Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Estonia PDPA - Estonian Data Protection Inspectorate
Establishes the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) as the independent supervisory authority (§51), sets qualifications (§52) and security check (§53) for the Head, appointment and dismissal procedure (§54) and the Inspectorate's competence in accrediting certification authorities (§55).
- Awareness of the Inspectorate's competence and contact channels
- Treating the Inspectorate as a generic government office
Sets the Inspectorate's competence (§56), special state-supervision measures (§57), specifications for state (§58) and administrative supervision (§59), the non-compliance levy rate (§60) and the term for review of complaints (§61).
- Cooperation records with Inspectorate inspections
- Complaint-handling within the §61 timelines
- Non-cooperation with Inspectorate inspections
- Late complaint responses
Estonia PDPA - GDPR Derogations for Specific Purposes
Personal data may be processed for journalistic purposes, in particular for the disclosure of personal data in the media, in the public interest, taking into account the principles of journalistic ethics; the data subject's rights are limited where their exercise would prevent or interfere with the journalistic purpose.
- Documented public-interest assessment for journalistic processing
- Evidence the processing follows journalistic ethics codes
- Disclosing personal data without a documented public-interest assessment
Personal data may be processed for academic, artistic and literary expression where this does not excessively damage the rights of the data subject; the data subject's rights are limited where their exercise would prevent or interfere with the expression purpose.
- Necessity/proportionality test for expression-based processing
- Open-ended processing for expression with no proportionality test
Personal data may be processed for scientific and historical research and for official statistics, including processing of sensitive personal data, subject to appropriate safeguards including data minimisation, pseudonymisation, and ethics committee assessment where applicable.
- Ethics-committee assessment where required
- Pseudonymisation and access controls for research datasets
- Identifiable research datasets where pseudonymisation is feasible
Personal data may be processed for archiving in the public interest, including in the National Archives system, subject to safeguards under the Archives Act and appropriate technical and organisational measures.
- Archival-purpose documentation
- Safeguards under the Archives Act
- Archive-flagged processing without genuine archival purpose
Estonia PDPA - General Provisions and GDPR Application
The Act applies to the processing of personal data, providing the national rules necessary alongside Regulation (EU) 2016/679 (GDPR) and implementing Directive (EU) 2016/680 for processing by competent authorities in the prevention, investigation, detection or prosecution of criminal offences and execution of criminal penalties.
- Determination of whether processing is in scope of GDPR + the Act, or of the Law Enforcement Directive chapter
- Treating Estonia PDPA as an alternative to GDPR rather than as a complementary national act
Specifies how the Act applies in conjunction with GDPR: the Act provides national derogations and supplementary provisions while GDPR remains directly applicable. Where the Act is silent on a matter governed by GDPR, GDPR applies directly.
- Mapping of Estonia PDPA national rules vs directly applicable GDPR provisions
- Relying solely on the Act and ignoring directly applicable GDPR obligations
The Administrative Procedure Act applies to proceedings under the Personal Data Protection Act, subject to the specifications established by this Act and the GDPR.
- Awareness of Administrative Procedure Act requirements for interactions with the Estonian Data Protection Inspectorate
- Procedural defects in interactions with the Inspectorate
Estonia PDPA - Law Enforcement Directive Implementation
Sets the scope of Chapter 4 as the processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences, the execution of criminal penalties, and the safeguarding against and prevention of threats to public security (implementing Directive (EU) 2016/680), and defines the terms used in that chapter.
- Determination of competent-authority status and Chapter 4 scope per processing activity
- Treating law-enforcement processing as ordinary GDPR processing
Sets the principles for law-enforcement processing: lawfulness (§15), purpose change (§16), retention (§17), differentiation between categories of data subjects (§18), distinguishing personal data based on assessment (§19), specifications for special-category data (§20) and automatic processing (§21).
- LED-specific principles applied per LE processing activity
- Categorisation of data subjects (suspects, witnesses, victims) per §18
- Documented assessment grading per §19
- Treating LE-processed data with GDPR principles only and ignoring §18-§19 differentiation
Sets data subject rights in LE processing: information to be made available (§22), information on notification (§23), access (§24), rectification and erasure (§25), notification obligation (§26), procedure for exercising rights (§27), and the right to address the Estonian Data Protection Inspectorate (§28). Rights may be restricted in the LE context subject to GDPR/LED safeguards.
- LE rights-handling procedure
- Justifications for any restriction of rights
- Blanket restriction of rights without case-specific justification
Sets controller/processor obligations: identification of the controller (§29), processor designation and obligations (§30), joint controllers (§31), processing in the controller's/processor's name (§32), data protection by design and by default (§33), processing requirements (§34), transmission requirements (§35), logging (§36), records of processing activities (§37), data protection impact assessment (§38), and prior consultation with the Estonian Data Protection Inspectorate (§39).
- LE controller/processor allocation and DPA
- Logging records per §36
- Records of processing per §37
- DPIA evidence per §38
- Prior-consultation records with the Inspectorate per §39
- No logging of LE access
- No DPIA for high-risk LE processing
Provides for the designation (§40), tasks (§41) and position (§42) of a Data Protection Specialist for competent authorities undertaking LE processing, equivalent to the GDPR Data Protection Officer but tailored to the LE context.
- DP Specialist designation and contact for LE processing
- Tasks documented and supported per §41
- No designated DP Specialist for LE-processing competent authority
Requires appropriate technical and organisational security measures for LE processing (§43), notification to the Estonian Data Protection Inspectorate of personal data breaches (§44), and notification to the data subject of breaches likely to result in a high risk to rights and freedoms (§45).
- LE-specific security measures
- Inspectorate breach-notification records
- Data-subject breach-notification records where required
- No breach notification path for LE processing
Sets the general conditions (§46), appropriate-safeguards transfers (§47), exceptional-case transfers (§48), transfers to recipients in third countries (§49), and notification/documentation of LE-context international transfers to the Inspectorate (§50).
- LE-transfer documentation and Inspectorate notifications
- Appropriate-safeguards or exceptional-case grounds per transfer
- Routine reliance on exceptional-case grounds in LE transfers
- Undocumented international LE transfers
Estonia PDPA - Liability and Implementing Provisions
Defines administrative-offence categories: violation of controller/processor obligations (§62), certification procedure violations (§63), code-of-conduct supervision violations (§64), processing-principles violations (§65), data subject rights violations (§66), transfer-procedure violations (§67), specific-principle violations (§68), failure to comply with Inspectorate orders (§69), violation of access to the Inspectorate (§70), illegal processing outside employment duties (§71), other processing-requirement violations (§72), and the proceedings for these offences (§73).
- Awareness of the offence categories applicable to controllers/processors
- Internal-violation handling that aligns with §71 personal-conduct provisions
- Personal-conduct processing of personal data outside employment duties
Establishes the public register of processors and persons responsible for data protection (§74), repeals the predecessor Personal Data Protection Act (§75), and sets entry into force (§76, 15 January 2019).
- Inspectorate-register entries where required
- Awareness of repeal of the predecessor Act
- Relying on the repealed predecessor Act
Estonia PDPA - National Specifications under GDPR
Personal data concerning a violation of an obligation by a data subject (e.g. unpaid debt) may be transmitted to a third party in respect of which the data subject has a contractual or other legal relationship, subject to safeguards including notification to the data subject and accuracy of the data transmitted.
- Notification to the data subject of the transmission
- Accuracy and review of debt/violation data
- Transmitting violation data to third parties without notifying the data subject
Capture of personal data with image/audio recording equipment in a publicly accessible place is permitted for the purpose of protection of persons and property, subject to notification of the recording by a clearly visible sign, retention of the recording only for as long as necessary, and proportionality.
- Visible recording-notification signs
- Retention schedule and justification for CCTV/audio recordings
- Proportionality assessment
- Covert recording without notification
- Indefinite retention of CCTV
Where Article 6(1)(a) GDPR applies in relation to the offer of information society services directly to a child, the processing of personal data is lawful where the child is at least 13 years of age (Estonia's exercise of the GDPR Article 8 national-determination option for ages 13-16).
- Age verification or assertion at consent
- Recordkeeping of the age relied upon
- Applying the GDPR-default age 16 without recognising Estonia's age 13
Personal data of a deceased natural person may be processed only with the consent of a successor, descendant, parent, sibling, spouse, child or other person specified by law, except where 10 years have passed since the death or where processing is necessary for specified purposes (genealogy, scientific research, history, official statistics or other lawful purposes).
- Consent records from authorised relatives where required
- Documentation of the 10-year threshold or specified-purpose ground
- Processing data of a recently deceased person without consent or a lawful exception
Scope and Application
Defines the scope of the Act in elaborating and supplementing the EU GDPR
- Scope statement
- Applicability analysis
- Regulator correspondence
- Processing inventory
- Scope ambiguous
- Out-of-scope processing
- No regulator engagement
- No inventory
Specifications for application of the Act and Regulation (EU) 2016/679
- Application matrix
- Specification register
- Boundary documentation
- Exemption analysis
- Boundaries unclear
- Exemptions unjustified
- No matrix
- No specification register
Applicability of the Administrative Procedure Act to proceedings under this Act
- Procedural manual
- Due process records
- Hearing transcripts
- Notice templates
- No procedural manual
- Due process gaps
- Notices stale
- No records
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) framework page.