What Is Personal Data Protection Act (Isikuandmete kaitse seadus)?
Estonia is an EU member state where the GDPR applies directly alongside the Personal Data Protection Act (Isikuandmete kaitse seadus, IKS). The IKS was enacted on 12 December 2018, published on 4 January 2019, and entered into force on 15 January 2019. Its current wording took effect on 16 March 2026, following amendments effective in 2023, 2025, and 2026. The IKS supplements GDPR procedures for information, access, correction, erasure, restriction, recipient notification, response format, and complaints to AKI. It also contains specific rules for journalism, academic and artistic expression, research, public-interest archiving, child consent, deceased persons, payment-default data, and public-place recording. These exceptions are not blanket waivers of data-subject rights. No general Estonia-specific data-broker complaint/deletion route was located. The ordinary controller-request-then-AKI-complaint route remains the identified mechanism, with a statutory AKI resolution period of 30 days that may be extended by up to 60 additional days with written notice.
At a glance
- Full name
- Personal Data Protection Act (Isikuandmete kaitse seadus)
- Short code
- IKS
- Jurisdiction
- Estonia
- Enacted
- 2018
- Last major update
- Current wording took effect 16 March 2026; the official amendment history shows amendments effective in 2023, 2025, and 2026
- Regulator
- AKI (Andmekaitse Inspektsioon)
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Act (Isikuandmete kaitse seadus)
Scope, who IKS covers
Protected data
Data subject rights
Right to information about processing
Right of access and to receive a copy of personal data
Right to correction of inaccurate or incomplete data
Right to erasure
Right to restriction of processing
Right to data portability
Right to object, including in the payment-default and debt-data context
Rights concerning automated decision-making and profiling
Right to complain to AKI
Notable features
The IKS layers national procedures and targeted exceptions onto directly applicable GDPR rights. Distinctive features include the 13-year information-society-service consent age, narrow payment-default and debt-data rules, research and archiving restrictions, and the concrete 30-day AKI complaint-resolution period extendable by 60 days.
Enforcement & penalties
Regulator: AKI (Andmekaitse Inspektsioon)
Penalties: GDPR Article 83 penalties apply, with fines of up to €10 million or 2% of worldwide annual turnover for the lower tier and up to €20 million or 4% of worldwide annual turnover for the upper tier. The IKS separately provides up to €10 million for offences under §§62-64, or for legal persons the greater of €10 million or 2% of worldwide prior-year turnover; up to €20 million for offences under §§65-70, or for legal persons the greater of €20 million or 4% of worldwide prior-year turnover; and up to 200 fine units for specified offences under §§71-72. Section 71¹ uses the €20 million/4% structure for a narrow political-online-advertising category.
Private right of action: A GDPR Article 78 judicial-remedy trigger applies where there has been no progress or outcome information for three months. A separate general private damages route was not identified in the reviewed report.
Relevance to data brokers
No general Estonia-specific data-broker complaint/deletion route was located. The identified mechanism is the ordinary controller request followed by an AKI complaint. A narrow objection and reassessment route exists for payment-default registers, while business-register republication may be treated as a low-priority supervisory matter and should not be presented as a guaranteed deletion route.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Estonia use the GDPR or a separate privacy law?+
The GDPR applies directly in Estonia, layered with the national Personal Data Protection Act (IKS). The IKS supplements GDPR procedures and adds national exceptions and law-enforcement provisions.
How long does AKI generally have to resolve a complaint?+
Under IKS §61, AKI generally has 30 days to resolve a complaint. The period may be extended by up to 60 additional days with written notice.
Does Estonia have a dedicated data-broker deletion route?+
No general Estonia-specific data-broker complaint/deletion route was located. The reviewed materials identify the ordinary controller-request-then-AKI-complaint route, with a narrow special mechanism for payment-default registers.
Official sources & citations
Other international privacy regimes
IKS sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
