What Estonia Personal Data Protection Act 2018 (IKÜS) - GDPR National Implementation requires
Estonia's Isikuandmete kaitse seadus (IKÜS - Personal Data Protection Act), adopted by the Riigikogu (Estonian Parliament) and published in the Riigi Teataja (RT I, 04.01.2019, 11), entered into force on 15 January 2019 and is Estonia's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Estonia. The GDPR is directly applicable Estonian law by virtue of Estonia's EU membership. The IKÜS provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Estonian Personal Data Protection Act (RT I 2003, 26, 158). Enforcement: the Andmekaitse Inspektsioon (AKI - Data Protection Inspectorate) is Estonia's independent data protection supervisory authority. The AKI is Estonia's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Estonia is a uniquely digital jurisdiction: it operates X-Road, the world's most advanced distributed data exchange platform used by Estonian government services to securely share data between public sector databases; maintains an e-Residency programme allowing digital business identity for non-residents; and operates i-Voting (internet voting) for national elections since 2005. The volume and sensitivity of personal data processed through Estonian digital government infrastructure makes GDPR and IKÜS compliance particularly significant for both public authorities and private sector entities interacting with Estonian digital services. Key Estonian national provisions: (1) Age of digital consent: Estonia has set the age of consent for information society services at 13 years - the lowest age permitted under GDPR (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment - the Employment Contracts Act (Töölepingu seadus, as amended, Estonia) governs employment relationships and the processing of employee personal data alongside GDPR; the Occupational Health and Safety Act (Töötervishoiu ja tööohutuse seadus) governs health and safety data in employment; (3) Freedom of expression - the IKÜS contains exemptions for journalistic, academic, artistic, and literary processing aligned with GDPR Art. 85; Estonian constitutional freedom of expression (Estonian Constitution, § 45) supplements these exemptions; (4) Public sector - Estonian public authorities process significant personal data through X-Road integrated government services; the IKÜS provides specific rules for public authority processing supplementing GDPR Art. 6(1)(e); (5) Research and statistics - extended processing for scientific research, statistics, and archiving in the public interest is permitted with appropriate safeguards under the IKÜS. Fines: GDPR administrative fines apply in Estonia - up to EUR 20 million or 4% of global annual turnover. The AKI has been an active supervisory authority with enforcement actions in digital services, public sector processing, and employment data contexts.
Pillar: Cybersecurity · Authority: Andmekaitse Inspektsioon (AKI - Data Protection Inspectorate, Estonia) · Version: 1.0.0 · Last updated:
Primary source: https://www.aki.ee/
SHA-256 integrity: 174ecd57f9ef9f242322fb945015a9026a428595141748b567f35489af37b41d
Primary Citations — 6 traced to source
- Isikuandmete kaitse seadus (IKÜS - Personal Data Protection Act, Estonia) - RT I, 04.01.2019, 11; in force 15 January 2019; supplements EU GDPR; national derogations: age of digital consent 13 years (lowest permitted under GDPR); public sector X-Road compliance requirements; research and statistics derogations; freedom of expression exemptions; repeals prior Personal Data Protection Act (RT I 2003, 26, 158)
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Estonia; fines up to EUR 20 million or 4% of global annual turnover; AKI is Estonia's supervisory authority and EDPB member; 72-hour breach notification to AKI under Art. 33; DPIA mandatory for high-risk processing under Art. 35; GDPR Art. 22 automated decision-making rights apply to AI-assisted Estonian public services
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access