Estonia
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.
Eight questions about Estonia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Estonia's rules apply to my company?
Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.
The Personal Data Protection Act (Isikuandmete kaitse seadus, IKS) says in section 1 that it only 'elaborates and supplements' the General Data Protection Regulation; it does not restate the territorial test, so Article 3 of the Regulation governs and Article 27 supplies the in-Europe representative duty. Estonia's cybersecurity law goes further for one group: under section 4 of the Cybersecurity Act (Kueberturvalisuse seadus, KueTS) a digital service provider with no place of business in the European Union must give the Estonian Information System Authority the address of its representative. Separately, the Gambling Act only lets a company hold an Estonian remote gambling permit if it is registered in Estonia or another European Economic Area state, so foreign gambling operators cannot serve Estonia from outside at all.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated text in force from 16 March 2026, sections 1 and 2
riigiteataja.ee
“This Act regulates: protection of natural persons upon processing of personal data to the extent in which it elaborates and supplements the provisions contained in Regulation (EU) 2016/679”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act (Kueberturvalisuse seadus), consolidated text in force from 1 January 2026, section 4
riigiteataja.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Responsibilities and obligations of a data processor
aki.ee
Link checked 18 August 2026
Can I store my users' data outside Estonia?
In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.
Sector by sector, checked 18 August 2026. TELECOMS: section 111-1(5) of the Electronic Communications Act (Elektroonilise side seadus, ESS) says the retained traffic and location data 'shall be preserved in the territory of a Member State of the European Union', and that three specific categories — the law-enforcement data requests and the answers to them, the interception log files and applications, and single court requests — must be preserved in Estonia. This is a hard wall, not a paperwork step. GAMBLING: sections 23 and 30(2) of the Gambling Act let the Tax and Customs Board refuse a remote gambling permit if the server sits outside Estonia, outside the parties to the Convention on Cybercrime, and outside states whose supervisors have a cooperation agreement with the Tax and Customs Board and the Financial Intelligence Unit. Section 55 also requires that player identification and session data held on that server be accessible to law enforcement without restriction. HEALTH: no localisation rule found in the Health Services Organisation Act, but a 30-year minimum retention applies and the state Health Information System is a national database. GOVERNMENT: no explicit ban on foreign hosting found, but public bodies must exchange data through the state data exchange layer and must apply the Estonian Information Security Standard. BANKING, PAYMENTS, INSURANCE, SECURITIES: no localisation rule found; the Financial Supervision and Resolution Authority regulates outsourcing and cloud use through advisory guidelines, and the European Union's financial resilience rules apply. EDUCATION, MAPPING AND GEOSPATIAL, DEFENCE PROCUREMENT: no localisation rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act (Elektroonilise side seadus), section 111-1, obligation to preserve data
riigiteataja.ee
“The data specified in subsections 2 and 3 of this section shall be preserved in the territory of a Member State of the European Union. The following shall be preserved in the territory of Estonia: 1) the requests and information provided for in § 112 of this Act; 2) the log files specified in subsection 5 of § 113 and the applications provided for in subsection 6 of § 113 of this Act; 3) the single requests provided for in § 114-1 of this Act.”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Gambling Act (Hasartmaenguseadus), consolidated text in force from 1 January 2026, sections 23, 30 and 55
riigiteataja.ee
“The issue of an operating permit may be refused if the operating permit is applied for organising remote gambling and the server containing the software to be used for organising remote gambling is located outside Estonia, states that are parties to the Convention on Cybercrime, and states whose competent authorities have entered into a cooperation agreement with the Tax and Customs Board and the Financial Intelligence Unit”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act (Tervishoiuteenuste korraldamise seadus), sections 42 and 59-1
riigiteataja.ee
Link checked 18 August 2026
What do I need in place before data leaves Estonia?
For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.
The Estonian Data Protection Inspectorate's own guidance sets out the ladder: an adequacy decision, then standard contractual clauses, binding corporate rules, an approved code of conduct or a certification, then the narrow exceptions. It states explicitly that standard contractual clauses and approved codes of conduct need no authorisation, that binding corporate rules need the Inspectorate's approval where the group's lead is in Estonia, and that a bespoke set of clauses needs the Inspectorate's approval after consulting the European Data Protection Board. It also notes that no certification scheme is operational for third-country transfers. The model is an allowlist and the list is populated: the European Commission's approved-destination list currently runs to sixteen countries and territories plus one international organisation, and includes the United States only for organisations self-certified under the European Union-United States Data Privacy Framework.
Sources
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Transfer of personal data to a foreign state under the General Data Protection Regulation
aki.ee
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
Who enforces the rules in Estonia, and what can they do?
The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.
The Inspectorate (Andmekaitse Inspektsioon) is headed by Pille Lehis, appointed 19 August 2019 and confirmed for a second term on 16 May 2024. Its published statistics page, last updated 22 April 2026, gives: complaints, challenges and misdemeanour reports 889 in 2024 and 1,568 in 2025; precepts 26 in 2024 and 13 in 2025; misdemeanour cases concluded 7 in 2024 and 6 in 2025; fines and non-compliance levies 7 in 2024 and 5 in 2025. Four precepts were published in 2026 up to 17 June 2026. Section 73 of the Personal Data Protection Act makes the Inspectorate the extra-judicial body for misdemeanour proceedings with a three-year limitation period, which is why penalty amounts stay small even though sections 65 to 71 allow up to 20 million euros or 4 per cent of worldwide turnover. The Estonian Information System Authority (Riigi Infosueesteemi Amet) supervises the Cybersecurity Act, the Public Information Act data exchange layer, the Emergency Act and the security duties in the Electronic Communications Act, and publishes its enforcement orders; those in 2025 and 2026 cover schools, municipalities, health providers, utilities and state agencies. Other live regulators: the Consumer Protection and Technical Regulatory Authority for telecoms, the Financial Supervision and Resolution Authority for banks and insurers, the Tax and Customs Board for gambling, and the Financial Intelligence Unit for money laundering.
Sources
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Statistics of the Estonian Data Protection Inspectorate, updated 22 April 2026
aki.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Published precepts of the Estonian Data Protection Inspectorate, most recent 17 June 2026
aki.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Structure of the Inspectorate — director general Pille Lehis, 34 service positions
aki.ee
Link checked 18 August 2026
- Official sourceRiigi Infosueesteemi Amet (Estonian Information System Authority)Supervision decisions of the Estonian Information System Authority, most recent 5 June 2026
ria.ee
Link checked 18 August 2026
How long do I have to keep the data?
Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.
FLOORS. Health Services Organisation Act section 42: in-patient and out-patient records 30 years after the data are approved, medical images 30 years, dental images 15 years, autopsy reports 30 years, blood and transfusion records 30 years after death, raw genetic data 30 years; the state Health Information System keeps data with no end date. Money Laundering and Terrorist Financing Prevention Act section 47: at least 5 years after the business relationship ends or the transaction is made, extendable by a further 5 years on a supervisor's compliance notice. Electronic Communications Act section 111-1(4): traffic and location data 1 year from the communication, and requests made under section 112 for 2 years; section 113 requires interception log files and applications to be kept at least 5 years. Gambling Act sections 55 and 57: electronic recordkeeping data at least 5 years, casino visitor records up to 5 years after the last visit, video surveillance at least 14 days. CEILINGS. The general limit is the European storage-limitation rule. Estonia adds three specific ones. Personal Data Protection Act section 9: consent survives death for 10 years, or 20 years if the person died a minor, and heirs control processing until then. Section 10: data about a broken obligation may be passed to credit reference agencies only after 30 days have passed and only for 5 years after the breach ends. Section 74: the old register of data processors is archived for up to 5 years and then erased. Note a common misreading — sections 17, 36 and 40 of the Act, which require a written keep-until date, full processing logs and a data protection specialist, sit in the chapter covering police and prosecutors, not ordinary businesses. CONFLICTS. Estonia resolves a clash the usual European way: a specific statutory keep-time overrides the delete duty for as long as it runs, and section 17(2) says a statutory period may not simply be extended at will.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act, section 42 — 30-year preservation of health records
riigiteataja.ee
“the data certifying the provision of in-patient and out-patient health services shall be preserved for 30 years after the approval of data concerning the service provided to a patient”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Money Laundering and Terrorist Financing Prevention Act, section 47 — five-year preservation of data
riigiteataja.ee
“the obliged entity must retain the originals or copies of the documents ... for no less than five years after the termination of the business relationship”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act, sections 9, 10 and 17
riigiteataja.ee
“The consent of a data subject shall remain valid during the lifetime of the data subject and for 10 years after the death of the data subject, unless the data subject decided otherwise. If the data subject died as a minor, his or her consent shall be valid for the term of 20 years after the death of the data subject.”
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.
The privacy clock is the European 72-hour rule; the Estonian Data Protection Inspectorate states it plainly on its own site. The cyber clock is section 8 of the Cybersecurity Act as rewritten by the amendment published on 30 December 2025 and in force from 1 January 2026, which transposes the European Union's second network and information security directive: an initial notification 'without delay, but no later than 24 hours after becoming aware' of a significant incident, an updating incident notification within 72 hours, an interim report on request, and a final report within one month. A trust service provider has 24 hours rather than 72 for the updating notification. If you outsource or host your system with someone else, you remain responsible for making sure they tell you within 24 hours. Penalties: up to 10 million euros or 2 per cent of worldwide turnover for an essential entity, and up to 7 million euros or 1.4 per cent for an important entity. Both privacy and cyber penalties run through the misdemeanour process with a three-year limitation period, and where a cyber breach also involves personal data the Personal Data Protection Act procedure applies.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, section 8 — obligation of service provider to notify of cyber incident
riigiteataja.ee
“A service provider, except for a security authority, submits to the Estonian Information System Authority an initial notification without delay, but no later than 24 hours after becoming aware of a cyber incident”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Estonian Data Protection Inspectorate — data breach notification within 72 hours
aki.ee
Link checked 18 August 2026
- Official sourceRiigi Infosueesteemi Amet (Estonian Information System Authority)Reporting a cyber incident to CERT-EE
ria.ee
Link checked 18 August 2026
What trips people up in Estonia?
Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.
(1) Section 8 of the Personal Data Protection Act sets the digital consent age at 13; below that a legal representative must consent. (2) Section 9. (3) Section 6 requires pseudonymisation before transfer for research and statistics, requires the controller to designate a named person with access to the re-identification key, and makes an ethics committee verify special-category research in advance; amendments in force from 1 October 2025 extended this framework to government policy analysis. (4) Section 73 makes the Inspectorate an extra-judicial misdemeanour body with a three-year limitation period, and section 71 creates a separate personal offence of up to 200 fine units for an employee who looks up personal data outside their duties, sitting alongside criminal offences in sections 157 and 157-1 of the Penal Code. (5) Section 2-1, in force from 1 January 2025, makes the Inspectorate a 'competent entity' able to bring national and cross-border collective representative actions for data subjects. (6) Section 6-1 of the Cybersecurity Act requires the service provider to designate at least one management board member who approves and oversees security measures and undergoes regular training; if none is designated the duty falls on every board member, and on a sole trader personally. Two further traps worth knowing: recording people in public places, where section 11 replaces consent with a duty to give people a visible chance to avoid being recorded; and the credit-reporting window in section 10, where reporting a missed payment before 30 days have passed, or after 5 years, is unlawful.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act, sections 2-1, 6, 8, 9, 10, 11, 71 and 73
riigiteataja.ee
“If Article 6(1)(a) of Regulation (EU) 2016/679 ... applies in connection with provision of information society services directly to a child, processing of the child's personal data is permitted only in the case the child is at least 13 years old.”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, section 6-1 — obligations of a member of the management board
riigiteataja.ee
“A service provider is to designate at least one member of the management board who approves the security measures, oversees their implementation and is responsible therefor.”
Link checked 18 August 2026
What is changing soon in Estonia?
One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.
DATED ITEMS. 1 October 2026: an unidentified amendment commences across at least eight Estonian acts, evidenced by the end date on every current consolidated text in Riigi Teataja. 12 January 2027: the European Union Data Act requires cloud switching charges and data egress fees to fall to zero. 1 January 2029: the three-year window in section 4-1 and section 28-1 of the Cybersecurity Act closes and every essential and important entity must be fully compliant. At European level, the European Union-United States Data Privacy Framework remains legally valid but is under pressure — the European Data Protection Board wrote to the Commission on 31 July 2026 asking it to re-examine the decision, and the Latombe appeal is pending before the Court of Justice. DORMANT SWITCHES, which matter more than pending bills. First, section 111-1(6) of the Electronic Communications Act lets the Government extend the one-year telecoms retention period by order, in the interest of public order or national security, with only a notification to the European Commission afterwards. Second, section 60 of the Gambling Act lets the Tax and Customs Board order internet providers to block gambling domain names by precept. Third, section 7(5) of the Cybersecurity Act lets the Government or a minister add binding security requirements, including the Estonian Information Security Standard, by regulation without primary legislation. Fourth, section 5-1 of the Personal Data Protection Act on research and policy analysis was widened by regulation-level change as recently as 1 October 2025.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act — consolidated text marked in force 16 March 2026 to 30 September 2026
riigiteataja.ee
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, sections 4-1 and 28-1 — three-month registration and three-year conformity windows
riigiteataja.ee
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act, section 111-1(6) — Government power to extend the retention period
riigiteataja.ee
“In the interest of public order and national security the Government of the Republic may extend, for a limited period, the term specified in subsection 4 of this section.”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges withdrawn from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
1 rule here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
Isikuandmete kaitse üldmäärus — Regulation (EU) 2016/679 (General Data Protection Regulation)
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rules apply directly in Estonia. They do not require data to stay in Europe; they set conditions on sending it out. A companion European regulation bans member states from imposing localisation on non-personal data except on public-security grounds.
Enforced by Estonian Data Protection Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Keep records of processing
- Secure the data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a local representativeRequired where the organisation has no establishment in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
What it costs if you get it wrong
- Percentage of global turnover: 20,000,000 euros or 4 per cent of worldwide group turnover — about $22 millionBreach of basic principles, individual rights or the transfer rules
- Order to stopOrder to stop processing or suspend a transfer
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
National rules1 rule
Isikuandmete kaitse seadus (IKS)
Act of parliament · Personal Data Protection Act, passed 12 December 2018; current consolidated text RT I, 06.03.2026, 2
Estonia's national privacy act adds detail on top of the European rules rather than replacing them. It imposes no data localisation. Its distinctive features are a digital consent age of 13, protection of a dead person's data for 10 or 20 years, strict pre-transfer pseudonymisation for research, and penalties that run through a minor-criminal process rather than an administrative one.
Enforced by Estonian Data Protection Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What it makes you do
- Get a parent's consent for children — applies at: under 13Estonia sets the digital consent age at 13, the European floor, not the 16 used in several neighbouring states.
- Delete data after a period — 10 yearsA deceased person's data stays protected for 10 years after death, 20 years if they died as a minor.
- Delete data after a period — applies at: Credit reference reporting of a broken obligation, 5 yearsAlso a floor: nothing may be reported until 30 days after the breach.
- Appoint a data protection officerThe Act's own data protection specialist duty applies to law enforcement authorities. Everyone else follows the European test.
- Keep logsDetailed processing logs are required of law enforcement authorities, not of ordinary businesses.
What it costs if you get it wrong
- Percentage of global turnover: 20,000,000 euros or 4 per cent of worldwide annual turnover — about $22 millionBreach of processing principles, individual rights, the transfer rules or a regulator order
- Fixed maximum fine: 10,000,000 euros or 2 per cent of worldwide annual turnover — about $11 millionBreach of controller and processor duties such as security, impact assessments and records
- Criminal liability: up to 200 fine unitsAn employee looking up personal data outside their duties; separate criminal offences sit in the Penal Code
- Daily fine until fixedNon-compliance levy attached to a precept
- Claims by individualsSince 1 January 2025 the regulator may itself bring a collective court action for a group of affected people
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated English text in force from 16 March 2026
riigiteataja.ee
“The limitation period of misdemeanours provided in this Chapter is three years. The Estonian Data Protection Inspectorate is the extra-judicial body which conducts proceedings in misdemeanour proceedings provided in this Chapter.”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Transfer of personal data to a foreign state — the Inspectorate's own guidance
aki.ee
Link checked 18 August 2026
Industry rules7 rules
Elektroonilise side seadus (ESS), § 111-1
Act of parliament · Electronic Communications Act, section 111-1; retention duty in force since 1 January 2008, internet data from 15 March 2009; current consolidated text in force 17 August 2026 · Telecoms
Phone and internet companies must keep a year of connection and location records, and those records may not leave the European Union. Three categories tied to police and court access must be held physically in Estonia. Operators bear the cost themselves — the law says the expense is not reimbursed.
Enforced by Consumer Protection and Technical Regulatory Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryRetained traffic and location data must sit inside the European Union. Law-enforcement requests and answers, interception log files and applications, and single court requests must sit inside Estonia.
- Keep data for a minimum period — 1 yearTraffic and location data, counted from the date of the communication. Unsuccessful calls are included; call attempts are not.
- Keep data for a minimum period — 2 yearsRequests made by authorities and the information given in response.
- Keep logs — 5 yearsInterception log files and access applications, which must be destroyed and certified after five years.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceSupervision by the Consumer Protection and Technical Regulatory Authority over communications undertakings
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act (Elektroonilise side seadus), sections 111-1, 112, 113 and 114-1
riigiteataja.ee
“The data specified in subsections 2 and 3 of this section shall be preserved for one year from the date of the communication ... The data specified in subsections 2 and 3 of this section shall be preserved in the territory of a Member State of the European Union.”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European Union via EUR-LexJudgment of the Court of Justice of 2 March 2021 in Case C-746/18 (H. K. v Prokuratuur), on a reference from the Estonian Supreme Court
eur-lex.europa.eu
Link checked 18 August 2026
Hasartmänguseadus (HasMS)
Act of parliament · Gambling Act, sections 23, 30, 55 and 57; current consolidated text in force from 1 January 2026 · Online gaming
An online gambling operator serving Estonia can only place its game server in an approved set of countries, and must give the tax authority a live data connection plus unrestricted law-enforcement access to player identity and session records. The allowlist is real and populated, and the permit can be refused on server location alone.
Enforced by Estonian Tax and Customs Board
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyThe permit application must state the physical address where the remote gambling server sits.
- Keep the data in the countryNot a hard Estonia-only rule, but the server must be in Estonia, in a party to the Convention on Cybercrime, or in a state whose regulators have a cooperation agreement with the Estonian Tax and Customs Board and Financial Intelligence Unit. Otherwise the permit can be refused.
- Keep data for a minimum period — 5 yearsElectronic recordkeeping and control system data, and betting and payout records, must be producible for at least five years.
- Delete data after a period — applies at: Casino visitor records, counted from the last visit, 5 years
What it costs if you get it wrong
- Loss of your licenceRefusal or withdrawal of the remote gambling operating permit
- Order to stopThe Tax and Customs Board may order internet providers to block the domain names of illegal remote gambling
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Gambling Act (Hasartmänguseadus), sections 23, 30, 55 and 57
riigiteataja.ee
“The possessor of a server containing the software used for the organisation of remote gambling and the organiser of remote gambling shall ensure unrestricted access for law enforcement agencies to the data referred to in subsection 1 of this section.”
Link checked 18 August 2026
- Official sourceMaksu- ja Tolliamet (Estonian Tax and Customs Board)Gambling operators — reporting and access: the electronic recordkeeping system and the live link to the tax authority
emta.ee
Link checked 18 August 2026
Küberturvalisuse seadus (KüTS), as amended by RT I, 30.12.2025, 4
Act of parliament · Cybersecurity Act, sections 3-1, 4, 4-1, 6-1, 7, 8, 18-2 and 28-1; amendment transposing Directive (EU) 2022/2555 published 30 December 2025
Estonia transposed the European Union's second cybersecurity directive by an amendment in force on 1 January 2026 — over a year late. Registration was due by 1 April 2026, incident reporting runs on a 24-hour, 72-hour and one-month clock, and full compliance with the security requirements is not due until 1 January 2029. There is no localisation duty.
Enforced by Estonian Information System Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 1 April 2026Essential and important entities, and domain name registration services, had three months from 1 January 2026 to register with the Information System Authority. Changes must be reported within two weeks.
- Report cyber incidents — within 24 hoursInitial warning. A fuller notification follows at 72 hours, an interim report on request, and a final report within one month. Trust service providers have 24 hours for the fuller notification too.
- Secure the data — from 1 January 2029Risk assessment and proportionate technical, operational and organisational measures. Existing providers have three years from 1 January 2026 to reach full conformity.
- Hold a security certificateThe Estonian Information Security Standard (E-ITS) is set by government regulation under section 7(5) and is mandatory for organisations performing public duties.
- Appoint a data protection officerNot a data protection officer — a named management board member who approves security measures, is personally responsible and must undergo regular training.
- Appoint a local representativeA digital service provider with no establishment in the European Union must give the address of its representative.
- Written vendor contractIf you outsource or host with someone else you stay responsible for their security measures and for them telling you of an incident within 24 hours.
What it costs if you get it wrong
- Percentage of global turnover: 10,000,000 euros or 2 per cent of worldwide turnover for an essential entity; 7,000,000 euros or 1.4 per cent for an important entity — about $11 millionBreach of the security-measure or incident-notification duties
- Daily fine until fixedNon-compliance levy attached to a supervision order
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act (Küberturvalisuse seadus), consolidated text in force from 1 January 2026
riigiteataja.ee
“A service provider, including a digital service provider, is to bring its activities into conformity with the requirements of this Act ... within three years as of the date on which it becomes compliant with the characteristics of a service provider”
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Management of state information security measures — the Estonian Information Security Standard (E-ITS)
ria.ee
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Published supervision decisions of the Estonian Information System Authority
ria.ee
Link checked 18 August 2026
Tervishoiuteenuste korraldamise seadus (TTKS)
Act of parliament · Health Services Organisation Act, sections 42, 59-1 to 59-3; current consolidated text in force from 1 July 2026 · Health and social care
No rule found requiring Estonian health data to stay in Estonia, checked 18 August 2026. What health providers do face is a 30-year minimum keep-time on records and images, compulsory participation in the national Health Information System, and a patient right to block cross-border sharing.
Enforced by Estonian Data Protection Inspectorate
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 30 yearsIn-patient and out-patient records, medical images, autopsy reports, transfusion records and raw genetic data. Dental images are 15 years.
- Keep records of processingProviders must feed the national Health Information System and follow its standards, classifications and address system.
- Let people objectA patient may forbid, through the Health Information System, the transmission of their data to another country.
What it costs if you get it wrong
- Loss of your licenceActivity licence conditions include readiness to exchange data with the Health Information System
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act (Tervishoiuteenuste korraldamise seadus), sections 42 and 59-1
riigiteataja.ee
“Data shall be preserved in the Health Information System without a term starting from the acceptance thereof in the information system”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Frequently asked questions — health care and personal data
aki.ee
Link checked 18 August 2026
Nõuded finantsjärelevalve subjekti tegevuse edasiandmisele — Outsourcing Requirements for Supervised Entities
Regulator guideline · Advisory guideline of the Estonian Financial Supervision and Resolution Authority, in force from 31 March 2024; earlier cloud recommendations from 1 July 2018 and the European Banking Authority outsourcing guidelines from 30 September 2019 · Finance
No localisation rule found for Estonian banks, payment firms, insurers or investment firms, checked 18 August 2026. What applies instead is an outsourcing and cloud regime: you must document where the data sits, keep audit and access rights, and have an exit plan. The European Union's financial resilience rules sit on top and override national IT rules.
Enforced by Estonian Financial Supervision and Resolution Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractWritten outsourcing agreement with audit and access rights, and an exit plan.
- Keep records of processingA register of outsourcing arrangements, including where the service and the data sit.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Financial Supervision and Resolution Authority
Sources
- Official sourceFinantsinspektsioon (Estonian Financial Supervision and Resolution Authority)Advisory guidelines — banking and credit, including Outsourcing Requirements for Supervised Entities (31 March 2024) and Recommendations on outsourcing to cloud service providers (1 July 2018)
fi.ee
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), applicable since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
Rahapesu ja terrorismi rahastamise tõkestamise seadus (RahaPTS)
Act of parliament · Money Laundering and Terrorist Financing Prevention Act, section 47; current consolidated text in force from 21 July 2026 · Finance
Anti-money-laundering records must be kept for at least five years after the customer relationship ends, and then deleted unless a supervisor extends the period. There is no requirement to keep them in Estonia, but they must be retrievable without delay for Estonian authorities.
Enforced by Estonian Financial Intelligence Unit
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 5 yearsCounted from the end of the business relationship or the date of the transaction. Data must be produced without delay on request from the Financial Intelligence Unit, other supervisors, investigators or courts.
- Delete data after a period — 10 yearsAfter the five years expire the data must be deleted, unless a supervisor's compliance notice extends it by up to five more years.
What it costs if you get it wrong
- Fixed maximum fineMisdemeanour penalties under the Act, enforced by the Financial Intelligence Unit and the Financial Supervision and Resolution Authority
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Money Laundering and Terrorist Financing Prevention Act, section 47 — preservation of data
riigiteataja.ee
“The obliged entity must retain the documents and data specified in subsections 1, 2 and 3 of this section in a manner that allows for exhaustively and without delay replying to the enquiries of the Financial Intelligence Unit”
Link checked 18 August 2026
Avaliku teabe seadus (AvTS), 5th chapter on databases and the state information system
Act of parliament · Public Information Act, sections 43-1 to 43-10 and 53-1; current consolidated text in force from 16 March 2026 · Government
No blanket ban found on hosting Estonian public-sector systems abroad, checked 18 August 2026. What public bodies and their suppliers must do is register the database, exchange data only through the state's own data layer, and apply the Estonian national security standard. The Information System Authority audits this and publishes its orders.
Enforced by Estonian Information System Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyEvery state and local government database must be registered in the administration system of the state information system before it goes live.
- Hold a security certificatePublic bodies must apply the Estonian Information Security Standard, set by government regulation under the Cybersecurity Act.
- Secure the dataData exchange between state databases must go through the state data exchange layer, X-tee.
What it costs if you get it wrong
- Daily fine until fixedPrecept plus non-compliance levy from the Information System Authority or the Data Protection Inspectorate
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Public Information Act (Avaliku teabe seadus), sections 43-3, 43-7, 43-9 and 53-1
riigiteataja.ee
“Exchange of data with the databases belonging to the state information system and between the databases belonging to the state information system shall be carried out through the data exchange layer of the state information system.”
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Administrative and national supervision by the Estonian Information System Authority
ria.ee
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
What law changes Estonian data rules on 1 October 2026
Riigi Teataja marks the current consolidated texts of the Personal Data Protection Act, Public Information Act, Cybersecurity Act, Electronic Communications Act, Emergency Act, Health Services Organisation Act, Health Insurance Act and Social Welfare Act as valid only to 30 September 2026, which proves an amendment commences on 1 October 2026. The gazette's search interface is a JavaScript application with no reachable search endpoint, so we could not identify the amending act itself. Treat the date as certain and the content as unknown.
Whether the one-year blanket telecoms retention duty in section 111-1 of the Electronic Communications Act is still applied in practice
The text is printed unchanged in the consolidated version in force on 18 August 2026, so a plain reading says it binds. But blanket retention of this design has been repeatedly held incompatible with European Union law, and the Estonian Supreme Court's own reference produced the 2021 Prokuratuur judgment restricting who may authorise access to the data. We could not locate an Estonian court ruling or amendment that removes the retention duty itself, nor confirm current enforcement practice.
Estonian minimum retention periods for accounting and tax records
Widely reported as seven years under the Accounting Act and the Taxation Act, but we could not retrieve either act's text from a government source during this run because the gazette has no machine-readable search and no ministry page we reached links to them. Not asserted in this record.
Whether any localisation or export restriction applies to Estonian mapping and geospatial data
No rule found, checked 18 August 2026. The Land Board's geoportal does not publish licensing or export restrictions on the page we reached, and we could not retrieve the Space Data Act text. Confidence medium, stated as a negative finding rather than a fact.
The largest data protection penalty ever imposed in Estonia
The Inspectorate publishes counts of penalties by year but not amounts. We can evidence that 5 penalties were imposed in 2025 and 7 in 2024, but not their size, so the claim that Estonian penalties stay small is an inference from the misdemeanour procedure, not a verified figure.
Exactly when the 24-hour cyber-incident clock starts biting for organisations that already existed on 1 January 2026
Section 28-1 of the Cybersecurity Act gives existing service providers three years to bring their activities into conformity, while carving out the registration duty at three months. Whether the incident-notification duty falls inside or outside that three-year window is not stated unambiguously in the English text. Plan on the notification duty applying now.
Estonia's data embassy in Luxembourg — its current legal basis and what it holds
Estonia is known for hosting copies of critical state data abroad under diplomatic immunity, which is the reverse of a localisation rule and would be a notable feature of this record. We could not locate a live official page describing it on the Information System Authority's site during this run, so it is deliberately omitted from the rules rather than asserted from memory.
Whether Estonian insurance and securities regulation adds any storage-location duty beyond the outsourcing guidelines
We checked the Financial Supervision and Resolution Authority's published guideline lists for banking and payments and found no localisation rule, but did not retrieve a dedicated insurance or securities guideline index. The finance rule is therefore recorded at medium confidence.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Estonia versus Argentina
- Estonia versus Armenia
- Estonia versus Australia
- Estonia versus Austria
- Estonia versus Azerbaijan
- Estonia versus Brazil
- Estonia versus Bulgaria
- Estonia versus Cambodia
- Estonia versus Canada
- Estonia versus China
- Estonia versus Croatia
- Estonia versus Cyprus
- Estonia versus France
- Estonia versus Georgia
- Estonia versus Germany
- Estonia versus Greece
- Estonia versus Hong Kong SAR
- Estonia versus Hungary
- Estonia versus Iceland
- Estonia versus India
- Estonia versus Indonesia
- Estonia versus Ireland
- Estonia versus Israel
- Estonia versus Italy
- Estonia versus Japan
- Estonia versus Latvia
- Estonia versus Lithuania
- Estonia versus Luxembourg
- Estonia versus Malta
- Estonia versus Mexico
- Estonia versus Mongolia
- Estonia versus Nepal
- Estonia versus Netherlands
- Estonia versus Poland
- Estonia versus Russia
- Estonia versus Saudi Arabia
- Estonia versus Serbia
- Estonia versus Singapore
- Estonia versus Slovakia
- Estonia versus Slovenia
- Estonia versus South Korea
- Estonia versus Spain
- Estonia versus Sri Lanka
- Estonia versus Sweden
- Estonia versus Switzerland
- Estonia versus Taiwan
- Estonia versus Thailand
- Estonia versus Turkey
- Estonia versus Ukraine
- Estonia versus United Arab Emirates
- Estonia versus United Kingdom
- Estonia versus United States
- Estonia versus Uzbekistan