Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2019-01-15
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the Estonian Data Protection Inspectorate (AKI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Estonia-specific narrowing of this timeline was independently confirmed this pass.
What it asks of an app →
Comprehensive regime
cite Isikuandmete kaitse seadus, RT I, 04.01.2019, 11, adopted 12 December 2018
stage In effect
since 2019-01-15
source Riigi Teataja official gazette listing
The Personal Data Protection Act (PDPA) gives the General Data Protection Regulation (GDPR) domestic effect in Estonia and is enforced by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI). Estonia's official gazette serves the Act's own text as a client-rendered page that could not be extracted through crawler infrastructure this pass, so the Act's specific derogation sections are not independently confirmed and are not restated here; the regime is instead described at the GDPR-baseline level.
Distinctively, Estonia's Information System Authority (RIA) operates a citizen-facing Data Tracker (Andmejalgija) that lets a person see, in one place, which public-sector systems connected via X-Road have processed their data, an operational implementation of the GDPR Article 15 access right rather than a separate statutory right.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-50
stage In effect
since 2019-01-15
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Estonia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Secondary commentary reports Estonia imposes no additional derogation beyond this General Data Protection Regulation (GDPR) Chapter V baseline; not independently confirmed against the Act's own text this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 15-22; Isikuandmete kaitse seadus
stage In effect
since 2019-01-15
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect, applied in Estonia through the Personal Data Protection Act.
The public sector's access right is distinctively implemented as unified infrastructure through RIA's Data Tracker service, letting a citizen see which public-sector systems have processed their data in one place rather than requesting this separately from each controller. No Estonia-specific derogation narrowing these rights was independently confirmed this pass.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2019-01-15
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.
Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; AKI imposes a General Data Protection Regulation (GDPR) fine through misdemeanor proceedings, a criminal-procedure-adjacent track, under the Penal Code, per secondary commentary (not independently confirmed against primary legislative text this pass), with amendments reported effective 1 November 2023 that extended the limitation period and applied the GDPR's own EUR 20 million or 4 percent ceiling as controlling.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2019-01-15
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Estonian statutory enumeration or illustrative list narrowing or expanding this definition was read this pass, and none is asserted; the Personal Data Protection Act's own text did not extract through crawler infrastructure, and the Estonian Data Protection Inspectorate's thematic-inspection page returned no usable content. No AKI guidance or enforcement decision naming facial recognition or voice data specifically was located.
What it asks of an app →