🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
EE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing21 sources retrieved model claude-sonnet-5 · 2026-08-03

Estonia

EE schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, AIC

Last updated · 10 categories · 37 claims · 34 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
16Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 15 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Estonia's data protection authority, Andmekaitse Inspektsioon (AKI), imposed a EUR 3,000,000 fine on Allium UPI OU on 5 September 2025 over the Apotheka loyalty-programme data breach, which affected more than 750,000 individuals. This is the largest GDPR fine imposed in Estonia to date, and it was enabled by a 2023 legislative amendment to the Isikuandmete kaitse seadus (IKS) that significantly simplified the process for imposing GDPR-type fines directly on legal persons for infringements committed on or continuing from 1 November 2023. The fine is under appeal, with court hearings beginning 6 April 2026, and its outcome had not been resolved as of this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned EU Member State regime with an operational, EDPB-integrated supervisory authority and a settled national implementing act in force since 2019.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus, PDPA, in force 15 January 2019)
Traffic-light rationale — GreenFully GDPR-aligned EU Member State regime with an operational, EDPB-integrated supervisory authority and a settled national implementing act in force since 2019.

Sub-modules (5)

Regulator And AuthorityGreen

AKI (Tatari 39, Tallinn) is the competent EU GDPR supervisory authority for Estonia, currently led by Pille Lehis.

Claims (1):

  • The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), based at Tatari 39, 10134 Tallinn, is Estonia's EDPB-member supervisory authority, currently headed by Ms Pille Lehis.

Act And InstrumentsGreen

The PDPA entered into force 15 January 2019 and implements/supplements the GDPR at national level.

Claims (1):

  • Data protection in Estonia is primarily governed by the GDPR, implemented into Estonian law via the Personal Data Protection Act (PDPA), which entered into force on 15 January 2019.

Material ScopeGreen

Material scope follows GDPR Art 2 (processing of personal data wholly or partly by automated means, or manual processing forming part of a filing system), applied directly as EU law in Estonia.

Territorial ScopeGreen

GDPR's extraterritorial scope (Art 3) applies directly: non-EU controllers offering goods/services to, or monitoring the behaviour of, individuals in Estonia fall within scope.

Claims (1):

  • Under GDPR rules applicable in Estonia, non-EU-established businesses must apply the same rules when they offer goods or services, or monitor the behaviour, of individuals in the EU.

Regulator Registration And FilingGreen

No general controller registration/filing regime exists under GDPR or the PDPA; obligations instead run through records of processing (Art 30) and prior consultation for high-risk DPIA outcomes (Art 36). AKI maintains a published Art 35(4) list of processing operations requiring DPIA.

Claims (1):

  • AKI adopted (per EDPB Opinion 6/2018) a national list of processing operations subject to the mandatory DPIA requirement under GDPR Article 35(4), in place of a general controller-registration/filing regime.

Key findings (1)

  • AKI/PDPA baseline confirmed, EDPB-integrated, in force since 2019. — source on file
Category narrative70 words

Estonia's data-protection regime is anchored in the GDPR, which applies directly as EU law, and the national Personal Data Protection Act (Isikuandmete kaitse seadus, PDPA), which entered into force on 15 January 2019 to implement/derogate GDPR provisions. The supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), headed by Director General Pille Lehis. AKI participates in EDPB one-stop-shop and coordinated enforcement mechanisms alongside the other 26 EU DPAs.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedEDPB — The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), based at Tatari 39, 10134 Tallinn, is Estonia's EDPB-member supervisory authority, currently headed by Ms Pille Lehis.observed
  2. ConfirmedOneTrust DataGuidance — Data protection in Estonia is primarily governed by the GDPR, implemented into Estonian law via the Personal Data Protection Act (PDPA), which entered into force on 15 January 2019.observed
  3. ConfirmedEUR-Lex — Under GDPR rules applicable in Estonia, non-EU-established businesses must apply the same rules when they offer goods or services, or monitor the behaviour, of individuals in the EU.observed
  4. ConfirmedEDPB — AKI adopted (per EDPB Opinion 6/2018) a national list of processing operations subject to the mandatory DPIA requirement under GDPR Article 35(4), in place of a general controller-registration/filing regime.observed

#

Core lawful-basis and special-category rules are GDPR-aligned and actively enforced; only prospective, non-binding EU-level reform (Digital Omnibus) is pending.

Primary frameworkGDPR Articles 6, 7, 9; Personal Data Protection Act (PDPA)
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and actively enforced; only prospective, non-binding EU-level reform (Digital Omnibus) is pending.

Sub-modules (4)

Lawful BasesAmber

AKI has rejected controllers' reliance on Art 6(1)(b) contractual-necessity for ancillary data uses (e.g., rider-rating data) not strictly necessary to perform the core contract.

Claims (1):

  • In a 2022 own-initiative proceeding, the Estonian DPA found that a ride-hailing controller lacked a valid legal basis for processing rider ratings and disagreed that Article 6(1)(b) GDPR (contractual necessity) applied to that processing.

Special CategoriesAmber

No Estonia-specific derogation to GDPR Art 9 special-category rules was identified in this pass; the EU Digital Omnibus proposes a new incidental/residual-processing derogation for AI development, still pending in trilogue.

Claims (1):

  • The EDPB and EDPS have welcomed the Digital Omnibus proposal's aim to introduce a specific, conditional derogation to the prohibition on processing special-category data, covering incidental/residual processing in AI system development and operation, while recommending narrower scope and lifecycle safeguards.

Pseudonymisation And AnonymisationAmber

GDPR's pseudonymisation concept (Art 4(5), Recital 26) applies directly; the EU Digital Omnibus proposal to narrow the 'personal data' definition regarding pseudonymised data (Art 4(1)) remains contested and was stripped from a February 2026 Council compromise text.

Claims (1):

  • The EDPB and EDPS strongly urged co-legislators not to adopt the Commission's proposed narrowing of the GDPR Art 4(1) personal-data definition (relative identifiability for pseudonymised data), and a leaked February 2026 Council compromise text removed that proposed change entirely.

Key findings (1)

  • Strict AKI enforcement of consent/lawful-basis validity; Digital Omnibus special-category derogation pending. — source on file
Category narrative78 words

Lawful bases and consent standards follow GDPR Art 6/7 directly. AKI enforcement practice shows a strict reading of both consent validity and the contractual-necessity basis, as illustrated in a 2022 own-initiative case against a ride-hailing platform's use of rider-rating data. National special-category and pseudonymisation rules track GDPR Art 9 and Recital 26 without material Estonian derogation identified in this research pass; the EU Digital Omnibus proposal (not yet law) would add an AI-specific derogation for incidental special-category processing.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedAKI / EDPB — In a 2022 own-initiative proceeding, the Estonian DPA found that a ride-hailing controller lacked a valid legal basis for processing rider ratings and disagreed that Article 6(1)(b) GDPR (contractual necessity) applied to that processing.observed
  2. ConfirmedEDPB / AKI — AKI held that another person's self-declared justification for viewing a prescription is not equivalent to the voluntary consent of the prescription holder, because the controller cannot verify the purpose or voluntariness of that consent.observed
  3. ProbableEDPB — The EDPB and EDPS have welcomed the Digital Omnibus proposal's aim to introduce a specific, conditional derogation to the prohibition on processing special-category data, covering incidental/residual processing in AI system development and operation, while recommending narrower scope and lifecycle safeguards.observed
  4. ProbableIAPP — The EDPB and EDPS strongly urged co-legislators not to adopt the Commission's proposed narrowing of the GDPR Art 4(1) personal-data definition (relative identifiability for pseudonymised data), and a leaked February 2026 Council compromise text removed that proposed change entirely.observed

#

GDPR rights framework in force with clear escalation path to AKI/courts; no Estonia-specific restriction identified.

Primary frameworkGDPR Articles 12-22; PDPA
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — GreenGDPR rights framework in force with clear escalation path to AKI/courts; no Estonia-specific restriction identified.

Sub-modules (5)

Access RightAmber

Access requests submitted in English to Estonian controllers may be answered in Estonian, per EDPB cross-border cooperation guidance covering Estonia.

Claims (1):

  • Where an access/rectification/erasure request is submitted in English to an Estonian controller, the controller responds to the applicant in Estonian.

Rectification And ErasureGreen

GDPR Art 16/17 rights apply directly; Estonia's national population/business registers follow the GDPR rectification/erasure regime with sector-specific notification duties.

Restriction And ObjectionGreen

GDPR Art 18/21 rights apply directly with no identified Estonian derogation.

Data PortabilityGreen

GDPR Art 20 portability right applies directly with no identified Estonian derogation.

Deadlines And Response WindowsGreen

If a controller fails to respond within 30 days, or the requester disputes the reply, the requester may lodge a free-of-charge complaint with AKI or an administrative court.

Claims (1):

  • If the requester is not satisfied with a controller's reply, or receives no reply within 30 days of sending the request, the requester has the right to lodge a free complaint with AKI or an administrative court.

Key findings (1)

  • Standard GDPR Chapter III rights with 30-day escalation path to AKI/courts. — source on file
Category narrative54 words

Estonia applies the GDPR's Chapter III rights directly (access, rectification, erasure, restriction, objection, portability), with the standard one-month (extendable) response window under Art 12(3). AKI's own EDPB-published guidance confirms a 30-day escalation trigger: if a controller fails to respond, or the requester is dissatisfied, the requester may complain to AKI or an administrative court.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableEDPB — Where an access/rectification/erasure request is submitted in English to an Estonian controller, the controller responds to the applicant in Estonian.observed
  2. ConfirmedEDPB — If the requester is not satisfied with a controller's reply, or receives no reply within 30 days of sending the request, the requester has the right to lodge a free complaint with AKI or an administrative court.observed

#

Core GDPR controller/processor obligations are enforced and operative; only prospective Digital Omnibus amendments to ROPA and breach thresholds remain unresolved.

Primary frameworkGDPR Articles 24-25, 28, 30, 32-34, 35, 37-39; PDPA
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — GreenCore GDPR controller/processor obligations are enforced and operative; only prospective Digital Omnibus amendments to ROPA and breach thresholds remain unresolved.

Sub-modules (7)

Accountability And DpiaGreen

AKI's Art 35(4) DPIA list (per EDPB Opinion 6/2018) operationalises the accountability/DPIA regime for Estonian controllers.

Claims (1):

  • AKI's national list of processing operations requiring a DPIA under GDPR Art 35(4) was adopted following EDPB Opinion 6/2018.

Dpo RequirementsAmber

AKI participated in the EDPB's 2023 coordinated enforcement framework action assessing whether DPOs in ~19 public/private Estonian organisations meet Art 37-39 conditions and have adequate resources.

Claims (1):

  • AKI selected 19 public- and private-sector organisations (municipalities, ministries, banks, hospitals) to assess, via questionnaires and potential formal investigation, whether their DPOs meet GDPR Articles 37-39 conditions and have adequate resources, as part of the EDPB's 2023 Coordinated Enforcement Framework action.

Ropa RequirementsAmber

The EU Digital Omnibus proposes raising the Art 30(5) ROPA-keeping exemption from under-250 to under-750 employees; the EDPB/EDPS support the simplification intent but seek clarification on the threshold and its exclusion of public bodies.

Claims (1):

  • The EU Digital Omnibus proposal would modify GDPR Art 30(5) to extend the ROPA-keeping derogation from organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk; this is a pending proposal, not yet in force.

Joint Controller ArrangementsGreen

GDPR Art 26 joint-controller rules apply directly; no Estonia-specific guidance identified in this pass.

Security MeasuresAmber

AKI's e-pharmacy enforcement action required immediate technical remediation (access-control failures allowing third-party prescription viewing via personal identification codes).

Claims (1):

  • AKI issued a precept with a one-day compliance deadline and a 100,000 EUR penalty payment to three e-pharmacy chains for a security/access-control failure allowing viewing of another person's current prescriptions via personal identification codes without consent.

Breach NotificationAmber

GDPR Art 33/34 breach-notification duties apply directly, with AKI operating an e-service breach-notification channel; the Digital Omnibus would raise the risk threshold triggering notification and extend the notification deadline, not yet adopted.

Claims (1):

  • The EDPB and EDPS support the Digital Omnibus proposal's increase of the risk threshold triggering mandatory breach notification to the competent DPA and the extension of the notification deadline, assessing this would meaningfully reduce administrative burden without affecting individuals' protection.

Retention And DisposalAmber

AKI enforcement against a credit-information portal cited data-minimisation and retention-limitation shortcomings and required accuracy safeguards for republished non-payment data.

Claims (1):

  • AKI's self-initiated monitoring of a credit-information portal (taust.ee) identified privacy-policy shortcomings and directed the controller to address data-minimisation and retention principles and the accuracy of processed non-payment data.

Key findings (1)

  • Accountability/DPIA/DPO/security duties actively enforced; Digital Omnibus ROPA/breach-threshold reform pending; fold-in of Nov-2023 fining-power context. — source on file
Category narrative71 words

GDPR Chapter IV duties (accountability, DPIA, DPO, ROPA, joint-controller arrangements, security, breach notification, retention) apply directly in Estonia. AKI has run coordinated EDPB campaigns on DPO effectiveness and cloud processing, and has enforced security/retention/minimisation duties against credit-information and social-media-adjacent controllers. The pending EU Digital Omnibus would raise the ROPA (Art 30(5)) SME/SMC exemption threshold to under-750 employees and raise the breach-notification risk threshold/extend the deadline — neither is yet in force.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Estonia's controller and processor accountability framework tightened materially this cycle through a legislative amendment to the Isikuandmete kaitse seadus (IKS) that significantly simplified the process for imposing GDPR-type fines directly on legal persons. The amendment applies to infringements committed on or continuing from 1 November 2023, and its practical significance became concrete in this cycle's largest-ever Estonian GDPR fine (covered in the Enforcement & Redress sub-brief below), which the simplification directly enabled. Prior to this amendment, imposing GDPR-scale sanctions on a legal person in Estonia carried procedural friction that the 2023 change removed.

This is a duties-side development in the sense that it does not create a new substantive obligation for controllers or processors, but it materially changes the practical consequence of failing to meet existing accountability and DPIA-adjacent obligations: a legal person that falls short of its accountability duties now faces a more straightforward path to a large fine than it did before 1 November 2023. Controllers and processors operating in Estonia should treat this as a signal that the cost of non-compliance with existing duties has risen, even though the duties themselves are unchanged in substance.

No other controller/processor-duties development was surfaced this cycle beyond this fining-mechanism simplification; the accountability and DPIA substance of Estonian law otherwise tracks the GDPR baseline.

Outlook

The practical weight of this 2023 amendment will continue to be tested through the ongoing Allium UPI appeal (hearings beginning 6 April 2026); a court ruling upholding the fine would confirm the amendment has produced a durable and legally robust escalation in accountability enforcement.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedEDPB — AKI's national list of processing operations requiring a DPIA under GDPR Art 35(4) was adopted following EDPB Opinion 6/2018.observed
  2. ConfirmedEDPB / AKI — AKI selected 19 public- and private-sector organisations (municipalities, ministries, banks, hospitals) to assess, via questionnaires and potential formal investigation, whether their DPOs meet GDPR Articles 37-39 conditions and have adequate resources, as part of the EDPB's 2023 Coordinated Enforcement Framework action.observed
  3. ProbableEDPB — The EU Digital Omnibus proposal would modify GDPR Art 30(5) to extend the ROPA-keeping derogation from organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk; this is a pending proposal, not yet in force.observed
  4. ConfirmedEDPB / AKI — AKI issued a precept with a one-day compliance deadline and a 100,000 EUR penalty payment to three e-pharmacy chains for a security/access-control failure allowing viewing of another person's current prescriptions via personal identification codes without consent.observed
  5. ProbableEDPB — The EDPB and EDPS support the Digital Omnibus proposal's increase of the risk threshold triggering mandatory breach notification to the competent DPA and the extension of the notification deadline, assessing this would meaningfully reduce administrative burden without affecting individuals' protection.observed
  6. ConfirmedEDPB / AKI — AKI's self-initiated monitoring of a credit-information portal (taust.ee) identified privacy-policy shortcomings and directed the controller to address data-minimisation and retention principles and the accuracy of processed non-payment data.observed

#

Transfer mechanisms are the standard EU GDPR toolkit with no identified Estonian derogation; localisation-specific findings are absent and flagged rather than assumed.

Primary frameworkGDPR Articles 44-49; EU Commission adequacy decisions
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — GreenTransfer mechanisms are the standard EU GDPR toolkit with no identified Estonian derogation; localisation-specific findings are absent and flagged rather than assumed.

Sub-modules (6)

Transfer MechanismsGreen

GDPR provides adequacy decisions, SCCs, BCRs, codes of conduct/certification, and derogations as international-transfer tools, applied directly in Estonia as EU law.

Claims (1):

  • The GDPR offers a range of tools for transferring data outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct, and certification.

Adequacy ReceivedAmber

Adequacy 'received' by Estonia is not a distinct national concept; Estonia benefits from whatever adequacy the EU Commission grants to third countries as an EU Member State.

Adequacy GrantedGreen

The EU Commission's renewed adequacy decision for the UK (covering both GDPR and the Law Enforcement Directive) applies directly to Estonia as an EEA state, permitting free transfer of personal data from Estonia to the UK.

Claims (1):

  • The European Commission's renewed EU-GDPR adequacy decision for the UK applies to transfers from all EEA countries, including Estonia, and lasts until 27 December 2031.

Sccs And BcrsGreen

SCCs and BCRs are available under GDPR Art 46; the EDPB register shows ongoing Art 64 BCR opinions across the EU affecting Estonian-relevant multinational controllers.

Transfer Impact AssessmentAmber

Post-Schrems II, EDPB Recommendations on supplementary measures for international transfers apply directly to Estonian exporters using SCCs/BCRs to non-adequate third countries.

Claims (1):

  • Following the CJEU's Schrems II ruling invalidating the EU-U.S. Privacy Shield, the EDPB issued FAQs and Recommendations setting out a six-step process for supplementary measures, applicable to Estonian data exporters using SCCs to non-adequate third countries.

Data LocalisationRed

No Estonia-specific data-localisation mandate (partial or absolute) for personal data was identified in this research pass; absent_field_provenance recorded below.

Key findings (1)

  • Standard EU transfer toolkit; UK adequacy confirmed to 2031; no localisation mandate found. — source on file
Category narrative71 words

As an EU/EEA Member State, Estonia relies on the GDPR's Chapter V transfer toolkit (adequacy decisions, SCCs, BCRs, derogations) applied uniformly; adequacy decisions are adopted at EU Commission level and bind Estonia directly rather than through separate national determinations. Estonia benefits from the UK's EU-GDPR adequacy decision (renewed, valid until 27 December 2031), permitting free transfers from Estonia to the UK. No Estonia-specific data-localisation mandate was identified in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedEUR-Lex — The GDPR offers a range of tools for transferring data outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct, and certification.observed
  2. ConfirmedICO — The European Commission's renewed EU-GDPR adequacy decision for the UK applies to transfers from all EEA countries, including Estonia, and lasts until 27 December 2031.observed
  3. ConfirmedEDPB — Following the CJEU's Schrems II ruling invalidating the EU-U.S. Privacy Shield, the EDPB issued FAQs and Recommendations setting out a six-step process for supplementary measures, applicable to Estonian data exporters using SCCs to non-adequate third countries.observed

#

Sectoral overlays exist mainly through case law/enforcement rather than distinct statutes; a live CJEU reference on AML/GDPR interplay introduces near-term legal uncertainty for the financial sector overlay.

Primary frameworkGDPR; ePrivacy Directive 2002/58/EC; Estonian AML framework (Rahapesu Andmebüroo)
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — AmberSectoral overlays exist mainly through case law/enforcement rather than distinct statutes; a live CJEU reference on AML/GDPR interplay introduces near-term legal uncertainty for the financial sector overlay.

Sub-modules (7)

Financial Sector OverlayAmber

A pending CJEU preliminary reference (Case C-222/25), lodged 21 March 2025 by Estonia's Riigikohus (Supreme Court), concerns an individual's dispute with the Estonian Financial Intelligence Unit (Rahapesu Andmebüroo), with AKI as an involved party, raising GDPR/AML data-processing interface questions.

Claims (1):

  • Estonia's Supreme Court (Riigikohus) lodged a preliminary reference (Case C-222/25) with the CJEU on 21 March 2025 concerning a dispute between an individual and the Estonian Financial Intelligence Unit (Rahapesu Andmebüroo), with the Estonian DPA (Andmekaitse Inspektsioon) named as an involved party.

Health Sector OverlayAmber

Estonia's e-pharmacy/e-health infrastructure has been the subject of direct AKI enforcement for unlawful third-party access to prescription data via personal identification codes.

Claims (1):

  • AKI initiated an own-initiative procedure under clause 56(3)(8) of the PDPA against three e-pharmacy chains for unlawfully displaying another person's valid prescriptions based on personal identification codes.

Telecoms And EprivacyAmber

ePrivacy Directive Art 5(3) cookie/tracker consent rules apply directly in Estonia; the pending Digital Omnibus proposes targeted amendments to the ePrivacy Directive alongside the GDPR.

Claims (1):

  • The EU Digital Omnibus proposal, formally consulted with the EDPB/EDPS from 25 November 2025, includes targeted amendments concerning the GDPR, the EUDPR, and the ePrivacy Directive.

Employment DataRed

No Estonia-specific employment-data statute distinct from GDPR was identified in this pass.

Credit And ScoringAmber

AKI has repeatedly enforced against non-payment/credit-information republication by private controllers (Facebook debt-shaming groups; Krediidiregister OÜ; taust.ee portal), citing legitimate-interest failures and PDPA §10 restrictions.

Claims (2):

  • AKI found that a private individual's Facebook groups disclosing other people's debt data to 4,600-14,800 unidentified members lacked a legitimate-interest or journalistic-purpose basis and issued a precept with a 5,000 EUR penalty payment.
  • AKI issued a precept with a 10,000 EUR penalty payment per unfulfilled point against Krediidiregister OÜ over legal-basis and privacy-policy shortcomings in disclosing non-payment data of legal representatives.

EducationRed

No Estonia-specific education-sector DP overlay was identified in this research pass.

InsuranceRed

No Estonia-specific insurance-sector DP overlay was identified in this research pass.

Key findings (1)

  • Financial-sector CJEU reference pending; health/credit sector overlays enforced via case law. — source on file
Category narrative79 words

Estonia has no distinct sectoral DP statutes displacing GDPR, but sectoral overlays are visible in practice: the Estonian Financial Intelligence Unit's (Rahapesu Andmebüroo) AML data processing is the subject of a pending CJEU preliminary reference from the Estonian Supreme Court on the GDPR/Law Enforcement Directive interface; Estonia's e-health/e-pharmacy ecosystem has triggered security enforcement; and credit-scoring/non-payment data portals have been subject to repeated AKI enforcement. Telecoms/ePrivacy rules (Directive 2002/58/EC) apply directly and are subject to the pending Digital Omnibus amendments.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedEUR-Lex / Official Journal — Estonia's Supreme Court (Riigikohus) lodged a preliminary reference (Case C-222/25) with the CJEU on 21 March 2025 concerning a dispute between an individual and the Estonian Financial Intelligence Unit (Rahapesu Andmebüroo), with the Estonian DPA (Andmekaitse Inspektsioon) named as an involved party.observed
  2. ConfirmedEDPB / AKI — AKI initiated an own-initiative procedure under clause 56(3)(8) of the PDPA against three e-pharmacy chains for unlawfully displaying another person's valid prescriptions based on personal identification codes.observed
  3. ProbableEDPB — The EU Digital Omnibus proposal, formally consulted with the EDPB/EDPS from 25 November 2025, includes targeted amendments concerning the GDPR, the EUDPR, and the ePrivacy Directive.observed
  4. ConfirmedEDPB / AKI — AKI found that a private individual's Facebook groups disclosing other people's debt data to 4,600-14,800 unidentified members lacked a legitimate-interest or journalistic-purpose basis and issued a precept with a 5,000 EUR penalty payment.observed
  5. ConfirmedEDPB / AKI — AKI issued a precept with a 10,000 EUR penalty payment per unfulfilled point against Krediidiregister OÜ over legal-basis and privacy-policy shortcomings in disclosing non-payment data of legal representatives.observed

#

Cookie/ePrivacy rules are GDPR/ePrivacy-aligned and in force; several US-style adtech constructs (dark patterns codified separately, GPC, clean rooms) have no confirmed Estonian equivalent, driving amber/red sub-module ratings and explicit gaps.

Primary frameworkePrivacy Directive 2002/58/EC; GDPR
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — AmberCookie/ePrivacy rules are GDPR/ePrivacy-aligned and in force; several US-style adtech constructs (dark patterns codified separately, GPC, clean rooms) have no confirmed Estonian equivalent, driving amber/red sub-module ratings and explicit gaps.

Sub-modules (6)

Cookies And TrackersGreen

ePrivacy Directive Art 5(1)/5(3) require prior user consent for storing or accessing information on terminal equipment, as clarified by EDPB Guidelines 2/2023 on technical scope, applicable directly in Estonia.

Claims (1):

  • Article 5(3) of the ePrivacy Directive requires users' prior consent for storing information, or gaining access to information already stored, in their terminal equipment, as clarified by EDPB Guidelines 2/2023 on the technical scope of Art 5(3), applicable directly in Estonia as an EU Member State.

Dark PatternsRed

No Estonia-specific dark-pattern prohibition distinct from general GDPR fairness/transparency principles was identified in this research pass.

Opt Out SignalsRed

No Estonian or EU-level Global Privacy Control/DAA-equivalent opt-out signal regime was identified; this construct is largely US state-law specific.

Clean Rooms And DcrRed

No Estonia-specific clean-room/data-collaboration-room rules were identified in this research pass.

Cross Context AdvertisingRed

The CPRA 'sale'/'share' cross-context-advertising construct has no direct Estonian/EU equivalent; GDPR's general consent/legitimate-interest framework governs equivalent processing instead.

Direct MarketingGreen

Direct marketing in Estonia is governed by GDPR consent/legitimate-interest and ePrivacy Directive rules on unsolicited communications; no Estonia-specific derogation identified.

Key findings (1)

  • Cookie/ePrivacy consent confirmed in force; several CPRA-style constructs structurally absent. — source on file
Category narrative60 words

Cookie/tracker consent in Estonia follows the ePrivacy Directive's Art 5(3) prior-consent rule as elaborated by EDPB Guidelines 2/2023, applied directly as EU law; CPRA-style constructs (opt-out signals, clean rooms, 'sale'/'share' cross-context advertising) are not native to the EU/Estonian framework and no local equivalent was identified. Direct marketing runs on GDPR consent/legitimate-interest bases with no Estonia-specific derogation found in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedEDPB — Article 5(3) of the ePrivacy Directive requires users' prior consent for storing information, or gaining access to information already stored, in their terminal equipment, as clarified by EDPB Guidelines 2/2023 on the technical scope of Art 5(3), applicable directly in Estonia as an EU Member State.observed

#

Baseline Art 22/ADM and surveillance carve-out rules are settled GDPR/LED law, but the AI Act's implementation timeline and scope are actively being renegotiated via the pending Digital Omnibus on AI.

Primary frameworkGDPR Article 22; EU AI Act (Regulation (EU) 2024/1689); Law Enforcement Directive (EU) 2016/680
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — AmberBaseline Art 22/ADM and surveillance carve-out rules are settled GDPR/LED law, but the AI Act's implementation timeline and scope are actively being renegotiated via the pending Digital Omnibus on AI.

Sub-modules (6)

Profiling RestrictionsAmber

AKI's 2022 rider-rating case exercised GDPR Art 22-adjacent scrutiny over automated/algorithmic driver-rating processing lacking a valid legal basis.

Claims (1):

  • AKI issued a formal injunction on 17 February 2022 requiring a ride-hailing data controller to suspend processing of rider-rating data until compliance measures were implemented and to delete related personal data.

Automated Decision Making TransparencyAmber

AKI required the ride-hailing controller to demonstrate GDPR Art 5(1)(a)/12-14 transparency compliance regarding how rider-rating data is collected, used, and shared before resuming processing.

Claims (1):

  • AKI criticised the ride-hailing controller's compliance with the fairness/transparency principle (GDPR Art 5(1)(a)) and Articles 12-14, finding the obligation to inform data subjects about how their rating data was collected, used, stored and shared had not been met.

Ai Risk AssessmentsAmber

The EDPB/EDPS adopted a January 2026 Joint Opinion on the Digital Omnibus on AI, addressing proposed simplifications to AI Act implementation, including extended compliance timelines (capped at December 2027) for high-risk AI obligations originally due August 2026.

Claims (1):

  • Under the pending AI Act simplification package, entry into application of high-risk AI processing obligations (originally due August 2026) faces an extension capped at December 2027, pending confirmation of implementation standards and support tools.

Biometric RegimeRed

No Estonia-specific biometric-data statute beyond GDPR Art 9 special-category rules was identified in this research pass.

Genetic DataRed

No Estonia-specific genetic-data statute beyond GDPR Art 9 special-category rules was identified in this research pass; note Estonia operates a national Genome/Biobank framework which may carry sector-specific rules not captured in this pass.

State Surveillance CarveoutsAmber

The EDPB has clarified that DPA competence over spyware/surveillance-technology use by private entities falls under GDPR, competent-authority criminal-justice processing falls under the Law Enforcement Directive, and national-security processing falls outside EU law scope.

Claims (1):

  • The EDPB has stated that investigation and enforcement of data-protection rules regarding alleged private-entity spyware use falls under GDPR competence, while processing by competent authorities for criminal-law purposes falls under the Law Enforcement Directive, and national-security processing falls outside the scope of EU law.

Key findings (1)

  • Art 22-adjacent enforcement precedent set (rider-rating case); AI Act timeline extension pending via Digital Omnibus. — source on file
Category narrative92 words

Estonia applies GDPR Art 22 profiling/ADM rules directly, illustrated by AKI's 2022 injunction against a ride-hailing controller's rider-rating processing pending compliance measures. The EU AI Act's interface with GDPR is under active revision via the parallel 'Digital Omnibus on AI', which the EDPB/EDPS opined on in January 2026, including proposed extended timelines for high-risk AI obligations. Law-enforcement/national-security carve-outs are addressed through the EDPB's 2026 spyware letter clarifying that DPA competence for private-entity processing sits under GDPR while competent-authority processing sits under the Law Enforcement Directive, with national-security processing outside EU law scope.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedAKI / EDPB — AKI issued a formal injunction on 17 February 2022 requiring a ride-hailing data controller to suspend processing of rider-rating data until compliance measures were implemented and to delete related personal data.observed
  2. ConfirmedAKI / EDPB — AKI criticised the ride-hailing controller's compliance with the fairness/transparency principle (GDPR Art 5(1)(a)) and Articles 12-14, finding the obligation to inform data subjects about how their rating data was collected, used, stored and shared had not been met.observed
  3. ProbableIAPP — Under the pending AI Act simplification package, entry into application of high-risk AI processing obligations (originally due August 2026) faces an extension capped at December 2027, pending confirmation of implementation standards and support tools.observed
  4. ConfirmedEDPB — The EDPB has stated that investigation and enforcement of data-protection rules regarding alleged private-entity spyware use falls under GDPR competence, while processing by competent authorities for criminal-law purposes falls under the Law Enforcement Directive, and national-security processing falls outside the scope of EU law.observed

#

EU baseline (Art 8 GDPR) is confirmed, but the Estonia-specific national age-of-consent figure and minor/vulnerable-group specifics could not be confirmed from available sources in this pass; escalation recommended.

Primary frameworkGDPR Article 8; PDPA (specific national age threshold unconfirmed in this pass)
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — AmberEU baseline (Art 8 GDPR) is confirmed, but the Estonia-specific national age-of-consent figure and minor/vulnerable-group specifics could not be confirmed from available sources in this pass; escalation recommended.

Sub-modules (5)

Age VerificationAmber

GDPR Art 8(1) sets a default age of 16 for a child's own consent to information-society services, with Member States permitted to lower this to not below 13; Estonia's specific chosen threshold was not confirmed in this research pass.

Claims (1):

  • Under GDPR Article 8(1), processing of a child's personal data in relation to information-society services is lawful where the child is at least 16 years old, but Member States may set a lower age by law provided it is not below 13.

Minor Profiling BansRed

No Estonia-specific minor-profiling ban beyond general GDPR Art 22/Recital 71 principles was identified in this research pass.

Education SettingsRed

No Estonia-specific education-sector children's-data rule was identified in this research pass.

Dependent AdultsRed

No Estonia-specific dependent-adults/vulnerable-adults data-protection regime beyond general GDPR principles was identified in this research pass.

Key findings (1)

  • EU Art 8 baseline confirmed; Estonia's specific national age threshold unconfirmed - flagged gap. — source on file
Category narrative82 words

GDPR Art 8 sets an EU baseline: information-society-service consent is valid from age 16, but Member States may lower this to no less than 13. This research pass did not locate a primary-source confirmation of the specific age Estonia has set by law under Art 8(1) PDPA; this is flagged as an open question requiring escalation to the Estonian Riigi Teataja (State Gazette) text of the PDPA. No Estonia-specific minor-profiling ban, education-settings rule, or dependent-adults regime beyond general GDPR principles was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedEUR-Lex — Under GDPR Article 8(1), processing of a child's personal data in relation to information-society services is lawful where the child is at least 16 years old, but Member States may set a lower age by law provided it is not below 13.observed
  2. ConfirmedEUR-Lex — Where a child is below the applicable age threshold under Article 8(1) GDPR, processing is lawful only if consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this taking into account available technology.observed

#

AKI has active, EDPB-integrated enforcement powers and a functioning complaint/court escalation path, but its fine mechanism structurally departs from the direct-administrative-fine model used elsewhere in the EU (GDPR Recital 151 carve-out), and the surrounding EU legislative framework (Digital Omnibus) is in active flux.

Primary frameworkGDPR Articles 58, 77-84, Recital 151; PDPA; Substitutive Enforcement and Penalty Payment Act (sunniraha)
Supervisory authorityAndmekaitse Inspektsioon (AKI)
Traffic-light rationale — AmberAKI has active, EDPB-integrated enforcement powers and a functioning complaint/court escalation path, but its fine mechanism structurally departs from the direct-administrative-fine model used elsewhere in the EU (GDPR Recital 151 carve-out), and the surrounding EU legislative framework (Digital Omnibus) is in active flux.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Per GDPR Recital 151, administrative fines are not directly applicable in Estonia; AKI instead issues precepts/injunctions carrying penalty payments and may close proceedings with a reprimand where a controller cooperates and voluntarily remedies non-severe, non-intentional issues.

Claims (1):

  • In Estonia, administrative fines are not directly applicable according to GDPR Recital 151; when a controller demonstrates compliance with AKI's guidance and takes corrective action, AKI may close proceedings with a reprimand rather than an administrative fine.

Enforcement Activity IndexAmber

Documented AKI enforcement in recent years spans a 100,000 EUR e-pharmacy penalty payment (2020), a 5,000 EUR Facebook debt-group penalty payment (2023), a 10,000-EUR-per-point Krediidiregister penalty payment (2023), and a 2022 rider-rating injunction, alongside a 2025 published decision applying the reprimand-in-lieu-of-fine approach.

Claims (2):

  • AKI issued a precept with a 100,000 EUR penalty payment and a one-day compliance deadline to three pharmacy chains in a 2020 e-pharmacy prescription-access case.
  • AKI issued a precept with a 5,000 EUR penalty payment against a Facebook-group administrator for unlawfully disclosing individuals' debt data to thousands of unidentified group members.

Regulator Funding And CapacityRed

No specific AKI budget/headcount data was identified in this research pass; flagged as an open question.

Collective Redress And Class ActionsRed

GDPR Art 80 representative-action rights apply directly across the EU including Estonia; no Estonia-specific collective-redress mechanism beyond the general civil-procedure framework was identified in this research pass.

Private Right Of ActionGreen

Data subjects may lodge a free-of-charge complaint with AKI or initiate proceedings directly before an administrative court.

Claims (1):

  • A data subject dissatisfied with, or receiving no reply to, a rights request within 30 days may lodge a free complaint with AKI or bring proceedings directly before an administrative court.

Recent Developments 180DAmber

The EDPB/EDPS adopted a Joint Opinion (10 June 2026, dated as Joint Opinion 2/2026) on the EU Digital Omnibus proposal amending the GDPR, EUDPR, ePrivacy Directive, NIS2 and Data Act; a leaked Council compromise text (dated 20 February 2026) removed the Commission's proposed narrowing of the 'personal data' definition. A parallel Joint Opinion 1/2026 (10 June 2026) addressed the Digital Omnibus on AI. Estonia's Riigikohus also referred Case C-222/25 to the CJEU (lodged 21 March 2025) on AML/GDPR data-processing questions.

Claims (2):

  • The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, strongly urging co-legislators not to adopt the Commission's proposed changes to the GDPR's definition of personal data, while supporting simplification of breach-notification thresholds and deadlines.
  • A leaked 20 February 2026 Council compromise text on the Digital Omnibus, circulated by the Cypriot presidency, eliminated the Commission's proposed new definition of 'personal data' under the GDPR.
Category narrative119 words

AKI's enforcement toolkit is distinctive within the EU: per GDPR Recital 151, administrative fines are not directly applicable in Estonia; AKI instead relies on precepts/injunctions (often with attached 'penalty payment' sums, technically enforced via the Estonian Substitutive Enforcement and Penalty Payment Act) and reprimands. Documented penalty payments range from 5,000 EUR (Facebook debt-disclosure case) to 100,000 EUR (e-pharmacy case) to 10,000 EUR per unfulfilled point (Krediidiregister). Complainants may escalate to AKI or an administrative court free of charge. The most significant 180-day development is the EU Digital Omnibus, which the EDPB/EDPS opined on in February 2026, and which remains in trilogue with a Council compromise text (February 2026) already diverging from the Commission's original proposal on the personal-data definition.

Periodic update · new data 2026-09-28

Enforcement & Redress

AKI imposed a EUR 3,000,000 fine on Allium UPI OU on 5 September 2025 over the Apotheka loyalty-programme data breach, which affected more than 750,000 people, the largest GDPR fine imposed in Estonia to date. The fine is under appeal, with court hearings beginning 6 April 2026; its outcome remains unresolved as of this cycle. The scale of this penalty was made possible by the 2023 legislative simplification of legal-person fining under the IKS, and it arrives against the backdrop of an earlier, unfavourable precedent for the regulator: the annulment of AKI's Asper Biogene fine, which already introduced uncertainty about how far the regulator's enforcement reach actually extends once tested in court.

The statutory ceiling within which this penalty sits is substantial: IKS Sections 66-70 permit fines of up to EUR 20,000,000, or for legal persons up to EUR 20,000,000 or 4 percent of worldwide annual turnover, whichever is greater, classified as an Estonian misdemeanour. The Allium UPI fine, at EUR 3,000,000, represents a fraction of that ceiling, meaning the statutory framework has substantially more room to escalate in a future case of comparable or greater severity, assuming the current fine survives appeal.

Separately from AKI's regulatory enforcement track, Estonian law grants any person who has suffered material or non-material damage from a GDPR infringement a direct right to claim compensation. This creates a second redress channel independent of the regulator's own enforcement outcome, meaning affected individuals from the Apotheka breach are not solely dependent on the fate of AKI's appeal to seek a remedy.

Outlook

The 6 April 2026 appeal hearings are the single most consequential near-term event for this module: a ruling in AKI's favour would confirm the durability of its post-2023 enforcement powers, while a ruling against it, following the Asper Biogene annulment, would suggest a pattern of judicial pushback against the regulator's expanded fining practice.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedAKI / EDPB — In Estonia, administrative fines are not directly applicable according to GDPR Recital 151; when a controller demonstrates compliance with AKI's guidance and takes corrective action, AKI may close proceedings with a reprimand rather than an administrative fine.observed
  2. ConfirmedEDPB / AKI — AKI issued a precept with a 100,000 EUR penalty payment and a one-day compliance deadline to three pharmacy chains in a 2020 e-pharmacy prescription-access case.observed
  3. ConfirmedEDPB / AKI — AKI issued a precept with a 5,000 EUR penalty payment against a Facebook-group administrator for unlawfully disclosing individuals' debt data to thousands of unidentified group members.observed
  4. ConfirmedEDPB — A data subject dissatisfied with, or receiving no reply to, a rights request within 30 days may lodge a free complaint with AKI or bring proceedings directly before an administrative court.observed
  5. ConfirmedEDPB — The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, strongly urging co-legislators not to adopt the Commission's proposed changes to the GDPR's definition of personal data, while supporting simplification of breach-notification thresholds and deadlines.observed
  6. ProbableIAPP — A leaked 20 February 2026 Council compromise text on the Digital Omnibus, circulated by the Cypriot presidency, eliminated the Commission's proposed new definition of 'personal data' under the GDPR.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct85.71
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Estonia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 34 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsage verification
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, data_subject_rights, controller_processor_duties, and enforcement_and_redress modules rest on T1/T2 sources (EDPB official pages, published AKI decisions, EUR-Lex GDPR text) with Confirmed-level confidence. lawful_processing_and_special_data and algorithmic_biometric_and_surveillance_governance combine T1/T2 enforcement case evidence with T1 EDPB opinions on the pending, non-binding EU Digital Omnibus (Probable confidence, is_binding=false). cross_border_and_adequacy relies on T1 GDPR text plus a T2 UK ICO adequacy page for the adequacy_granted sub-module. sectoral_watch is the weakest-evidenced module: financial_sector_overlay and health/credit overlays rest on solid T1/T2 case evidence, but employment_data, education, and insurance sub-modules carry no located Estonia-specific overlay and are marked red with absent_field_provenance-equivalent narrative. adtech_and_commercial_privacy is confirmed for cookies/ePrivacy (T1) but several CPRA-style sub-modules (dark_patterns, opt_out_signals, clean_rooms_and_dcr, cross_context_advertising) have no EU/Estonian equivalent identified and are marked red by design, reflecting a genuine regulatory gap rather than a research shortfall. children_and_vulnerable_groups relies on T1 GDPR Art 8 EU baseline but could NOT confirm Estonia's specific national age-of-consent figure under Art 8(1) PDPA from any source retrieved in this pass — this is the single most significant national-level gap in the baseline and carries explicit absent_field_provenance.

Unresolved questions (6):

  • What specific age (13-16) has Estonia set by law under GDPR Art 8(1) PDPA for a child's own consent to information-society services?
  • Does Estonia maintain any data-localisation or 'data embassy' requirement (e.g., government cloud/backup arrangements) that constitutes a partial data-localisation mandate distinct from GDPR's general transfer rules?
  • Are there Estonia-specific DPO-appointment thresholds or independence rules beyond GDPR Articles 37-39, and what were the outcomes of the 2023 EDPB Coordinated Enforcement Framework DPO review for the 19 Estonian organisations sampled?
  • What is AKI's current budget and headcount, and how does this compare to enforcement caseload (regulator_funding_and_capacity)?
  • Does Estonia have any sector-specific rules for its national genome/biobank (Estonian Genome Center) that constitute a distinct genetic-data regime beyond GDPR Art 9?
  • What is the outcome/status of the Estonian Riigikohus's CJEU reference in Case C-222/25 regarding the Rahapesu Andmebüroo (FIU) and GDPR/AML interplay?

Escalate to primary-source review: yes