Skip to content

Evidence request lists

Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)

Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Estonia PDPA - Estonian Data Protection Inspectorate

EST-IKS-§51-55
Formation of the Estonian Data Protection Inspectorate and Head appointment

Establishes the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) as the independent supervisory authority (§51), sets qualifications (§52) and security check (§53) for the Head, appointment and dismissal procedure (§54) and the Inspectorate's competence in accrediting certification authorities (§55).

Artefacts an auditor will ask for
  • Awareness of the Inspectorate's competence and contact channels
Where this commonly fails
  • Treating the Inspectorate as a generic government office
EST-IKS-§56-61
Exercise of state and administrative supervision by the Inspectorate

Sets the Inspectorate's competence (§56), special state-supervision measures (§57), specifications for state (§58) and administrative supervision (§59), the non-compliance levy rate (§60) and the term for review of complaints (§61).

Artefacts an auditor will ask for
  • Cooperation records with Inspectorate inspections
  • Complaint-handling within the §61 timelines
Where this commonly fails
  • Non-cooperation with Inspectorate inspections
  • Late complaint responses

Estonia PDPA - GDPR Derogations for Specific Purposes

EST-IKS-§4
Processing for journalistic purposes (GDPR Art.85 derogation)

Personal data may be processed for journalistic purposes, in particular for the disclosure of personal data in the media, in the public interest, taking into account the principles of journalistic ethics; the data subject's rights are limited where their exercise would prevent or interfere with the journalistic purpose.

Artefacts an auditor will ask for
  • Documented public-interest assessment for journalistic processing
  • Evidence the processing follows journalistic ethics codes
Where this commonly fails
  • Disclosing personal data without a documented public-interest assessment
EST-IKS-§5
Processing for academic, artistic and literary expression

Personal data may be processed for academic, artistic and literary expression where this does not excessively damage the rights of the data subject; the data subject's rights are limited where their exercise would prevent or interfere with the expression purpose.

Artefacts an auditor will ask for
  • Necessity/proportionality test for expression-based processing
Where this commonly fails
  • Open-ended processing for expression with no proportionality test
EST-IKS-§6
Processing for scientific and historical research and official statistics

Personal data may be processed for scientific and historical research and for official statistics, including processing of sensitive personal data, subject to appropriate safeguards including data minimisation, pseudonymisation, and ethics committee assessment where applicable.

Artefacts an auditor will ask for
  • Ethics-committee assessment where required
  • Pseudonymisation and access controls for research datasets
Where this commonly fails
  • Identifiable research datasets where pseudonymisation is feasible
EST-IKS-§7
Processing for archiving in the public interest

Personal data may be processed for archiving in the public interest, including in the National Archives system, subject to safeguards under the Archives Act and appropriate technical and organisational measures.

Artefacts an auditor will ask for
  • Archival-purpose documentation
  • Safeguards under the Archives Act
Where this commonly fails
  • Archive-flagged processing without genuine archival purpose

Estonia PDPA - General Provisions and GDPR Application

EST-IKS-§1
Scope of regulation of the Act

The Act applies to the processing of personal data, providing the national rules necessary alongside Regulation (EU) 2016/679 (GDPR) and implementing Directive (EU) 2016/680 for processing by competent authorities in the prevention, investigation, detection or prosecution of criminal offences and execution of criminal penalties.

Artefacts an auditor will ask for
  • Determination of whether processing is in scope of GDPR + the Act, or of the Law Enforcement Directive chapter
Where this commonly fails
  • Treating Estonia PDPA as an alternative to GDPR rather than as a complementary national act
EST-IKS-§2
Specifications for application of the Act and Regulation (EU) 2016/679

Specifies how the Act applies in conjunction with GDPR: the Act provides national derogations and supplementary provisions while GDPR remains directly applicable. Where the Act is silent on a matter governed by GDPR, GDPR applies directly.

Artefacts an auditor will ask for
  • Mapping of Estonia PDPA national rules vs directly applicable GDPR provisions
Where this commonly fails
  • Relying solely on the Act and ignoring directly applicable GDPR obligations
EST-IKS-§3
Application of the Administrative Procedure Act

The Administrative Procedure Act applies to proceedings under the Personal Data Protection Act, subject to the specifications established by this Act and the GDPR.

Artefacts an auditor will ask for
  • Awareness of Administrative Procedure Act requirements for interactions with the Estonian Data Protection Inspectorate
Where this commonly fails
  • Procedural defects in interactions with the Inspectorate

Estonia PDPA - Law Enforcement Directive Implementation

EST-IKS-§12-13
Application of the Law Enforcement chapter and terms

Sets the scope of Chapter 4 as the processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences, the execution of criminal penalties, and the safeguarding against and prevention of threats to public security (implementing Directive (EU) 2016/680), and defines the terms used in that chapter.

Artefacts an auditor will ask for
  • Determination of competent-authority status and Chapter 4 scope per processing activity
Where this commonly fails
  • Treating law-enforcement processing as ordinary GDPR processing
EST-IKS-§14-21
Principles of processing by law enforcement authorities

Sets the principles for law-enforcement processing: lawfulness (§15), purpose change (§16), retention (§17), differentiation between categories of data subjects (§18), distinguishing personal data based on assessment (§19), specifications for special-category data (§20) and automatic processing (§21).

Artefacts an auditor will ask for
  • LED-specific principles applied per LE processing activity
  • Categorisation of data subjects (suspects, witnesses, victims) per §18
  • Documented assessment grading per §19
Where this commonly fails
  • Treating LE-processed data with GDPR principles only and ignoring §18-§19 differentiation
EST-IKS-§22-28
Rights of data subjects in law enforcement processing

Sets data subject rights in LE processing: information to be made available (§22), information on notification (§23), access (§24), rectification and erasure (§25), notification obligation (§26), procedure for exercising rights (§27), and the right to address the Estonian Data Protection Inspectorate (§28). Rights may be restricted in the LE context subject to GDPR/LED safeguards.

Artefacts an auditor will ask for
  • LE rights-handling procedure
  • Justifications for any restriction of rights
Where this commonly fails
  • Blanket restriction of rights without case-specific justification
EST-IKS-§29-39
Obligations of controllers and processors in law enforcement processing

Sets controller/processor obligations: identification of the controller (§29), processor designation and obligations (§30), joint controllers (§31), processing in the controller's/processor's name (§32), data protection by design and by default (§33), processing requirements (§34), transmission requirements (§35), logging (§36), records of processing activities (§37), data protection impact assessment (§38), and prior consultation with the Estonian Data Protection Inspectorate (§39).

Artefacts an auditor will ask for
  • LE controller/processor allocation and DPA
  • Logging records per §36
  • Records of processing per §37
  • DPIA evidence per §38
  • Prior-consultation records with the Inspectorate per §39
Where this commonly fails
  • No logging of LE access
  • No DPIA for high-risk LE processing
EST-IKS-§40-42
Data Protection Specialist for law enforcement processing

Provides for the designation (§40), tasks (§41) and position (§42) of a Data Protection Specialist for competent authorities undertaking LE processing, equivalent to the GDPR Data Protection Officer but tailored to the LE context.

Artefacts an auditor will ask for
  • DP Specialist designation and contact for LE processing
  • Tasks documented and supported per §41
Where this commonly fails
  • No designated DP Specialist for LE-processing competent authority
EST-IKS-§43-45
Security measures and breach notification in law enforcement processing

Requires appropriate technical and organisational security measures for LE processing (§43), notification to the Estonian Data Protection Inspectorate of personal data breaches (§44), and notification to the data subject of breaches likely to result in a high risk to rights and freedoms (§45).

Artefacts an auditor will ask for
  • LE-specific security measures
  • Inspectorate breach-notification records
  • Data-subject breach-notification records where required
Where this commonly fails
  • No breach notification path for LE processing
EST-IKS-§46-50
Transmission of personal data to third countries and international organisations

Sets the general conditions (§46), appropriate-safeguards transfers (§47), exceptional-case transfers (§48), transfers to recipients in third countries (§49), and notification/documentation of LE-context international transfers to the Inspectorate (§50).

Artefacts an auditor will ask for
  • LE-transfer documentation and Inspectorate notifications
  • Appropriate-safeguards or exceptional-case grounds per transfer
Where this commonly fails
  • Routine reliance on exceptional-case grounds in LE transfers
  • Undocumented international LE transfers

Estonia PDPA - Liability and Implementing Provisions

EST-IKS-§62-73
Violations, proceedings and penalties

Defines administrative-offence categories: violation of controller/processor obligations (§62), certification procedure violations (§63), code-of-conduct supervision violations (§64), processing-principles violations (§65), data subject rights violations (§66), transfer-procedure violations (§67), specific-principle violations (§68), failure to comply with Inspectorate orders (§69), violation of access to the Inspectorate (§70), illegal processing outside employment duties (§71), other processing-requirement violations (§72), and the proceedings for these offences (§73).

Artefacts an auditor will ask for
  • Awareness of the offence categories applicable to controllers/processors
  • Internal-violation handling that aligns with §71 personal-conduct provisions
Where this commonly fails
  • Personal-conduct processing of personal data outside employment duties
EST-IKS-§74-76
Register, repeal and entry into force

Establishes the public register of processors and persons responsible for data protection (§74), repeals the predecessor Personal Data Protection Act (§75), and sets entry into force (§76, 15 January 2019).

Artefacts an auditor will ask for
  • Inspectorate-register entries where required
  • Awareness of repeal of the predecessor Act
Where this commonly fails
  • Relying on the repealed predecessor Act

Estonia PDPA - National Specifications under GDPR

EST-IKS-§10
Processing of personal data in connection with violation of an obligation

Personal data concerning a violation of an obligation by a data subject (e.g. unpaid debt) may be transmitted to a third party in respect of which the data subject has a contractual or other legal relationship, subject to safeguards including notification to the data subject and accuracy of the data transmitted.

Artefacts an auditor will ask for
  • Notification to the data subject of the transmission
  • Accuracy and review of debt/violation data
Where this commonly fails
  • Transmitting violation data to third parties without notifying the data subject
EST-IKS-§11
Processing of personal data in public places (CCTV)

Capture of personal data with image/audio recording equipment in a publicly accessible place is permitted for the purpose of protection of persons and property, subject to notification of the recording by a clearly visible sign, retention of the recording only for as long as necessary, and proportionality.

Artefacts an auditor will ask for
  • Visible recording-notification signs
  • Retention schedule and justification for CCTV/audio recordings
  • Proportionality assessment
Where this commonly fails
  • Covert recording without notification
  • Indefinite retention of CCTV
EST-IKS-§8
Processing of children's personal data for information society services

Where Article 6(1)(a) GDPR applies in relation to the offer of information society services directly to a child, the processing of personal data is lawful where the child is at least 13 years of age (Estonia's exercise of the GDPR Article 8 national-determination option for ages 13-16).

Artefacts an auditor will ask for
  • Age verification or assertion at consent
  • Recordkeeping of the age relied upon
Where this commonly fails
  • Applying the GDPR-default age 16 without recognising Estonia's age 13
EST-IKS-§9
Processing of personal data after death of the data subject

Personal data of a deceased natural person may be processed only with the consent of a successor, descendant, parent, sibling, spouse, child or other person specified by law, except where 10 years have passed since the death or where processing is necessary for specified purposes (genealogy, scientific research, history, official statistics or other lawful purposes).

Artefacts an auditor will ask for
  • Consent records from authorised relatives where required
  • Documentation of the 10-year threshold or specified-purpose ground
Where this commonly fails
  • Processing data of a recently deceased person without consent or a lawful exception

Scope and Application

EPDPA-1
Scope of Regulation (§1)

Defines the scope of the Act in elaborating and supplementing the EU GDPR

Artefacts an auditor will ask for
  • Scope statement
  • Applicability analysis
  • Regulator correspondence
  • Processing inventory
Where this commonly fails
  • Scope ambiguous
  • Out-of-scope processing
  • No regulator engagement
  • No inventory
EPDPA-2
Specifications for Application (§2)

Specifications for application of the Act and Regulation (EU) 2016/679

Artefacts an auditor will ask for
  • Application matrix
  • Specification register
  • Boundary documentation
  • Exemption analysis
Where this commonly fails
  • Boundaries unclear
  • Exemptions unjustified
  • No matrix
  • No specification register
EPDPA-3
Application of Administrative Procedure Act (§3)

Applicability of the Administrative Procedure Act to proceedings under this Act

Artefacts an auditor will ask for
  • Procedural manual
  • Due process records
  • Hearing transcripts
  • Notice templates
Where this commonly fails
  • No procedural manual
  • Due process gaps
  • Notices stale
  • No records
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) framework page.