Law / Estonia

Estonia

privacy

Estonia's private-sector regime is the General Data Protection Regulation (GDPR) plus the Personal Data Protection Act (Isikuandmete kaitse seadus, RT I, 04.01.2019, 11), enforced by the Estonian Data Protection Inspectorate (AKI). Estonia does not recognize an ordinary administrative fine; AKI pursues a GDPR fine through misdemeanor proceedings instead, per secondary commentary not independently confirmed against primary legislative text this pass.

The Act's own consolidated text could not be extracted through crawler infrastructure this pass (the official gazette serves a client-rendered application shell), so the Act's specific derogation provisions are not restated here beyond the GDPR baseline. As at 2026-08-24; later amendment is not independently confirmed.

15 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Estonia

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2019-01-15 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the Estonian Data Protection Inspectorate (AKI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Estonia-specific narrowing of this timeline was independently confirmed this pass.

What it asks of an app

Comprehensive regime

Personal Data Protection Act (Isikuandmete kaitse seadus)

cite Isikuandmete kaitse seadus, RT I, 04.01.2019, 11, adopted 12 December 2018 stage In effect since 2019-01-15 source Riigi Teataja official gazette listing

The Personal Data Protection Act (PDPA) gives the General Data Protection Regulation (GDPR) domestic effect in Estonia and is enforced by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI). Estonia's official gazette serves the Act's own text as a client-rendered page that could not be extracted through crawler infrastructure this pass, so the Act's specific derogation sections are not independently confirmed and are not restated here; the regime is instead described at the GDPR-baseline level.

Distinctively, Estonia's Information System Authority (RIA) operates a citizen-facing Data Tracker (Andmejalgija) that lets a person see, in one place, which public-sector systems connected via X-Road have processed their data, an operational implementation of the GDPR Article 15 access right rather than a separate statutory right.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Estonia

cite Regulation (EU) 2016/679, Arts. 44-50 stage In effect since 2019-01-15 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Estonia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Secondary commentary reports Estonia imposes no additional derogation beyond this General Data Protection Regulation (GDPR) Chapter V baseline; not independently confirmed against the Act's own text this pass.

What it asks of an app

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Estonia

cite Regulation (EU) 2016/679, Arts. 15-22; Isikuandmete kaitse seadus stage In effect since 2019-01-15 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect, applied in Estonia through the Personal Data Protection Act.

The public sector's access right is distinctively implemented as unified infrastructure through RIA's Data Tracker service, letting a citizen see which public-sector systems have processed their data in one place rather than requesting this separately from each controller. No Estonia-specific derogation narrowing these rights was independently confirmed this pass.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and AKI Enforcement in Estonia

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2019-01-15 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.

Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; AKI imposes a General Data Protection Regulation (GDPR) fine through misdemeanor proceedings, a criminal-procedure-adjacent track, under the Penal Code, per secondary commentary (not independently confirmed against primary legislative text this pass), with amendments reported effective 1 November 2023 that extended the limitation period and applied the GDPR's own EUR 20 million or 4 percent ceiling as controlling.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Estonia

cite Regulation (EU) 2016/679, Art. 9 stage In effect since 2019-01-15 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Estonian statutory enumeration or illustrative list narrowing or expanding this definition was read this pass, and none is asserted; the Personal Data Protection Act's own text did not extract through crawler infrastructure, and the Estonian Data Protection Inspectorate's thematic-inspection page returned no usable content. No AKI guidance or enforcement decision naming facial recognition or voice data specifically was located.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.