Estonia
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Estonia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can store Estonian data anywhere. Estonia has no general rule forcing data to stay in the country. It adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union. Some of those records must sit on computers in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator is active, but its fines are small.
Data governance in Estonia
The eight things that decide how you handle data about people in Estonia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules reach you even if you have no office in Estonia. Estonia does not write its own reach test. It uses the European Union's. If you offer goods or services to people in Estonia, the European privacy rules apply. The same is true if you track what people in Estonia do online. Estonia's regulator can then act against you. There is no size or revenue threshold to fall below. If you have no branch anywhere in Europe, you normally have to name a written representative inside Europe.
- What you have to do here:
- Appoint a representative
Estonia's own privacy law is the Personal Data Protection Act (Isikuandmete kaitse seadus, IKS). It says it only adds detail to the European privacy rules. It does not set its own test for who is covered. So the European rules decide that, and they are also what makes you name a representative inside Europe. Estonia's cybersecurity law goes further for one group. The Cybersecurity Act is called Kueberturvalisuse seadus, or KueTS. Under it, a digital service provider with no place of business in the European Union must name a representative. It must give that representative's address to the Estonian Information System Authority. The Gambling Act is stricter again. A company can only hold an Estonian remote gambling permit if it is registered in Estonia or another European Economic Area country. So foreign gambling operators cannot serve Estonia from outside at all.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated text in force from 16 March 2026, sections 1 and 2
riigiteataja.ee
“This Act regulates: protection of natural persons upon processing of personal data to the extent in which it elaborates and supplements the provisions contained in Regulation (EU) 2016/679”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act (Kueberturvalisuse seadus), consolidated text in force from 1 January 2026, section 4
riigiteataja.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Responsibilities and obligations of a data processor
aki.ee
Link checked 18 August 2026
Where the data is allowed to live
Yes, in general. Estonia has no law telling you to keep personal data in Estonia. European law even stops member states from imposing one on non-personal data. Two industries are different. Phone and internet companies must keep their call and connection records inside the European Union. Certain police-request records must stay on computers in Estonia. Online gambling companies may only place their game server in three kinds of place. In Estonia. In a country that has signed the cybercrime treaty. Or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.
Industry by industry, checked 18 August 2026. PHONE AND INTERNET: the Electronic Communications Act is called Elektroonilise side seadus, or ESS. It says stored traffic and location data must be kept inside a European Union member state. Three kinds of record must be kept in Estonia itself. Those are police data requests and the answers to them, interception log files and applications, and single court requests. This is a real ban on moving the data, not a paperwork step. GAMBLING: the Gambling Act lets the Tax and Customs Board refuse a remote gambling permit if the server sits outside Estonia. The same applies if the server sits outside the countries that signed the Convention on Cybercrime. It also applies if the server sits outside countries whose supervisors have a cooperation agreement with the Tax and Customs Board and the Financial Intelligence Unit. Player identity and session data held on that server must also be open to law enforcement without restriction. HEALTH: we found no rule in the Health Services Organisation Act forcing health data to stay in Estonia. Records must be kept for at least 30 years, and the state Health Information System is a national database. GOVERNMENT: we found no explicit ban on hosting abroad. Public bodies must exchange data through the state data-sharing system and must apply the Estonian Information Security Standard. BANKING, PAYMENTS, INSURANCE, SECURITIES: we found no rule forcing data to stay in the country. The Financial Supervision and Resolution Authority sets guidance on outsourcing and cloud use, and the European Union's financial resilience rules apply. EDUCATION, MAPPING AND GEOSPATIAL, DEFENCE PROCUREMENT: we found no rule forcing data to stay in the country, checked 18 August 2026, medium confidence.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act (Elektroonilise side seadus), section 111-1, obligation to preserve data
riigiteataja.ee
“The data specified in subsections 2 and 3 of this section shall be preserved in the territory of a Member State of the European Union. The following shall be preserved in the territory of Estonia: 1) the requests and information provided for in § 112 of this Act; 2) the log files specified in subsection 5 of § 113 and the applications provided for in subsection 6 of § 113 of this Act; 3) the single requests provided for in § 114-1 of this Act.”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Gambling Act (Hasartmaenguseadus), consolidated text in force from 1 January 2026, sections 23, 30 and 55
riigiteataja.ee
“The issue of an operating permit may be refused if the operating permit is applied for organising remote gambling and the server containing the software to be used for organising remote gambling is located outside Estonia, states that are parties to the Convention on Cybercrime, and states whose competent authorities have entered into a cooperation agreement with the Tax and Customs Board and the Financial Intelligence Unit”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act (Tervishoiuteenuste korraldamise seadus), sections 42 and 59-1
riigiteataja.ee
Link checked 18 August 2026
What to do: Plan for a database inside Estonia: this data is not allowed to leave.
Sending data out of the country
For the usual routes you file nothing with the Estonian regulator. If the European Commission has officially approved the destination country as safe enough, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient. You must also check first whether the destination country is safe. Only two routes need the Estonian regulator to sign off. One is group-wide internal rules where the parent company is in Estonia. The other is a one-off contract you wrote yourself.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Approved code of conduct · Certification scheme · Government sign-off needed
The Estonian Data Protection Inspectorate's own guidance sets out the order to try. First, an official decision that the destination country is safe enough. Then the European standard contract, group-wide internal rules, an approved code of conduct, or a certification. After that, only a few narrow exceptions. The guidance says the standard contract and approved codes of conduct need no permission. Group-wide internal rules need the Inspectorate's approval where the group's lead company is in Estonia. A contract you wrote yourself needs the Inspectorate's approval, after it consults the European Data Protection Board. The guidance also notes that no certification scheme is running for transfers outside Europe. You can send data freely only to approved countries, and that approved list is real. The European Commission's list currently runs to sixteen countries and territories plus one international organisation. It includes the United States only for organisations signed up to the European Union-United States Data Privacy Framework.
Sources
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Transfer of personal data to a foreign state under the General Data Protection Regulation
aki.ee
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Data Protection Inspectorate, and it is active. It has 34 posts and publishes its orders. Its director general started a second term in May 2024. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. Estonian data protection penalties are handled like minor criminal charges. That makes them slow and small. No Estonian fine has ever come close to the European maximums. Cyber rules are enforced separately by the Information System Authority. It also publishes orders. The most recent was on 5 June 2026.
The Inspectorate (Andmekaitse Inspektsioon) is headed by Pille Lehis. She was appointed on 19 August 2019 and confirmed for a second term on 16 May 2024. Its published statistics page was last updated on 22 April 2026. It shows 889 complaints, challenges and misdemeanour reports in 2024, and 1,568 in 2025. Orders were 26 in 2024 and 13 in 2025. Misdemeanour cases concluded were 7 in 2024 and 6 in 2025. Fines and non-compliance levies were 7 in 2024 and 5 in 2025. Four orders were published in 2026 up to 17 June 2026. The Personal Data Protection Act makes the Inspectorate a non-court body for minor criminal cases, with a three-year time limit. That is why penalty amounts stay small, even though the Act allows up to 20 million euros or 4 per cent of worldwide turnover. The Estonian Information System Authority is called Riigi Infosueesteemi Amet. It polices four things. The Cybersecurity Act, the state data-sharing system under the Public Information Act, the Emergency Act, and the security duties in the Electronic Communications Act. It publishes its enforcement orders. Those in 2025 and 2026 cover schools, municipalities, health providers, utilities and state agencies. Other active regulators are the Consumer Protection and Technical Regulatory Authority for telecoms, the Financial Supervision and Resolution Authority for banks and insurers, the Tax and Customs Board for gambling, and the Financial Intelligence Unit for money laundering.
Sources
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Statistics of the Estonian Data Protection Inspectorate, updated 22 April 2026
aki.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Published precepts of the Estonian Data Protection Inspectorate, most recent 17 June 2026
aki.ee
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Structure of the Inspectorate — director general Pille Lehis, 34 service positions
aki.ee
Link checked 18 August 2026
- Official sourceRiigi Infosueesteemi Amet (Estonian Information System Authority)Supervision decisions of the Estonian Information System Authority, most recent 5 June 2026
ria.ee
Link checked 18 August 2026
How long you must keep it — and when to delete it
Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork must be kept for 5 years after the customer leaves. Phone and internet connection records must be kept for 1 year. The police request logs behind them must be kept for 5 years. Gambling records must be kept for 5 years. There are limits the other way too. A dead person's data stays protected for 10 years after death. That becomes 20 years if they died as a child. A missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUM KEEP-TIMES. Health Services Organisation Act: in-patient and out-patient records 30 years after the data are approved. Medical images 30 years. Dental images 15 years. Autopsy reports 30 years. Blood and transfusion records 30 years after death. Raw genetic data 30 years. The state Health Information System keeps data with no end date. Money Laundering and Terrorist Financing Prevention Act: at least 5 years after the business relationship ends or the transaction is made. A supervisor can add a further 5 years by written notice. Electronic Communications Act: traffic and location data 1 year from the communication, and authority requests for 2 years. Interception log files and applications must be kept at least 5 years. Gambling Act: electronic record data at least 5 years. Casino visitor records up to 5 years after the last visit. Video surveillance at least 14 days. MAXIMUM KEEP-TIMES. The general limit is the European rule that you delete data once you no longer need it. Estonia adds three specific limits. Consent survives death for 10 years, or 20 years if the person died a child, and heirs decide what happens to the data until then. Data about a missed payment may be passed to credit reference agencies only after 30 days have passed. It may be passed on only for 5 years after the missed payment ends. The old register of data users is archived for up to 5 years and then erased. CLASHES. Estonia solves a clash the usual European way. A specific keep-time set by law beats the duty to delete for as long as that keep-time runs. The Act also says a keep-time set by law may not simply be extended at will. One point to watch. Three duties sit in the chapter covering police and prosecutors. They are the written delete-by date, the full usage logs, and the data protection specialist. They do not apply to ordinary businesses.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act, section 42 — 30-year preservation of health records
riigiteataja.ee
“the data certifying the provision of in-patient and out-patient health services shall be preserved for 30 years after the approval of data concerning the service provided to a patient”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Money Laundering and Terrorist Financing Prevention Act, section 47 — five-year preservation of data
riigiteataja.ee
“the obliged entity must retain the originals or copies of the documents ... for no less than five years after the termination of the business relationship”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act, sections 9, 10 and 17
riigiteataja.ee
“The consent of a data subject shall remain valid during the lifetime of the data subject and for 10 years after the death of the data subject, unless the data subject decided otherwise. If the data subject died as a minor, his or her consent shall be valid for the term of 20 years after the death of the data subject.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three separate deadlines. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate. You must also tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority. Then you have 72 hours for a fuller report. Then one month for a final report. Trust service providers, such as e-signature and certificate companies, must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The privacy deadline is the European 72-hour rule. The Estonian Data Protection Inspectorate states it plainly on its own site. The cyber deadline comes from the Cybersecurity Act, as rewritten by an amendment published on 30 December 2025 and in force from 1 January 2026. That amendment brings the European Union's second network and information security directive into Estonian law. It requires a first notice without delay, and no later than 24 hours after you become aware of a significant incident. An update follows within 72 hours. An interim report follows if asked for. A final report is due within one month. A trust service provider has 24 hours rather than 72 for the update. If you outsource or host your system with someone else, you stay responsible for making sure they tell you within 24 hours. Penalties reach up to 10 million euros or 2 per cent of worldwide turnover for an essential entity. For an important entity they reach up to 7 million euros or 1.4 per cent. Both privacy and cyber penalties run through the minor-criminal process, with a three-year time limit. Where a cyber breach also involves personal data, the Personal Data Protection Act procedure applies.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, section 8 — obligation of service provider to notify of cyber incident
riigiteataja.ee
“A service provider, except for a security authority, submits to the Estonian Information System Authority an initial notification without delay, but no later than 24 hours after becoming aware of a cyber incident”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Estonian Data Protection Inspectorate — data breach notification within 72 hours
aki.ee
Link checked 18 August 2026
- Official sourceRiigi Infosueesteemi Amet (Estonian Information System Authority)Reporting a cyber incident to CERT-EE
ria.ee
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Six things the summary does not tell you. (1) For online services, a child in Estonia is anyone under 13, not 16 as in much of Europe. A consent flow built for Germany will block Estonian teenagers who are old enough. (2) A dead person's data stays protected for 10 years after death, or 20 years if they died as a child. The heirs control it. (3) Research on Estonians must have names stripped out before the data are handed over. An ethics committee must approve sensitive projects. You must name the individual who holds the key that links the data back to people. (4) Data protection fines are handled like minor criminal charges. That keeps them small, but it also pulls a named person into the case. (5) Since 1 January 2025 the regulator can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
(1) The Personal Data Protection Act sets the digital consent age at 13. Below that age a parent or guardian must consent. (2) The same Act protects a dead person's data. (3) The Act requires names to be stripped out before data are handed over for research and statistics. The company handing the data over must name one person who can access the key that links the data back to people. An ethics committee must check sensitive research in advance. Changes in force from 1 October 2025 extended these rules to government policy analysis. (4) The Act makes the Inspectorate a non-court body for minor criminal cases, with a three-year time limit. It also creates a separate personal offence for an employee who looks up personal data outside their duties, worth up to 200 fine units. Crimes in the Penal Code sit alongside it. (5) A change in force from 1 January 2025 lets the Inspectorate bring group claims for affected people, in Estonia and across borders. (6) The Cybersecurity Act requires a service provider to name at least one management board member. That person approves and oversees security measures, and gets regular training. If nobody is named, the duty falls on every board member, and on a sole trader personally. Two more points are worth knowing. When you record people in public places you do not need consent, but you must give people a visible chance to avoid being recorded. And reporting a missed payment to credit agencies before 30 days have passed, or after 5 years, is against the law.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act, sections 2-1, 6, 8, 9, 10, 11, 71 and 73
riigiteataja.ee
“If Article 6(1)(a) of Regulation (EU) 2016/679 ... applies in connection with provision of information society services directly to a child, processing of the child's personal data is permitted only in the case the child is at least 13 years old.”
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, section 6-1 — obligations of a member of the management board
riigiteataja.ee
“A service provider is to designate at least one member of the management board who approves the security measures, oversees their implementation and is responsible therefor.”
Link checked 18 August 2026
What's changing next
One near-term date stands out. Estonia's official gazette marks its current texts of eight laws as valid only until 30 September 2026. Those laws cover privacy, public information, cybersecurity, telecoms, emergencies, health services, health insurance and social welfare. So a further change starts on 1 October 2026. We could not identify the law making the change, so put that date in your diary. After that, the cyber rules phase in. Registration was due by 1 April 2026. Full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.
DATED ITEMS. 1 October 2026: an unidentified change starts across at least eight Estonian laws. The evidence is the end date printed on every current consolidated text in Riigi Teataja. 12 January 2027: the European Union Data Act cuts cloud switching charges and data export fees to zero. 1 January 2029: the three-year window in the Cybersecurity Act closes and every essential and important entity must be fully compliant. At European level, the European Union-United States Data Privacy Framework is still legally valid but under pressure. The European Data Protection Board wrote to the Commission on 31 July 2026 asking it to re-examine the decision. The Latombe appeal is pending before the Court of Justice. POWERS THAT COULD BE USED WITHOUT A NEW LAW. These matter more than pending bills. First, the Electronic Communications Act lets the Government extend the one-year telecoms keep-time by order, for public order or national security. It only has to tell the European Commission afterwards. Second, the Gambling Act lets the Tax and Customs Board order internet providers to block gambling websites. Third, the Cybersecurity Act lets the Government or a minister add binding security requirements, including the Estonian Information Security Standard, without a new law. Fourth, the part of the Personal Data Protection Act on research and policy analysis was widened this way as recently as 1 October 2025.
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act — consolidated text marked in force 16 March 2026 to 30 September 2026
riigiteataja.ee
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act, sections 4-1 and 28-1 — three-month registration and three-year conformity windows
riigiteataja.ee
Link checked 18 August 2026
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act, section 111-1(6) — Government power to extend the retention period
riigiteataja.ee
“In the interest of public order and national security the Government of the Republic may extend, for a limited period, the term specified in subsection 4 of this section.”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges withdrawn from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 1 January 2029 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Elektroonilise side seadus (ESS), § 111-1 · Electronic Communications Act, section 111-1; retention duty in force since 1 January 2008, internet data from 15 March 2009; current consolidated text in force 17 August 2026 · Act of parliament
Phone and internet companies must keep a year of connection and location records. Those records may not leave the European Union. Three kinds of record tied to police and court access must be held on computers in Estonia. Operators pay for this themselves. The law says the expense is not reimbursed.
Enforced by Consumer Protection and Technical Regulatory Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryStored traffic and location data must sit inside the European Union. Police requests and answers, interception log files and applications, and single court requests must sit inside Estonia.
- Keep data for a minimum period — 1 yearTraffic and location data, counted from the date of the communication. Unsuccessful calls are included. Call attempts are not.
- Keep data for a minimum period — 2 yearsRequests made by authorities and the information given in response.
- Keep logs — 5 yearsInterception log files and access applications. After five years they must be destroyed, and the destruction must be certified.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceSupervision by the Consumer Protection and Technical Regulatory Authority over communications undertakings
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Electronic Communications Act (Elektroonilise side seadus), sections 111-1, 112, 113 and 114-1
riigiteataja.ee
“The data specified in subsections 2 and 3 of this section shall be preserved for one year from the date of the communication ... The data specified in subsections 2 and 3 of this section shall be preserved in the territory of a Member State of the European Union.”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European Union via EUR-LexJudgment of the Court of Justice of 2 March 2021 in Case C-746/18 (H. K. v Prokuratuur), on a reference from the Estonian Supreme Court
eur-lex.europa.eu
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Hasartmänguseadus (HasMS) · Gambling Act, sections 23, 30, 55 and 57; current consolidated text in force from 1 January 2026 · Act of parliament
An online gambling operator serving Estonia can only place its game server in an approved set of countries. It must give the tax authority a live data connection. It must also give law enforcement unrestricted access to player identity and session records. The list of approved countries is real and used. A permit can be refused on server location alone.
Enforced by Estonian Tax and Customs Board
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyThe permit application must state the physical address where the remote gambling server sits.
- Keep the data in the countryThe server does not have to be in Estonia. It must be in Estonia, or in a country that signed the Convention on Cybercrime. It can also be in a country whose regulators have a cooperation agreement with the Estonian Tax and Customs Board and Financial Intelligence Unit. Otherwise the permit can be refused.
- Keep data for a minimum period — 5 yearsYou must be able to produce electronic record and control system data, plus betting and payout records, for at least five years.
- Delete data after a period — applies at: Casino visitor records, counted from the last visit, 5 years
What it costs if you get it wrong
- Loss of your licenceRefusal or withdrawal of the remote gambling operating permit
- Order to stopThe Tax and Customs Board may order internet providers to block the domain names of illegal remote gambling
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Gambling Act (Hasartmänguseadus), sections 23, 30, 55 and 57
riigiteataja.ee
“The possessor of a server containing the software used for the organisation of remote gambling and the organiser of remote gambling shall ensure unrestricted access for law enforcement agencies to the data referred to in subsection 1 of this section.”
Link checked 18 August 2026
- Official sourceMaksu- ja Tolliamet (Estonian Tax and Customs Board)Gambling operators — reporting and access: the electronic recordkeeping system and the live link to the tax authority
emta.ee
Link checked 18 August 2026
Cyber security rules
Official name: Küberturvalisuse seadus (KüTS), as amended by RT I, 30.12.2025, 4 · Cybersecurity Act, sections 3-1, 4, 4-1, 6-1, 7, 8, 18-2 and 28-1; amendment transposing Directive (EU) 2022/2555 published 30 December 2025 · Act of parliament
Estonia brought the European Union's second cybersecurity directive into national law by an amendment in force on 1 January 2026. That was over a year late. Registration was due by 1 April 2026. Incident reporting runs on a 24-hour, 72-hour and one-month clock. Full compliance with the security requirements is not due until 1 January 2029. Nothing here forces data to stay in Estonia.
That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2029. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Estonian Information System Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 1 April 2026Essential and important entities, and domain name registration services, had three months from 1 January 2026 to register with the Information System Authority. Changes must be reported within two weeks.
- Report cyber incidents — within 24 hoursInitial warning. A fuller notification follows at 72 hours, an interim report on request, and a final report within one month. Trust service providers have 24 hours for the fuller notification too.
- Secure the data — from 1 January 2029You must assess your risks and put in place suitable technical, operational and organisational measures. Existing providers have three years from 1 January 2026 to fully comply.
- Hold a security certificateThe Estonian Information Security Standard (E-ITS) is set by government regulation. It is compulsory for organisations performing public duties.
- Appoint a data protection officerThis is not a data protection officer. It is a named management board member. They approve security measures, are personally responsible, and must get regular training.
- Appoint a representativeIf you provide a digital service and have no office in the European Union, you must give the address of your representative.
- Written vendor contractIf you outsource or host with someone else, you stay responsible for their security measures. You are also responsible for them telling you of an incident within 24 hours.
What it costs if you get it wrong
- Percentage of global turnover: 10,000,000 euros or 2 per cent of worldwide turnover for an essential entity; 7,000,000 euros or 1.4 per cent for an important entity — about $11 millionBreach of the security-measure or incident-notification duties
- Daily fine until fixedNon-compliance levy attached to a supervision order
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Cybersecurity Act (Küberturvalisuse seadus), consolidated text in force from 1 January 2026
riigiteataja.ee
“A service provider, including a digital service provider, is to bring its activities into conformity with the requirements of this Act ... within three years as of the date on which it becomes compliant with the characteristics of a service provider”
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Management of state information security measures — the Estonian Information Security Standard (E-ITS)
ria.ee
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Published supervision decisions of the Estonian Information System Authority
ria.ee
Link checked 18 August 2026
Health data rules
Official name: Tervishoiuteenuste korraldamise seadus (TTKS) · Health Services Organisation Act, sections 42, 59-1 to 59-3; current consolidated text in force from 1 July 2026 · Act of parliament
We found no rule requiring Estonian health data to stay in Estonia, checked 18 August 2026. Health providers do face other duties. Records and images must be kept for at least 30 years. You must take part in the national Health Information System. Patients can block sharing of their data with another country.
Enforced by Estonian Data Protection Inspectorate
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 30 yearsIn-patient and out-patient records, medical images, autopsy reports, transfusion records and raw genetic data. Dental images are 15 years.
- Keep records of how you use dataProviders must feed the national Health Information System and follow its standards, classifications and address system.
- Let people objectA patient may forbid, through the Health Information System, the transmission of their data to another country.
What it costs if you get it wrong
- Loss of your licenceActivity licence conditions include readiness to exchange data with the Health Information System
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Health Services Organisation Act (Tervishoiuteenuste korraldamise seadus), sections 42 and 59-1
riigiteataja.ee
“Data shall be preserved in the Health Information System without a term starting from the acceptance thereof in the information system”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Frequently asked questions — health care and personal data
aki.ee
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Nõuded finantsjärelevalve subjekti tegevuse edasiandmisele — Outsourcing Requirements for Supervised Entities · Advisory guideline of the Estonian Financial Supervision and Resolution Authority, in force from 31 March 2024; earlier cloud recommendations from 1 July 2018 and the European Banking Authority outsourcing guidelines from 30 September 2019 · Regulator guideline
We found no rule requiring Estonian banks, payment firms, insurers or investment firms to keep data in the country, checked 18 August 2026. Instead there are rules on outsourcing and cloud use. You must record where the data sits. You must keep audit and access rights. You must have an exit plan. The European Union's financial resilience rules sit on top and override national IT rules.
Enforced by Estonian Financial Supervision and Resolution Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractWritten outsourcing agreement with audit and access rights, and an exit plan.
- Keep records of how you use dataA register of outsourcing arrangements, including where the service and the data sit.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Financial Supervision and Resolution Authority
Sources
- Official sourceFinantsinspektsioon (Estonian Financial Supervision and Resolution Authority)Advisory guidelines — banking and credit, including Outsourcing Requirements for Supervised Entities (31 March 2024) and Recommendations on outsourcing to cloud service providers (1 July 2018)
fi.ee
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), applicable since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
Finance data rules
Official name: Rahapesu ja terrorismi rahastamise tõkestamise seadus (RahaPTS) · Money Laundering and Terrorist Financing Prevention Act, section 47; current consolidated text in force from 21 July 2026 · Act of parliament
Anti-money-laundering records must be kept for at least five years after the customer relationship ends. Then you must delete them, unless a supervisor extends the period. You do not have to keep them in Estonia. But Estonian authorities must be able to get them without delay.
Enforced by Estonian Financial Intelligence Unit
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 5 yearsCounted from the end of the business relationship or the date of the transaction. Data must be produced without delay on request from the Financial Intelligence Unit, other supervisors, investigators or courts.
- Delete data after a period — 10 yearsAfter the five years expire the data must be deleted, unless a supervisor's compliance notice extends it by up to five more years.
What it costs if you get it wrong
- Fixed maximum fineMisdemeanour penalties under the Act, enforced by the Financial Intelligence Unit and the Financial Supervision and Resolution Authority
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Money Laundering and Terrorist Financing Prevention Act, section 47 — preservation of data
riigiteataja.ee
“The obliged entity must retain the documents and data specified in subsections 1, 2 and 3 of this section in a manner that allows for exhaustively and without delay replying to the enquiries of the Financial Intelligence Unit”
Link checked 18 August 2026
State and security data rules
Official name: Avaliku teabe seadus (AvTS), 5th chapter on databases and the state information system · Public Information Act, sections 43-1 to 43-10 and 53-1; current consolidated text in force from 16 March 2026 · Act of parliament
We found no general ban on hosting Estonian public-sector systems abroad, checked 18 August 2026. Public bodies and their suppliers must register the database. They must exchange data only through the state's own data-sharing system. They must apply the Estonian national security standard. The Information System Authority checks this and publishes its orders.
Enforced by Estonian Information System Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyEvery state and local government database must be registered in the administration system of the state information system before it goes live.
- Hold a security certificatePublic bodies must apply the Estonian Information Security Standard, set by government regulation under the Cybersecurity Act.
- Secure the dataData exchange between state databases must go through the state data exchange layer, X-tee.
What it costs if you get it wrong
- Daily fine until fixedPrecept plus non-compliance levy from the Information System Authority or the Data Protection Inspectorate
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Public Information Act (Avaliku teabe seadus), sections 43-3, 43-7, 43-9 and 53-1
riigiteataja.ee
“Exchange of data with the databases belonging to the state information system and between the databases belonging to the state information system shall be carried out through the data exchange layer of the state information system.”
Link checked 18 August 2026
- Official sourceRiigi Infosüsteemi Amet (Estonian Information System Authority)Administrative and national supervision by the Estonian Information System Authority
ria.ee
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Isikuandmete kaitse seadus (IKS) · Personal Data Protection Act, passed 12 December 2018; current consolidated text RT I, 06.03.2026, 2 · Act of parliament
Estonia's national privacy law adds detail on top of the European rules rather than replacing them. It does not force data to stay in Estonia. Four points are unusual. The digital consent age is 13. A dead person's data stays protected for 10 or 20 years. Names must be stripped out before data are handed over for research. Penalties are handled like minor criminal charges, not administrative fines.
Enforced by Estonian Data Protection Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What you have to do
- Get a parent's consent for children — applies at: under 13Estonia sets the digital consent age at 13. That is the lowest Europe allows. Several neighbouring countries use 16.
- Delete data after a period — 10 yearsA dead person's data stays protected for 10 years after death. It is 20 years if they died a child.
- Delete data after a period — applies at: Credit reference reporting of a broken obligation, 5 yearsThere is also a minimum wait. You may not report anything until 30 days after the missed payment.
- Appoint a data protection officerThe Act's own duty to appoint a data protection specialist applies to police and prosecutors. Everyone else follows the European test.
- Keep logsDetailed logs of who used the data are required of police and prosecutors, not of ordinary businesses.
What it costs if you get it wrong
- Percentage of global turnover: 20,000,000 euros or 4 per cent of worldwide annual turnover — about $22 millionBreach of processing principles, individual rights, the transfer rules or a regulator order
- Fixed maximum fine: 10,000,000 euros or 2 per cent of worldwide annual turnover — about $11 millionBreach of controller and processor duties such as security, impact assessments and records
- Criminal liability: up to 200 fine unitsAn employee looking up personal data outside their duties; separate criminal offences sit in the Penal Code
- Daily fine until fixedNon-compliance levy attached to a precept
- Claims by individualsSince 1 January 2025 the regulator may itself bring a collective court action for a group of affected people
Sources
- Official sourceRiigi Teataja (State Gazette of Estonia)Personal Data Protection Act (Isikuandmete kaitse seadus), consolidated English text in force from 16 March 2026
riigiteataja.ee
“The limitation period of misdemeanours provided in this Chapter is three years. The Estonian Data Protection Inspectorate is the extra-judicial body which conducts proceedings in misdemeanour proceedings provided in this Chapter.”
Link checked 18 August 2026
- Official sourceAndmekaitse Inspektsioon (Estonian Data Protection Inspectorate)Transfer of personal data to a foreign state — the Inspectorate's own guidance
aki.ee
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Isikuandmete kaitse üldmäärus — Regulation (EU) 2016/679 (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rules apply directly in Estonia. They do not require data to stay in Europe. They set conditions on sending it out. A companion European regulation stops member states from forcing non-personal data to stay in the country, except on public-security grounds.
Enforced by Estonian Data Protection Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Keep records of how you use data
- Secure the data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a representativeYou need this if you have no office in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
What it costs if you get it wrong
- Percentage of global turnover: 20,000,000 euros or 4 per cent of worldwide group turnover — about $22 millionBreach of basic principles, individual rights or the transfer rules
- Order to stopOrder to stop processing or suspend a transfer
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
What law changes Estonian data rules on 1 October 2026
We know a change to Estonian law starts on 1 October 2026, but we could not identify the law that makes it. Riigi Teataja marks the current texts of eight acts as valid only to 30 September 2026. Those are the Personal Data Protection Act, Public Information Act, Cybersecurity Act, Electronic Communications Act, Emergency Act, Health Services Organisation Act, Health Insurance Act and Social Welfare Act. Treat the date as certain and the content as unknown. Check the gazette closer to the date.
Whether the one-year blanket telecoms retention duty in section 111-1 of the Electronic Communications Act is still applied in practice
We could not confirm whether the telecoms keep-everything rule is still enforced. The text is printed unchanged in the version in force on 18 August 2026, so a plain reading says it binds. But European courts have repeatedly ruled that keeping everyone's records this way breaks European Union law. Estonia's own Supreme Court asked the question, which led to the 2021 Prokuratuur judgment limiting who can approve access. We found no Estonian ruling or change that removes the duty to keep the data. If you run a phone or internet service, ask the regulator before you rely on this.
Estonian minimum retention periods for accounting and tax records
We could not confirm the seven-year keep-time for accounting and tax records. It is widely reported under the Accounting Act and the Taxation Act. We could not get either text from a government source, so we do not state it as fact here. Check with the Tax and Customs Board before you rely on it.
Whether any localisation or export restriction applies to Estonian mapping and geospatial data
We found no rule restricting mapping or space data, checked 18 August 2026. The Land Board's map portal does not publish licensing or export limits on the page we reached. We could not get the text of the Space Data Act. Treat this as a gap in our checking, not proof that no rule exists. If you work with maps or satellite data, check before you rely on it.
The largest data protection penalty ever imposed in Estonia
We could not confirm how large Estonian data protection fines actually are. The Inspectorate publishes how many penalties it imposed each year but not the amounts. We can show 5 penalties in 2025 and 7 in 2024. The claim that Estonian penalties stay small comes from how the process works, not from published figures.
Exactly when the 24-hour cyber-incident clock starts biting for organisations that already existed on 1 January 2026
We could not confirm when the cyber incident-reporting duty starts for existing providers. The Cybersecurity Act gives them three years to bring their activities into line, but requires registration within three months. The English text does not clearly say whether incident reporting sits inside or outside that three-year window. Plan on having to report incidents now.
Estonia's data embassy in Luxembourg — its current legal basis and what it holds
We could not confirm that Estonia keeps copies of critical state data abroad under diplomatic protection. This is widely reported, and it is the opposite of a rule forcing data to stay in the country. We found no live official page describing it on the Information System Authority's site. We have left it out of the rules rather than state it from memory.
Whether Estonian insurance and securities regulation adds any storage-location duty beyond the outsourcing guidelines
We could not fully confirm the position for insurers and investment firms. We checked the Financial Supervision and Resolution Authority's published guideline lists for banking and payments. We found no rule forcing data to stay in the country. We did not find a separate guideline index for insurance or securities. The finance rule is therefore recorded at medium confidence.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.