Estonia
Estonia Data Privacy Laws: GDPR, PDPA, and AKI Enforcement (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 32 primary sources cited on this page. How we verify our legal content

Under the GDPR and Estonia's Personal Data Protection Act (Isikuandmete kaitse seadus), in force since 15 January 2019, the Andmekaitse Inspektsioon (AKI) enforces data privacy for all controllers in Estonia, with maximum penalties of EUR 20 million or 4 percent of global annual turnover under GDPR Article 83(5).
Estonia operates one of the world's most advanced digital states. More than 99 percent of government services are available online, every citizen carries a chip-enabled digital ID card, and the X-Road backbone processes over a billion data transactions annually. That level of digital integration demands an equally rigorous data-protection framework.
This article covers Estonia's complete data privacy regime: the constitutional foundation, the EU GDPR, the national Personal Data Protection Act, the AKI's enforcement record through 2025-2026, the landmark Apotheka fine, the Penal Code changes that shaped how those fines can be imposed, the EU AI Act overlay, and practical compliance guidance for businesses and e-residents.
This article addresses Estonian data privacy law as of 10 September 2026. It covers the EU GDPR, the Estonian Personal Data Protection Act 2019, and AKI enforcement through September 2026. It does not provide legal advice; consult a qualified Estonian data protection lawyer for guidance on specific situations.
Quick Answer
Estonia's data protection framework rests on two layers. The EU General Data Protection Regulation (GDPR) applies directly as binding EU law. The national Personal Data Protection Act (PDPA), in force since 15 January 2019, supplements the GDPR in areas where member states retain discretion. The Andmekaitse Inspektsioon (AKI) enforces both. The PDPA has set maximum fines of EUR 20 million or 4 percent of worldwide annual turnover since 2019, and the AKI imposes them through Estonian misdemeanour proceedings. The AKI used that power in September 2025, fining Allium UPI EUR 3 million for the Apotheka pharmacy breach, and Harju County Court upheld that fine on 2 September 2026.
For the broader EU framework that applies in Estonia, see the EU data privacy laws overview.

Constitutional Foundation
Estonia's data privacy rules are rooted in constitutional guarantees. The Constitution of the Republic of Estonia establishes the foundational rights that all subsequent data protection legislation must respect.
Article 26 provides that everyone is entitled to the inviolability of private and family life. Government agencies, local authorities, and their officials may not interfere with any person's private or family life except in cases and pursuant to procedures provided by law to protect public health, public morality, public order, or the rights and freedoms of others, or to prevent a criminal offence or apprehend an offender. The Constitutional Review Chamber of the Supreme Court has interpreted Article 26 broadly to include personal autonomy, identity, personal immunity, and informational privacy.
Article 44 establishes the right of every Estonian citizen to access information held about them by government agencies and local authorities and in government archives. By law, the same right extends to citizens of foreign states and stateless persons in Estonia. This provision is the constitutional origin of the data-subject access right that the PDPA and GDPR operationalize.
Article 43 complements these protections by guaranteeing the confidentiality of messages, which the Supreme Court has extended to cover electronic communications. Together, Articles 26, 43, and 44 form a constitutional data-privacy triangle that gives AKI enforcement authority a firm legal foundation when challenged in court.

GDPR and the Estonian Personal Data Protection Act
As an EU member state, Estonia is bound by the General Data Protection Regulation (GDPR), Regulation (EU) 2016/679. The GDPR applies directly and uniformly across all EU member states without requiring national transposition. It provides the default rules for lawful processing, data subject rights, breach notification, international transfers, and penalties.
Estonia supplements the GDPR through two national instruments:
- The Personal Data Protection Act (Isikuandmete kaitse seadus), adopted 12 December 2018 and in force from 15 January 2019. It has been amended since, most recently with effect from 16 March 2026.
- The Personal Data Protection Act Implementation Act, adopted 20 February 2019, published as RT I, 13.03.2019, 2, and in force from 15 March 2019.
One practical warning for anyone reading the Act in English. Riigi Teataja's English translation of the Personal Data Protection Act is the redaction that was in force from 15 January 2019 to 31 October 2023. No later redaction has been translated, so the Estonian consolidated text is the only authoritative current version.
Neither law replaces the GDPR. Both fill specific gaps or exercise the discretion the GDPR explicitly leaves to member states.
Key National Provisions
Children's consent age. Estonia set the minimum age for children to independently consent to information society services at 13. This is the lowest threshold the GDPR permits under Article 8(1). For children under 13, consent must be given or authorized by a parent or legal guardian.
National identification code (isikukood). The Estonian personal identification code is a unique 11-digit number assigned to every registered resident. The PDPA sets no special legal-ground test for it. The word isikukood does not appear anywhere in the consolidated Act, and the Act has no identification-code section. Processing an identification code needs an ordinary GDPR Article 6 legal basis like any other identifier, and GDPR Article 9 as well where the surrounding processing reveals a special category of data. Because the isikukood appears across virtually all Estonian public and private databases, controllers should still be able to explain why they need it and keep its use proportionate.
Automated decision-making by law-enforcement authorities. PDPA section 21 prohibits decisions based solely on automated processing, including profiling, that carry adverse legal consequences for a data subject or otherwise significantly affect them, unless a law permits the decision and lays down safeguards for the data subject's rights, freedoms and legitimate interests. That prohibition sits in the chapter on processing by law-enforcement authorities, and section 12(1) limits the chapter to processing for preventing, detecting and prosecuting offences and enforcing punishments. For private and ordinary public-sector controllers the applicable rule is GDPR Article 22, described under Data Subject Rights below.
Special category data. Processing health data, biometric data, genetic data, and similar sensitive categories is prohibited unless a specific legal ground under GDPR Article 9(2) applies. Explicit consent is required where consent is the chosen ground.
Offences and penalties. Chapter 6 of the PDPA, sections 62 to 73, creates misdemeanour offences rather than criminal offences, and section 73(2) makes the AKI the extrajudicial body that conducts those proceedings. Penal Code sections 157 and 157-1(1) create further misdemeanour offences for unlawful disclosure of personal data, to which PDPA sections 71 and 72 expressly yield; criminal liability proper arises under section 157-1(2), which carries a pecuniary punishment or up to one year of imprisonment where the disclosure was for gain or caused damage. Penal Code section 157-1(2) carries a pecuniary punishment or up to one year of imprisonment where the disclosure was for gain or caused damage.
Data Protection Officer Requirements
Estonia follows GDPR Article 37 without adding national-level DPO appointment requirements. A DPO must be designated when the controller or processor is a public authority or body (with the exception of courts acting in their judicial capacity); when core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale; or when core activities consist of processing special categories of data or personal data relating to criminal convictions on a large scale.
The DPO must be appointed based on professional qualifications and expert knowledge of data protection law and practice. The GDPR's independence requirement is strict: the DPO must not receive instructions on the exercise of their tasks and must not be dismissed or penalized for performing those tasks. The Asper Biogene case illustrates what happens when organizations treat the DPO role as a formality.

The Data Protection Inspectorate (AKI)
The Andmekaitse Inspektsioon (AKI) is Estonia's independent national supervisory authority for data protection. It is also the freedom-of-information regulator, giving it a dual mandate unusual among EU data protection authorities.
The AKI operates under GDPR Article 51 as Estonia's lead supervisory authority for controllers and processors established in Estonia. For matters involving cross-border processing, it participates in the European Data Protection Board's consistency and one-stop-shop mechanisms alongside supervisory authorities from other member states.
Powers
The AKI's enforcement toolkit includes:
- Conducting investigations, audits, and on-site inspections.
- Issuing warnings and reprimands.
- Ordering controllers and processors to bring processing operations into compliance within a specified time.
- Imposing temporary or permanent bans on processing.
- Ordering rectification, restriction, or erasure of data.
- Revoking certifications.
- Imposing fines through misdemeanour proceedings (the GDPR's administrative fines).
- Referring matters for criminal prosecution.
The AKI also provides advisory services to organizations, publishes guidance on specific processing activities, and issues opinions on draft legislation with data protection implications. It does not run a public register of data protection officers: controllers notify their DPO's contact details to the AKI under GDPR Article 37(7), and the register of processors and responsible persons that PDPA section 74 carried over from the pre-2019 law was an archived legacy register, retained for at most five years from 15 January 2019 and reachable only by application.
Advisory and Supervisory Statistics (2025)
The AKI published its 2025 annual report on 31 March 2026. Key figures for 2025:
- 1,380 complaints received, a record annual total.
- 1,784 requests for clarification, memoranda, demand letters and information requests, including media queries.
- 1,383 calls to the advisory telephone line, 77 percent of them about the Personal Data Protection Act.
- 46 supervisory proceedings opened on the AKI's own initiative, 30 percent of them prompted by a data leak.
- 251 personal data breach notifications, up about a third on 2024 and the highest annual figure since May 2018. Those breaches touched 3,030,325 people in Estonia and abroad in total.
- 50 court cases handled during the year.
For comparison, the 2024 annual report, published on 11 March 2025, recorded 4,162 inquiries of every kind, 184 breach notifications affecting roughly 910,000 people, 12 administrative offence proceedings and EUR 79,100 in fines imposed during 2024.
The fine totals look modest in isolation. The Allium UPI / Apotheka decision issued in September 2025 was an order of magnitude larger, and Harju County Court upheld it on 2 September 2026.
Legal Bases for Processing
Under the GDPR, every personal data processing operation must rest on one of six legal bases in Article 6(1). Estonian organizations rely on these bases as follows.
Consent (Article 6(1)(a)). Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes do not constitute valid consent. Consent for newsletter subscriptions, direct marketing, and use of photographs and video materials are common Estonian examples. Consent must be obtained through a clear affirmative action, and organizations must be able to demonstrate that valid consent was obtained.
Contract (Article 6(1)(b)). Processing is lawful when necessary for performing a contract with the data subject or taking pre-contractual steps at the data subject's request. E-resident businesses commonly rely on this basis for processing personal data needed to deliver contracted services.
Legal obligation (Article 6(1)(c)). Where Estonian law or EU law requires processing, for example tax record-keeping obligations under Estonian tax law, this basis applies.
Vital interests (Article 6(1)(d)). Applies in emergency situations where processing is necessary to protect the life of a data subject or another natural person.
Public task (Article 6(1)(e)). Applies to processing by public authorities in the performance of their tasks. This is the primary basis for most AKI-supervised government processing in Estonia.
Legitimate interests (Article 6(1)(f)). Organizations may process personal data in pursuit of legitimate interests provided those interests are not overridden by the interests or fundamental rights of data subjects. A balancing test is required. Data subjects have the right to object to processing on this basis under GDPR Article 21. The EDPB's October 2024 Guidelines 1/2024 on legitimate interests, directly applicable in Estonia, require organizations to document their balancing assessment.
Data Subject Rights
Individuals whose data is processed by Estonian controllers or processors hold the full set of GDPR data subject rights.
Right of access (Article 15). Data subjects may request confirmation of whether their personal data is being processed and obtain a copy of that data together with information about the purposes, recipients, retention periods, and their rights. Controllers must respond within one month, extendable by two additional months for complex or numerous requests.
Right to rectification (Article 16). Inaccurate personal data must be corrected without undue delay. Incomplete data may be completed, including by providing a supplementary statement.
Right to erasure (Article 17). Data subjects may request deletion when data is no longer necessary for its original purpose, when consent is withdrawn and no other legal ground exists, when the subject objects and no overriding legitimate grounds exist, when data has been unlawfully processed, or when erasure is required by EU or Estonian law.
Right to restriction of processing (Article 18). Data subjects may request that processing be restricted while accuracy is contested, while an objection is pending, or when processing is unlawful but the subject prefers restriction to erasure.
Right to data portability (Article 20). Where processing is based on consent or contract and carried out by automated means, data subjects may request their personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to object (Article 21). Data subjects may object at any time to processing based on legitimate interests or the performance of a public task, including profiling. The controller must cease processing unless it can demonstrate compelling legitimate grounds that override the data subject's interests.
Rights in automated decision-making (Article 22). Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, unless specific conditions apply.
The AKI provides a complaint mechanism for data subjects who believe their rights have been violated. Complaints are free of charge.
Breach Notification
Estonia follows the GDPR's two-track breach notification requirement.
Supervisory authority notification. When a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the controller must notify the AKI without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach. If notification is made after 72 hours, it must be accompanied by reasons for the delay. The notification must describe the nature of the breach, the categories and approximate number of data subjects and personal data records affected, the likely consequences, and the measures taken or proposed to address the breach.
Processors must notify controllers without undue delay after becoming aware of a breach, enabling the controller to meet the 72-hour window.
Individual notification. When a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must also communicate the breach to the affected individuals without undue delay. This communication must describe the nature of the breach in clear and plain language, provide the name and contact details of the DPO or other contact point, describe the likely consequences, and describe the measures taken or proposed.
Individual notification is not required when the controller has implemented appropriate technical protection measures such as encryption that render the data unintelligible, when subsequent measures ensure high risk is no longer likely to materialize, or when notification would involve disproportionate effort (in which case a public communication is permitted).
The AKI received 251 breach notifications in 2025, up from 184 in 2024. Failure to notify is subject to fines in the lower GDPR tier: up to EUR 10 million or 2 percent of global annual turnover.
Communications undertakings carry a second, stricter track that sits alongside the GDPR rule. Electronic Communications Act section 102-1(2) requires a communications undertaking to notify the AKI of a personal data breach at the first opportunity rather than within a 72-hour window, and section 102-1(4) requires it to tell the affected customer where the breach may harm that person's personal data or privacy. Section 102-1(8) requires the undertaking to keep its own record of breaches.
How Estonia Imposes GDPR Fines
Estonia's fine maxima were never raised in 2023, and it is worth being precise about this because the opposite is widely repeated.
The PDPA has prescribed GDPR-level maxima since the day it took effect. Sections 65 to 70 have carried a maximum of EUR 20 million or 4 percent of worldwide annual turnover, and sections 62 to 64 a maximum of EUR 10 million or 2 percent, since 15 January 2019. The consolidated text in force on 1 November 2023 is word for word identical to the 2019 text on those figures.
What has been contested is the Estonian machinery for imposing them. AKI fines are misdemeanour penalties, and the Penal Code's general cap on misdemeanour fines for legal persons, in section 47(2), is EUR 100 to 400,000.
The act that entered into force on 1 November 2023, RT I, 11.03.2023, 1, addressed that in the Penal Code rather than in the PDPA. It rewrote Penal Code section 14 on the liability of legal persons, set the court-imposed pecuniary punishment on a legal person in section 44(8) at EUR 4,000 to 40,000,000, and inserted a new section 47(4) allowing the special part of the Penal Code or another act to set misdemeanour fines on a different basis and in a different amount. Its only change to the PDPA was to add section 73(1), a three-year limitation period for data-protection misdemeanours.
That vehicle has since been replaced. The Competition Act amendment act, RT I, 05.07.2025, 1, repealed Penal Code section 47(4) with effect from 6 July 2025 and moved the derogation into a new second sentence of Penal Code section 1(1), which allows other acts to depart from the General Part of the Penal Code where the particular field being regulated requires it. The same act reset Penal Code section 81(3) to a flat two-year limitation for misdemeanours, leaving PDPA section 73(1) to supply the three-year period in data-protection cases.
The courts have not settled the question. In its 2025 annual report the AKI records that the misdemeanour proceedings against Viljandi Hospital, Pere Sihtkapital and Asper Biogene all ended with the court terminating the case, and that for misdemeanours committed before 1 November 2023 a legal person cannot be fined for a GDPR breach at all, because the earlier wording of Penal Code section 14 was not compatible with EU law. Director General Pille Lehis has said that achieving legal clarity on whether and how Estonian administrative offence proceedings allow GDPR fines to be imposed is one of the authority's main objectives for the coming years.
Penalties and AKI Enforcement
Fine Tiers
The PDPA has implemented the GDPR's two-tier fine structure since it took effect in 2019.
Upper tier (GDPR Article 83(5)): Violations of the basic principles of processing, the conditions for consent, data subject rights, the transfer restrictions for international transfers, and member-state specific obligations attract fines of up to EUR 20,000,000 or up to 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.
Lower tier (GDPR Article 83(4)): Obligations of controllers and processors, certification bodies, and monitoring bodies attract fines of up to EUR 10,000,000 or up to 2 percent of total worldwide annual turnover, whichever is higher. Failures to notify data breaches fall in this tier.
When determining fine amounts, the AKI considers: the nature, gravity, and duration of the infringement; its intentional or negligent character; steps taken to mitigate damage; degree of cooperation with the supervisory authority; the categories of personal data affected; how the supervisory authority became aware of the infringement; and whether previous infringements were committed by the same controller or processor.
Notable Enforcement Actions
Allium UPI / Apotheka (September 2025) -- EUR 3,000,000. The AKI imposed its largest-ever fine of EUR 3 million on Allium UPI OÜ, the operator of the Apotheka pharmacy loyalty program. A cyberattack in early 2024 exposed personal data of more than 750,000 individuals, including children and other vulnerable groups. The compromised files contained first and last names, personal identification codes (isikukood), language, gender, email addresses, telephone numbers, home addresses, and detailed purchase histories for individuals who had joined the loyalty program between 2014 and 2020. The purchase histories included records of pregnancy and ovulation tests, hearing-aid accessories, blood-pressure monitors, intimate hygiene products, and skin-care items, all of which carry significant sensitivity under GDPR given their health-related nature.
The AKI investigation found that Allium UPI had failed to implement multi-factor authentication on systems holding the loyalty program database, had not secured database backups, had absent activity logging, and had deployed weak access controls that did not restrict internal access to the full dataset. The AKI described the attitude toward customer data as negligent. Allium UPI appealed. On 2 September 2026 Harju County Court dismissed the appeal, held the EUR 3 million fine justified and proportionate, and left the company to bear the costs, singling out failures in administrator-account protection, security monitoring and the storage of backups. The AKI notes that this is a county court judgment and the proceedings are not yet closed; the company had 30 days to take the case to the Supreme Court.
The RIA (Information System Authority) published a post-incident technical analysis identifying systemic infrastructure failures.
Asper Biogene (January 2025) -- EUR 85,000 fined, annulled. In January 2025 the AKI fined Asper Biogene EUR 85,000 over a late-2023 cyberattack that compromised approximately 100,000 files of genetic and health data. The penalty was split in two: EUR 80,000 for failing to secure the processing, and EUR 5,000 for appointing the company's sole managing board member as DPO, which breached the GDPR's independence and competence requirements. Tartu County Court annulled the fine on 26 June 2025. It agreed that the DPO appointment was a violation, since a board member who decides the purposes and means of processing cannot independently perform the DPO's tasks, but terminated that limb on expediency grounds because culpability was low and the company had since appointed a competent specialist and added security measures. It terminated the security limb because the conduct predated the amendments that more clearly regulate the liability of legal persons. The Supreme Court of Estonia declined to hear the AKI's appeal in August 2025, making the annulment final.
Pere Sihtkapital (June 2024) -- EUR 30,000 fined, annulled. AKI imposed a EUR 30,000 fine on this population-policy foundation over a commissioned survey of childless women that drew on data from Estonia's population register and gathered sensitive information about income, education, living conditions, sexual habits, political views and beliefs. Harju County Court annulled the fine on 13 May 2025, and the Supreme Court declined to hear the AKI's cassation appeal in June 2025.
Neither outcome was a review of whether the fine was proportionate. Both turned on Estonian legal-person liability and misdemeanour procedure. In Pere Sihtkapital the county court held that the wording of Penal Code section 14 then in force was not compatible with EU law and that the foundation could not have expected to be held liable; in Asper Biogene the security limb fell for the same reason and the DPO limb was ended on expediency grounds. The AKI's own summary is that no court instance assessed the processing against the GDPR on the merits. That gap, rather than judicial proportionality review, is the live weakness in Estonian data protection enforcement.
E-Residency and Data Privacy
Estonia's e-Residency program allows non-residents from anywhere in the world to establish and manage an EU-based company entirely online. More than 100,000 e-residents from over 170 countries have registered since the program launched in 2014.
Any company registered through e-Residency is an Estonian legal entity. GDPR and the PDPA apply in full, regardless of where the e-resident physically resides or operates.
Practical compliance obligations for e-resident businesses include maintaining records of processing activities under GDPR Article 30; implementing appropriate technical and organizational security measures under GDPR Article 32; appointing a DPO when required under GDPR Article 37; conducting DPIAs for high-risk processing under GDPR Article 35; responding to data subject rights requests within GDPR timelines; notifying the AKI within 72 hours of qualifying breaches; and using valid transfer mechanisms for data sent outside the EEA.
The AKI has full enforcement authority over e-resident companies. Public institutions and large enterprises in Estonia commonly require proof of GDPR alignment before entering contractual relationships, making compliance a commercial as well as a legal requirement.
For Estonia-specific recording and surveillance law, see Estonia recording laws.
X-Road: Secure Data Exchange Infrastructure
Estonia's X-Road (X-tee) is the backbone of the country's digital government. Originally developed and deployed in 2001 by the Information System Authority (RIA), X-Road enables encrypted, authenticated data exchange between government agencies, municipalities, and authorized private sector organizations. The platform processes over one billion transactions annually and has been adopted by more than 25 countries and territories.
Privacy-by-Design Architecture
Data flows directly between the sending and receiving party without passing through or being stored in a central hub. All outgoing data is digitally signed and encrypted using certificates issued by trusted Certification Authorities. All incoming data is authenticated and logged. Transaction metadata (headers) is logged and published as open data; the content of queries and responses remains private between communicating parties.
Citizen Data Tracker
One of X-Road's most significant privacy features is the Data Tracker tool available through the eesti.ee government portal. Any Estonian citizen or resident can log in with their digital ID and review a complete log of which government agencies have accessed their personal data and for what purpose. If a data subject believes an access was unauthorized, they can report it directly to the AKI. This transparency mechanism operationalizes the Article 44 constitutional right in real time.
X-Road Governance
Government of the Republic Regulation No. 105 of 23 September 2016, Infosüsteemide andmevahetuskiht, issued under Public Information Act section 43-9(1)(5), governs X-Road participation. An organization joins by applying to RIA, the centre responsible for administering X-Road, which processes membership, subsystem and security-server applications and publishes the joining and use conditions on its own website. Under section 5(2) the applicant then concludes a joining agreement with RIA that fixes the rights, obligations and liability of the parties. Section 5(4) obliges each member to keep its own information system secure and to have the measures it applies independently audited at least once every four years, and RIA may refuse an application where the applicant or its system does not meet the regulation's requirements. Data services themselves run on a separate use agreement between the providing and the using member under section 12, which must set the information security measures required for that service.
Digital ID, KSI Blockchain, and Data Integrity
Estonia's mandatory digital ID card (eID) is central to the digital society. Every Estonian citizen and permanent resident receives an ID card with an embedded microchip enabling secure digital authentication and legally binding electronic signatures. The card is used to access government services, sign contracts, vote in elections, access health records, and authenticate banking transactions.
In 2025, Estonia launched the eesti.ee mobile app to extend these capabilities to smartphones. The app uses time-limited QR codes and restricts identity data exposure to the minimum necessary for each specific transaction.
The KSI blockchain, developed in partnership with Guardtime from 2008 onward, ensures the integrity of data held in government registries. KSI creates a cryptographic hash of each data record and stores it on the blockchain. Any modification to the original data can be detected immediately, regardless of whether the change was made by an external attacker, an employee, or a government official. Government registries secured by KSI include the Healthcare Registry, the Property Registry, the Business Registry, the Succession Registry, the Digital Court System, and the State Gazette.
International Data Transfers
Estonia follows the GDPR's Chapter V framework for international transfers. Personal data may be transferred outside the EEA only when the European Commission has issued an adequacy decision for the receiving country; when appropriate safeguards exist (such as Standard Contractual Clauses adopted in June 2021, Binding Corporate Rules, or approved codes of conduct); or when one of the specific derogations in GDPR Article 49 applies.
For e-resident businesses, the transfer framework is practically significant. An e-resident based in a non-EEA country who transfers personal data from their Estonian company to servers in their home country must ensure a valid transfer mechanism is in place. Organizations relying on SCCs after the Schrems II judgment must conduct a transfer impact assessment (TIA) to verify that the receiving country's law does not undermine the SCCs' effectiveness. The AKI has aligned with EDPB guidance on transfer mechanisms.
EU AI Act Interaction
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. As an EU regulation, it applies directly in Estonia without national transposition.
Application Timeline in Estonia
- 2 February 2025: Prohibitions on unacceptable-risk AI practices entered application. These include AI systems using subliminal techniques to distort behavior, systems exploiting vulnerabilities of specific groups, most real-time remote biometric identification in public spaces, and social scoring by public authorities.
- 2 August 2025: Rules for general-purpose AI models and the AI governance framework became applicable.
- 2 August 2026: Article 50 transparency duties apply, including chatbot disclosure and deepfake labelling, along with the conformity-assessment and registration rules.
- 2 December 2027: Requirements for Annex III high-risk AI systems apply, moved from 2 August 2026 by the July 2026 Digital Omnibus.
- 2 August 2028: Requirements for Annex I high-risk AI built into regulated products apply, completing the application of the Act.
Estonia's National Governance
Estonia has named the Consumer Protection and Technical Regulatory Authority (TTJA) to the European Commission as its single point of contact for AI Act market surveillance. The designation is not complete. On the Commission's list of market surveillance authorities under the AI Act, last updated 7 September 2026, the Estonian entry is flagged as one where the national designation decision is still pending final adoption, and TTJA's own guidance for businesses says it will take on the competent authority role in the supervision of AI systems in future. The AKI already supervises data protection compliance within AI-driven processing, including profiling, automated decision-making, and high-risk AI systems that process personal data.
Estonia developed the AI and Data Action Plan (Kratt) 2024-2026 as its national implementation roadmap, led by the Ministry of Economic Affairs and Communications.
GDPR and AI Act Overlap
For organizations using AI systems in Estonia, the GDPR and AI Act overlap in key areas. GDPR Article 22 rights in automated decision-making apply alongside AI Act Article 86's right to explanation for AI-driven decisions. Providers of high-risk AI systems listed in AI Act Annex III must implement conformity assessments that intersect with GDPR DPIAs. AI Act Articles 10 and 17 data governance requirements complement the GDPR's data minimization, accuracy, and purpose limitation principles.
Organizations implementing AI systems in Estonia should conduct both a GDPR-based DPIA and an AI Act conformity assessment for high-risk applications.
Business Compliance Framework
Organizations operating in Estonia or processing personal data of Estonian residents should structure their compliance programs around the following elements.
Records of processing activities. GDPR Article 30 requires controllers with 250 or more employees to maintain written records of all processing activities. Smaller organizations must maintain the record when processing is likely to result in risk to data subjects, when processing is not occasional, or when it includes special category data. Given the size of recent Estonian fines, even smaller organizations should treat Article 30 records as standard practice.
Privacy notices. Controllers must provide individuals with transparent processing information at the time data is collected (GDPR Articles 13 and 14). Organizations processing the national identification code (isikukood) should specifically address that processing in their privacy notices.
Cookies and website tracking. For an ordinary business website the governing standard is the GDPR one. Estonia's Electronic Communications Act transposes the ePrivacy Directive, but its storage and processing rules bind communications undertakings: section 102(3) lets such an undertaking process communications data only if it explains the purposes clearly and gives the customer a way to refuse, and section 102(4) carves out processing whose sole purpose is delivering the service over the network or that is necessary for an information society service the customer expressly requested. On a website, cookies and trackers that process personal data and are not strictly necessary to deliver what the visitor asked for need consent meeting the GDPR test: a freely given, specific, informed and unambiguous affirmative act. Pre-ticked boxes and consent inferred from continued browsing do not meet it.
Security measures. GDPR Article 32 requires appropriate technical and organizational security measures. The Allium UPI case provides a concrete checklist of what the AKI treats as basic measures: multi-factor authentication, secured database backups, activity logging, and role-based access controls that limit who can access sensitive datasets.
Data protection impact assessments. The AKI publishes its own DPIA guidance and is explicit that its list of examples is advisory, supplementing rather than replacing the test in GDPR Article 35(1). The examples include large-scale systematic automated profiling with legal or similarly significant effects, large-scale processing of special category or criminal-offence data, large-scale systematic monitoring of publicly accessible areas, large-scale biometric processing for unique identification, large-scale genetic data, and systematic monitoring of employees' activities in the employment context. The AKI treats processing as large scale at 5,000 or more people for special category or offence data, 10,000 or more for data that carries a high risk, and 50,000 or more for other personal data, and does not apply those thresholds to cross-border processing.
Children's data. Estonia's 13-year minimum consent age means organizations must verify user age before relying on child consent for information society services. For users under 13, parental or guardian authorization is required.
Responding to data subjects. Controllers must respond to data subject requests within one calendar month of receipt. The period may be extended by two further months for complex or numerous requests, but the data subject must be informed of the extension within the first month.
Recent Developments (2024-2026)
Allium UPI fine upheld (September 2026). On 2 September 2026 Harju County Court dismissed Allium UPI's appeal and held the EUR 3 million fine justified and proportionate, faulting the company's protection of administrator accounts, its security monitoring and its handling of backups. The AKI describes the judgment as a significant one for assessing whether security measures are adequate where large volumes of sensitive data are processed, while noting that it is a county court decision that has not entered into force and that the company can take to the Supreme Court.
Asper Biogene annulment confirmed (August 2025). The Supreme Court's refusal to hear the AKI's appeal made Tartu County Court's annulment final. The case turned on Estonian misdemeanour procedure and the liability of legal persons rather than on whether the company had complied with the GDPR, which no court instance assessed.
EDPB Guidelines 1/2024 on Legitimate Interests (October 2024). The EDPB's final guidelines on GDPR Article 6(1)(f) are directly relevant to Estonian organizations. They require documentation of a balancing test and impose stricter standards for demonstrating that the claimed legitimate interest is specific and genuinely pursued.
EU AI Act prohibited practices (February 2025). Prohibitions on unacceptable-risk AI practices entered application on 2 February 2025 in Estonia. Organizations using AI for social scoring, subliminal manipulation, or real-time remote biometric identification in public spaces must have ceased those practices. The AKI can act where the practice involves processing personal data. TTJA, the authority Estonia has named for AI market surveillance, describes enforcement of the prohibitions as a task it will take on once its designation is complete.
PDPA collective representative actions (January 2025). A new PDPA section 2-1, in force from 1 January 2025, makes the AKI a qualified entity for the purposes of Consumer Protection Act sections 60-2 and 66-2. It can bring a domestic collective representative action in a county court, or a cross-border action in the court of another EU member state, in the name of the Republic of Estonia to protect the collective interests of data subjects.
PDPA research and ethics changes (October 2025). Amendments in force from 1 October 2025 reworked PDPA section 6 on processing for scientific and historical research and official statistics, including when an ethics committee must vet a study that uses special category data and how executive-branch policy analyses are handled.
Political advertising misdemeanour (March 2026). A new PDPA section 71-1, in force from 16 March 2026, makes a breach of Articles 18 and 19 of Regulation (EU) 2024/900 on the transparency and targeting of political advertising a misdemeanour punishable by up to EUR 20 million, or up to 4 percent of worldwide turnover for a legal person.
eesti.ee mobile app (2025). The launch of the eesti.ee mobile app expanded digital government access. The app's data processing is subject to the same PDPA and GDPR standards as the desktop portal. The RIA published the app's DPIA.
Disclaimer: This article presents general legal information about Estonia's data privacy laws as of 10 September 2026. It is not legal advice and does not create an attorney-client relationship. Data protection laws change; information is provided for general educational purposes. Consult a qualified attorney licensed in Estonia for advice on your specific situation.
Frequently Asked Questions
What is Estonia's main data protection law?
Estonia's data protection framework has two layers. The EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applies directly as binding EU law. The national Personal Data Protection Act (Isikuandmete kaitse seadus), in force from 15 January 2019, supplements the GDPR in areas where the regulation grants member states discretion. Key national rules include setting the children's consent age at 13, special grounds for journalistic and research processing, and a chapter of misdemeanour offences that the AKI prosecutes itself as the extrajudicial body. The Act contains no separate regime for the national identification code (isikukood), and criminal liability for unlawful disclosure of personal data sits in the Penal Code rather than the PDPA. The Andmekaitse Inspektsioon (AKI) enforces both instruments.
What constitutional rights protect personal data in Estonia?
Article 26 of the Estonian Constitution guarantees inviolability of private and family life. Government agencies may not interfere with private life except in circumstances and under procedures provided by law. Article 44 guarantees the right of citizens to access information about themselves held by government agencies and public archives. Article 43 guarantees confidentiality of communications, including electronic messages. Together these provisions give the AKI's enforcement authority a constitutional foundation that Estonian courts have upheld in regulatory-challenge proceedings.
What did the November 2023 amendment to Estonian data protection law change?
Less than is often reported, and it did not touch the fine ceiling. The PDPA's maxima were already GDPR-level when the Act took effect on 15 January 2019: EUR 20 million or 4 percent of worldwide annual turnover for the most serious breaches, EUR 10 million or 2 percent for the rest. The act in force from 1 November 2023 changed the Penal Code instead. It rewrote the rules on the liability of legal persons, set the court-imposed pecuniary punishment on a legal person at EUR 4,000 to 40,000,000, and inserted a provision letting a special act set misdemeanour fines on a different basis and in a different amount than the general cap of EUR 100 to 400,000. Its only PDPA change was a three-year limitation period for data-protection misdemeanours. That Penal Code provision was itself repealed on 6 July 2025, and the derogation now sits in the second sentence of Penal Code section 1(1).
What was the Apotheka / Allium UPI data breach fine?
In September 2025, the AKI imposed Estonia's largest-ever data protection fine of EUR 3 million on Allium UPI OÜ, the operator of the Apotheka pharmacy loyalty program. A 2024 cyberattack exposed personal data of more than 750,000 individuals, including names, identification codes, and purchase histories containing sensitive health-related items. The AKI found that Allium UPI had failed to implement multi-factor authentication, secure database backups, activity logging, and adequate access controls. The company appealed, and on 2 September 2026 Harju County Court dismissed the appeal and held the fine justified and proportionate. That is a county court judgment and can still be taken to the Supreme Court.
Does GDPR apply to e-residency businesses in Estonia?
Yes. Any company registered through Estonia's e-Residency program is an Estonian legal entity fully subject to the GDPR and the national PDPA, regardless of where the e-resident physically resides or operates. The AKI has enforcement authority over these companies. E-resident businesses must maintain processing records, implement security measures, appoint a DPO when required, conduct DPIAs for high-risk processing, respond to data subject rights requests within GDPR timelines, notify the AKI within 72 hours of qualifying breaches, and use valid transfer mechanisms for data sent outside the EEA.
How can Estonian citizens see who has accessed their personal data?
Estonian citizens can use the Data Tracker tool through the eesti.ee government portal. After logging in with a digital ID, citizens can view a complete log of which government agencies have accessed their personal data, when, and for what stated purpose. If a citizen believes an access was unauthorized, they can report it directly to the AKI. This transparency mechanism is built into Estonia's X-Road data exchange infrastructure and operationalizes the Article 44 constitutional right.
What are the breach notification requirements in Estonia?
Estonia follows the GDPR's standard breach notification rules. Data controllers must notify the AKI within 72 hours of becoming aware of a personal data breach likely to pose a risk to the rights and freedoms of individuals. When a breach poses a high risk to affected individuals, the controller must also notify those individuals directly without undue delay. The notification must describe the nature of the breach, categories of data affected, likely consequences, and measures taken. Failing to notify falls under the lower GDPR fine tier: up to EUR 10 million or 2 percent of annual worldwide turnover. Communications undertakings have a separate and stricter duty under Electronic Communications Act section 102-1 to notify the AKI at the first opportunity and to tell affected customers.
How does the EU AI Act interact with Estonian data protection law?
The EU AI Act (Regulation (EU) 2024/1689) applies directly in Estonia from August 2024. Prohibitions on unacceptable-risk AI practices entered application on 2 February 2025. Requirements for high-risk AI systems apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. The AKI supervises data protection compliance in AI-driven processing, including profiling and automated decision-making under GDPR Articles 22 and 35. Estonia has named the Consumer Protection and Technical Regulatory Authority (TTJA) to the European Commission as its AI market surveillance contact point, but the Commission's list of 7 September 2026 records the Estonian designation as still pending final adoption, and TTJA describes the role as one it will take on in future. Organizations deploying high-risk AI systems must satisfy both AI Act conformity requirements and GDPR DPIA obligations.
Updates
Corrected the page's account of Estonian fining law: the Personal Data Protection Act has carried GDPR-level maximum fines since 2019 and they were not raised in November 2023, the Penal Code provision that reform inserted was repealed on 6 July 2025, and the Act contains no special rule for the national identification code. Also confined the automated-decision prohibition to law-enforcement processing, replaced the fabricated X-Road regulation number with Government Regulation No. 105 of 2016, updated the AKI statistics to the 2025 annual report published 31 March 2026, recorded Harju County Court's 2 September 2026 judgment upholding the EUR 3 million Allium UPI fine, corrected the Asper Biogene and Pere Sihtkapital outcomes, and noted that Estonia's designation of TTJA as its AI Act market-surveillance authority is still pending.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, while the 2 August 2026 transparency date is unchanged.
Expanded from approximately 2,650 to approximately 6,200 words. Added: constitutional basis (Articles 26, 43, 44); the Estonian framework for imposing GDPR fines; Apotheka / Allium UPI EUR 3 million fine (September 2025); Asper Biogene reversal (August 2025); Pere Sihtkapital annulment (May 2025); EU AI Act application timeline and Estonia national authorities; EDPB Guidelines 1/2024 on legitimate interests; legal bases for processing; data subject rights; international transfer framework; 2024-2026 recent developments section.
Reviewed and approved by an editor
Initial publication covering GDPR framework, AKI, e-Residency, X-Road, KSI blockchain.
Sources and References
- Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated text RT I, 06.03.2026, 10, in force 16 March 2026(riigiteataja.ee).gov
- Estonian Constitution(riigiteataja.ee).gov
- Andmekaitse Inspektsioon (AKI)(aki.ee).gov
- AKI Annual Report 2024(aki.ee).gov
- Apotheka Fine - ERR News(news.err.ee)
- RIA - Lessons from a Massive Data Leak(ria.ee).gov
- Magnusson - Enforcement Analysis(magnussonlaw.com)
- DataGuidance - Asper Biogene Fine(dataguidance.com)
- e-Residency Official Website(e-resident.gov.ee).gov
- e-Residency GDPR Compliance Guide(e-resident.gov.ee).gov
- X-Road Platform (e-Estonia)(e-estonia.com).gov
- X-Road RIA Documentation(ria.ee).gov
- KSI Blockchain(e-estonia.com).gov
- Electronic Identity eID (RIA)(ria.ee).gov
- Data Tracker - eesti.ee(eesti.ee).gov
- GDPR - EUR-Lex(eur-lex.europa.eu).gov
- EU AI Act - EUR-Lex(eur-lex.europa.eu).gov
- EDPB Guidelines 1/2024 on Legitimate Interests(edpb.europa.eu).gov
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- Penal Code Amendment Act (fines arising from EU law), RT I, 11.03.2023, 1, adopted 22.02.2023, in force 01.11.2023(riigiteataja.ee).gov
- Competition Act Amendment Act, RT I, 05.07.2025, 1, in force 06.07.2025 (repeals Penal Code section 47(4))(riigiteataja.ee).gov
- Penal Code (Karistusseadustik), current consolidated text(riigiteataja.ee).gov
- Personal Data Protection Act Implementation Act, RT I, 13.03.2019, 2, in force 15.03.2019(riigiteataja.ee).gov
- Government Regulation No. 105 of 23.09.2016, Infosusteemide andmevahetuskiht (X-tee), consolidated text RT I, 28.04.2026, 13(riigiteataja.ee).gov
- Electronic Communications Act (Elektroonilise side seadus), current consolidated text(riigiteataja.ee).gov
- AKI publishes its 2025 annual report, 31 March 2026(aki.ee).gov
- AKI Annual Report 2025 - activity indicators(aastaraamat.aki.ee).gov
- AKI Annual Report 2025 - personal data breach notifications(aastaraamat.aki.ee).gov
- AKI Annual Report 2025 - significant court cases(aastaraamat.aki.ee).gov
- AKI: Harju County Court upholds the EUR 3 million Allium UPI fine, 2 September 2026(aki.ee).gov
- AKI: the Asper Biogene court dispute has ended(aki.ee).gov
- AKI: the Pere Sihtkapital court dispute has ended(aki.ee).gov
- AKI guidance, Chapter 5: data protection impact assessment(aki.ee).gov
- European Commission, Market surveillance authorities under the AI Act (updated 7 September 2026)(digital-strategy.ec.europa.eu).gov
- TTJA, Artificial intelligence systems (business guidance)(ttja.ee).gov