Law note · Estonia
Personal Data Protection Act (Isikuandmete kaitse seadus)
The Personal Data Protection Act (PDPA) gives the General Data Protection Regulation (GDPR) domestic effect in Estonia and is enforced by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI). Estonia's official gazette serves the Act's own text as a client-rendered page that could not be extracted through crawler infrastructure this pass, so the Act's specific derogation sections are not independently confirmed and are not restated here; the regime is instead described at the GDPR-baseline level.
Distinctively, Estonia's Information System Authority (RIA) operates a citizen-facing Data Tracker (Andmejalgija) that lets a person see, in one place, which public-sector systems connected via X-Road have processed their data, an operational implementation of the GDPR Article 15 access right rather than a separate statutory right.
What it asks of an app
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Estonia, including data collected by crawling.
- Honor a request made through, or equivalent to, RIA's Data Tracker service for an overview of operations performed on a person's data by a public-sector controller connected via X-Road, as an implementation of the GDPR Article 15 access right.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot
Primary source: Riigi Teataja official gazette listing
RIA (Estonian Information System Authority), Data Tracker service page, fetched and read directly