EnglishET
Estonia flag

Estonia

Estonia Data Privacy Laws: GDPR, PDPA, and AKI Enforcement (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 32 primary sources cited on this page. How we verify our legal content

Estonia Data Privacy Laws: GDPR, PDPA, and AKI Enforcement (2026)

Frequently Asked Questions

What is Estonia's main data protection law?

Estonia's data protection framework has two layers. The EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applies directly as binding EU law. The national Personal Data Protection Act (Isikuandmete kaitse seadus), in force from 15 January 2019, supplements the GDPR in areas where the regulation grants member states discretion. Key national rules include setting the children's consent age at 13, special grounds for journalistic and research processing, and a chapter of misdemeanour offences that the AKI prosecutes itself as the extrajudicial body. The Act contains no separate regime for the national identification code (isikukood), and criminal liability for unlawful disclosure of personal data sits in the Penal Code rather than the PDPA. The Andmekaitse Inspektsioon (AKI) enforces both instruments.

What constitutional rights protect personal data in Estonia?

Article 26 of the Estonian Constitution guarantees inviolability of private and family life. Government agencies may not interfere with private life except in circumstances and under procedures provided by law. Article 44 guarantees the right of citizens to access information about themselves held by government agencies and public archives. Article 43 guarantees confidentiality of communications, including electronic messages. Together these provisions give the AKI's enforcement authority a constitutional foundation that Estonian courts have upheld in regulatory-challenge proceedings.

What did the November 2023 amendment to Estonian data protection law change?

Less than is often reported, and it did not touch the fine ceiling. The PDPA's maxima were already GDPR-level when the Act took effect on 15 January 2019: EUR 20 million or 4 percent of worldwide annual turnover for the most serious breaches, EUR 10 million or 2 percent for the rest. The act in force from 1 November 2023 changed the Penal Code instead. It rewrote the rules on the liability of legal persons, set the court-imposed pecuniary punishment on a legal person at EUR 4,000 to 40,000,000, and inserted a provision letting a special act set misdemeanour fines on a different basis and in a different amount than the general cap of EUR 100 to 400,000. Its only PDPA change was a three-year limitation period for data-protection misdemeanours. That Penal Code provision was itself repealed on 6 July 2025, and the derogation now sits in the second sentence of Penal Code section 1(1).

What was the Apotheka / Allium UPI data breach fine?

In September 2025, the AKI imposed Estonia's largest-ever data protection fine of EUR 3 million on Allium UPI OÜ, the operator of the Apotheka pharmacy loyalty program. A 2024 cyberattack exposed personal data of more than 750,000 individuals, including names, identification codes, and purchase histories containing sensitive health-related items. The AKI found that Allium UPI had failed to implement multi-factor authentication, secure database backups, activity logging, and adequate access controls. The company appealed, and on 2 September 2026 Harju County Court dismissed the appeal and held the fine justified and proportionate. That is a county court judgment and can still be taken to the Supreme Court.

Does GDPR apply to e-residency businesses in Estonia?

Yes. Any company registered through Estonia's e-Residency program is an Estonian legal entity fully subject to the GDPR and the national PDPA, regardless of where the e-resident physically resides or operates. The AKI has enforcement authority over these companies. E-resident businesses must maintain processing records, implement security measures, appoint a DPO when required, conduct DPIAs for high-risk processing, respond to data subject rights requests within GDPR timelines, notify the AKI within 72 hours of qualifying breaches, and use valid transfer mechanisms for data sent outside the EEA.

How can Estonian citizens see who has accessed their personal data?

Estonian citizens can use the Data Tracker tool through the eesti.ee government portal. After logging in with a digital ID, citizens can view a complete log of which government agencies have accessed their personal data, when, and for what stated purpose. If a citizen believes an access was unauthorized, they can report it directly to the AKI. This transparency mechanism is built into Estonia's X-Road data exchange infrastructure and operationalizes the Article 44 constitutional right.

What are the breach notification requirements in Estonia?

Estonia follows the GDPR's standard breach notification rules. Data controllers must notify the AKI within 72 hours of becoming aware of a personal data breach likely to pose a risk to the rights and freedoms of individuals. When a breach poses a high risk to affected individuals, the controller must also notify those individuals directly without undue delay. The notification must describe the nature of the breach, categories of data affected, likely consequences, and measures taken. Failing to notify falls under the lower GDPR fine tier: up to EUR 10 million or 2 percent of annual worldwide turnover. Communications undertakings have a separate and stricter duty under Electronic Communications Act section 102-1 to notify the AKI at the first opportunity and to tell affected customers.

How does the EU AI Act interact with Estonian data protection law?

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Estonia from August 2024. Prohibitions on unacceptable-risk AI practices entered application on 2 February 2025. Requirements for high-risk AI systems apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. The AKI supervises data protection compliance in AI-driven processing, including profiling and automated decision-making under GDPR Articles 22 and 35. Estonia has named the Consumer Protection and Technical Regulatory Authority (TTJA) to the European Commission as its AI market surveillance contact point, but the Commission's list of 7 September 2026 records the Estonian designation as still pending final adoption, and TTJA describes the role as one it will take on in future. Organizations deploying high-risk AI systems must satisfy both AI Act conformity requirements and GDPR DPIA obligations.

Updates

Corrected the page's account of Estonian fining law: the Personal Data Protection Act has carried GDPR-level maximum fines since 2019 and they were not raised in November 2023, the Penal Code provision that reform inserted was repealed on 6 July 2025, and the Act contains no special rule for the national identification code. Also confined the automated-decision prohibition to law-enforcement processing, replaced the fabricated X-Road regulation number with Government Regulation No. 105 of 2016, updated the AKI statistics to the 2025 annual report published 31 March 2026, recorded Harju County Court's 2 September 2026 judgment upholding the EUR 3 million Allium UPI fine, corrected the Asper Biogene and Pere Sihtkapital outcomes, and noted that Estonia's designation of TTJA as its AI Act market-surveillance authority is still pending.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, while the 2 August 2026 transparency date is unchanged.

Expanded from approximately 2,650 to approximately 6,200 words. Added: constitutional basis (Articles 26, 43, 44); the Estonian framework for imposing GDPR fines; Apotheka / Allium UPI EUR 3 million fine (September 2025); Asper Biogene reversal (August 2025); Pere Sihtkapital annulment (May 2025); EU AI Act application timeline and Estonia national authorities; EDPB Guidelines 1/2024 on legitimate interests; legal bases for processing; data subject rights; international transfer framework; 2024-2026 recent developments section.

Reviewed and approved by an editor

Initial publication covering GDPR framework, AKI, e-Residency, X-Road, KSI blockchain.

Sources and References

  1. Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated text RT I, 06.03.2026, 10, in force 16 March 2026(riigiteataja.ee).gov
  2. Estonian Constitution(riigiteataja.ee).gov
  3. Andmekaitse Inspektsioon (AKI)(aki.ee).gov
  4. AKI Annual Report 2024(aki.ee).gov
  5. Apotheka Fine - ERR News(news.err.ee)
  6. RIA - Lessons from a Massive Data Leak(ria.ee).gov
  7. Magnusson - Enforcement Analysis(magnussonlaw.com)
  8. DataGuidance - Asper Biogene Fine(dataguidance.com)
  9. e-Residency Official Website(e-resident.gov.ee).gov
  10. e-Residency GDPR Compliance Guide(e-resident.gov.ee).gov
  11. X-Road Platform (e-Estonia)(e-estonia.com).gov
  12. X-Road RIA Documentation(ria.ee).gov
  13. KSI Blockchain(e-estonia.com).gov
  14. Electronic Identity eID (RIA)(ria.ee).gov
  15. Data Tracker - eesti.ee(eesti.ee).gov
  16. GDPR - EUR-Lex(eur-lex.europa.eu).gov
  17. EU AI Act - EUR-Lex(eur-lex.europa.eu).gov
  18. EDPB Guidelines 1/2024 on Legitimate Interests(edpb.europa.eu).gov
  19. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  20. Penal Code Amendment Act (fines arising from EU law), RT I, 11.03.2023, 1, adopted 22.02.2023, in force 01.11.2023(riigiteataja.ee).gov
  21. Competition Act Amendment Act, RT I, 05.07.2025, 1, in force 06.07.2025 (repeals Penal Code section 47(4))(riigiteataja.ee).gov
  22. Penal Code (Karistusseadustik), current consolidated text(riigiteataja.ee).gov
  23. Personal Data Protection Act Implementation Act, RT I, 13.03.2019, 2, in force 15.03.2019(riigiteataja.ee).gov
  24. Government Regulation No. 105 of 23.09.2016, Infosusteemide andmevahetuskiht (X-tee), consolidated text RT I, 28.04.2026, 13(riigiteataja.ee).gov
  25. Electronic Communications Act (Elektroonilise side seadus), current consolidated text(riigiteataja.ee).gov
  26. AKI publishes its 2025 annual report, 31 March 2026(aki.ee).gov
  27. AKI Annual Report 2025 - activity indicators(aastaraamat.aki.ee).gov
  28. AKI Annual Report 2025 - personal data breach notifications(aastaraamat.aki.ee).gov
  29. AKI Annual Report 2025 - significant court cases(aastaraamat.aki.ee).gov
  30. AKI: Harju County Court upholds the EUR 3 million Allium UPI fine, 2 September 2026(aki.ee).gov
  31. AKI: the Asper Biogene court dispute has ended(aki.ee).gov
  32. AKI: the Pere Sihtkapital court dispute has ended(aki.ee).gov
  33. AKI guidance, Chapter 5: data protection impact assessment(aki.ee).gov
  34. European Commission, Market surveillance authorities under the AI Act (updated 7 September 2026)(digital-strategy.ec.europa.eu).gov
  35. TTJA, Artificial intelligence systems (business guidance)(ttja.ee).gov
Share: