation sections are not independently confirmed and are not restated here; the regime is instead described at the GDPR-baseline level.

Distinctively, Estonia's Information System Authority (RIA) operates a citizen-facing Data Tracker (Andmejalgija) that lets a person see, in one place, which public-sector systems connected via X-Road have processed their data, an operational implementation of the GDPR Article 15 access right rather than a separate statutory right.

What it asks of an app

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Estonia, including data collected by crawling.
  • Honor a request made through, or equivalent to, RIA's Data Tracker service for an overview of operations performed on a person's data by a public-sector controller connected via X-Road, as an implementation of the GDPR Article 15 access right.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot

Primary source: Riigi Teataja official gazette listing
RIA (Estonian Information System Authority), Data Tracker service page, fetched and read directly

← Back to the example  ·  Lint your app →