Skip to the content
Global Data RulesData governance rules, country by country

Estonia

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Estonia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

You can store Estonian data anywhere. Estonia has no general rule forcing data to stay in the country. It adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union. Some of those records must sit on computers in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator is active, but its fines are small.

Data governance in Estonia

The eight things that decide how you handle data about people in Estonia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach you even if you have no office in Estonia. Estonia does not write its own reach test. It uses the European Union's. If you offer goods or services to people in Estonia, the European privacy rules apply. The same is true if you track what people in Estonia do online. Estonia's regulator can then act against you. There is no size or revenue threshold to fall below. If you have no branch anywhere in Europe, you normally have to name a written representative inside Europe.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in general. Estonia has no law telling you to keep personal data in Estonia. European law even stops member states from imposing one on non-personal data. Two industries are different. Phone and internet companies must keep their call and connection records inside the European Union. Certain police-request records must stay on computers in Estonia. Online gambling companies may only place their game server in three kinds of place. In Estonia. In a country that has signed the cybercrime treaty. Or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.

What to do: Plan for a database inside Estonia: this data is not allowed to leave.

Sending data out of the country

For the usual routes you file nothing with the Estonian regulator. If the European Commission has officially approved the destination country as safe enough, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient. You must also check first whether the destination country is safe. Only two routes need the Estonian regulator to sign off. One is group-wide internal rules where the parent company is in Estonia. The other is a one-off contract you wrote yourself.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Certification scheme · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Data Protection Inspectorate, and it is active. It has 34 posts and publishes its orders. Its director general started a second term in May 2024. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. Estonian data protection penalties are handled like minor criminal charges. That makes them slow and small. No Estonian fine has ever come close to the European maximums. Cyber rules are enforced separately by the Information System Authority. It also publishes orders. The most recent was on 5 June 2026.

How long you must keep it — and when to delete it

Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork must be kept for 5 years after the customer leaves. Phone and internet connection records must be kept for 1 year. The police request logs behind them must be kept for 5 years. Gambling records must be kept for 5 years. There are limits the other way too. A dead person's data stays protected for 10 years after death. That becomes 20 years if they died as a child. A missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three separate deadlines. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate. You must also tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority. Then you have 72 hours for a fuller report. Then one month for a final report. Trust service providers, such as e-signature and certificate companies, must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Six things the summary does not tell you. (1) For online services, a child in Estonia is anyone under 13, not 16 as in much of Europe. A consent flow built for Germany will block Estonian teenagers who are old enough. (2) A dead person's data stays protected for 10 years after death, or 20 years if they died as a child. The heirs control it. (3) Research on Estonians must have names stripped out before the data are handed over. An ethics committee must approve sensitive projects. You must name the individual who holds the key that links the data back to people. (4) Data protection fines are handled like minor criminal charges. That keeps them small, but it also pulls a named person into the case. (5) Since 1 January 2025 the regulator can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability · Claims by individuals

What's changing next

One near-term date stands out. Estonia's official gazette marks its current texts of eight laws as valid only until 30 September 2026. Those laws cover privacy, public information, cybersecurity, telecoms, emergencies, health services, health insurance and social welfare. So a further change starts on 1 October 2026. We could not identify the law making the change, so put that date in your diary. After that, the cyber rules phase in. Registration was due by 1 April 2026. Full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.

What to do: Diarise 1 January 2029 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Elektroonilise side seadus (ESS), § 111-1 · Electronic Communications Act, section 111-1; retention duty in force since 1 January 2008, internet data from 15 March 2009; current consolidated text in force 17 August 2026 · Act of parliament

In forceNo — it stays put

Phone and internet companies must keep a year of connection and location records. Those records may not leave the European Union. Three kinds of record tied to police and court access must be held on computers in Estonia. Operators pay for this themselves. The law says the expense is not reimbursed.

In force since 1 January 2008Enforced from 15 March 2009

Enforced by Consumer Protection and Technical Regulatory Authority

How this country controls where data goes: Not allowed

Online gaming

Record-keeping rules for tax and accounts

Official name: Hasartmänguseadus (HasMS) · Gambling Act, sections 23, 30, 55 and 57; current consolidated text in force from 1 January 2026 · Act of parliament

In forceYes, with paperwork

An online gambling operator serving Estonia can only place its game server in an approved set of countries. It must give the tax authority a live data connection. It must also give law enforcement unrestricted access to player identity and session records. The list of approved countries is real and used. A permit can be refused on server location alone.

In force since 1 January 2009

Enforced by Estonian Tax and Customs Board

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Cyber security rules

Official name: Küberturvalisuse seadus (KüTS), as amended by RT I, 30.12.2025, 4 · Cybersecurity Act, sections 3-1, 4, 4-1, 6-1, 7, 8, 18-2 and 28-1; amendment transposing Directive (EU) 2022/2555 published 30 December 2025 · Act of parliament

Partly in forceYes — store it anywhere

Estonia brought the European Union's second cybersecurity directive into national law by an amendment in force on 1 January 2026. That was over a year late. Registration was due by 1 April 2026. Incident reporting runs on a 24-hour, 72-hour and one-month clock. Full compliance with the security requirements is not due until 1 January 2029. Nothing here forces data to stay in Estonia.

In force since 1 January 2026In force now, but not enforced until 1 January 2029

That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2029. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Estonian Information System Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Isikuandmete kaitse seadus (IKS) · Personal Data Protection Act, passed 12 December 2018; current consolidated text RT I, 06.03.2026, 2 · Act of parliament

In forceYes — store it anywhere

Estonia's national privacy law adds detail on top of the European rules rather than replacing them. It does not force data to stay in Estonia. Four points are unusual. The digital consent age is 13. A dead person's data stays protected for 10 or 20 years. Names must be stripped out before data are handed over for research. Penalties are handled like minor criminal charges, not administrative fines.

In force since 15 January 2019

Enforced by Estonian Data Protection Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Isikuandmete kaitse üldmäärus — Regulation (EU) 2016/679 (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rules apply directly in Estonia. They do not require data to stay in Europe. They set conditions on sending it out. A companion European regulation stops member states from forcing non-personal data to stay in the country, except on public-security grounds.

In force since 25 May 2018

Enforced by Estonian Data Protection Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Who you would hear from

  • Andmekaitse Inspektsioon

    Personal data protection and freedom of information across all sectors

    Fully working. The director general is Pille Lehis. She has been in post since 19 August 2019 and was confirmed for a second term on 16 May 2024. The Inspectorate has 34 service positions. Published statistics up to 22 April 2026 show 1,568 complaints, 13 orders, 6 concluded misdemeanour cases and 5 penalties in 2025. Four orders were published in 2026 up to 17 June 2026. Penalties are small because they run through the minor-criminal process rather than administrative fining.

  • Riigi Infosüsteemi Amet (RIA)

    Cybersecurity Act, state information system and data exchange layer, security duties under the Electronic Communications Act and the Emergency Act; hosts CERT-EE

    Actively issuing enforcement orders against schools, municipalities, health providers, utilities and state agencies. The most recent published decision was 5 June 2026. It became the responsible authority for the European cybersecurity directive on 1 January 2026.

  • Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA)

    Telecoms and electronic communications, including the data preservation duty and interception log supervision

  • Maksu- ja Tolliamet (MTA)

    Gambling licensing and supervision, including server location and the live reporting link; tax record keeping

    Runs the electronic gambling reporting system and publishes a list of legal operators and a list of blocked gambling websites.

  • Finantsinspektsioon

    Banks, payment and e-money institutions, insurers, investment firms; outsourcing and cloud guidelines

  • Rahapesu Andmebüroo

    Anti-money-laundering supervision and the five-year record retention duty

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • What law changes Estonian data rules on 1 October 2026

    We know a change to Estonian law starts on 1 October 2026, but we could not identify the law that makes it. Riigi Teataja marks the current texts of eight acts as valid only to 30 September 2026. Those are the Personal Data Protection Act, Public Information Act, Cybersecurity Act, Electronic Communications Act, Emergency Act, Health Services Organisation Act, Health Insurance Act and Social Welfare Act. Treat the date as certain and the content as unknown. Check the gazette closer to the date.

  • Whether the one-year blanket telecoms retention duty in section 111-1 of the Electronic Communications Act is still applied in practice

    We could not confirm whether the telecoms keep-everything rule is still enforced. The text is printed unchanged in the version in force on 18 August 2026, so a plain reading says it binds. But European courts have repeatedly ruled that keeping everyone's records this way breaks European Union law. Estonia's own Supreme Court asked the question, which led to the 2021 Prokuratuur judgment limiting who can approve access. We found no Estonian ruling or change that removes the duty to keep the data. If you run a phone or internet service, ask the regulator before you rely on this.

  • Estonian minimum retention periods for accounting and tax records

    We could not confirm the seven-year keep-time for accounting and tax records. It is widely reported under the Accounting Act and the Taxation Act. We could not get either text from a government source, so we do not state it as fact here. Check with the Tax and Customs Board before you rely on it.

  • Whether any localisation or export restriction applies to Estonian mapping and geospatial data

    We found no rule restricting mapping or space data, checked 18 August 2026. The Land Board's map portal does not publish licensing or export limits on the page we reached. We could not get the text of the Space Data Act. Treat this as a gap in our checking, not proof that no rule exists. If you work with maps or satellite data, check before you rely on it.

  • The largest data protection penalty ever imposed in Estonia

    We could not confirm how large Estonian data protection fines actually are. The Inspectorate publishes how many penalties it imposed each year but not the amounts. We can show 5 penalties in 2025 and 7 in 2024. The claim that Estonian penalties stay small comes from how the process works, not from published figures.

  • Exactly when the 24-hour cyber-incident clock starts biting for organisations that already existed on 1 January 2026

    We could not confirm when the cyber incident-reporting duty starts for existing providers. The Cybersecurity Act gives them three years to bring their activities into line, but requires registration within three months. The English text does not clearly say whether incident reporting sits inside or outside that three-year window. Plan on having to report incidents now.

  • Estonia's data embassy in Luxembourg — its current legal basis and what it holds

    We could not confirm that Estonia keeps copies of critical state data abroad under diplomatic protection. This is widely reported, and it is the opposite of a rule forcing data to stay in the country. We found no live official page describing it on the Information System Authority's site. We have left it out of the rules rather than state it from memory.

  • Whether Estonian insurance and securities regulation adds any storage-location duty beyond the outsourcing guidelines

    We could not fully confirm the position for insurers and investment firms. We checked the Financial Supervision and Resolution Authority's published guideline lists for banking and payments. We found no rule forcing data to stay in the country. We did not find a separate guideline index for insurance or securities. The finance rule is therefore recorded at medium confidence.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.