Skip to the content
Global Data RulesData governance rules, country by country

Estonia

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.

Eight questions about Estonia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Estonia's rules apply to my company?

Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Estonia?

In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.

High confidenceDepends on your industryNo — it stays putAllowlist

What do I need in place before data leaves Estonia?

For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesApproved code of conductCertification schemeGovernment sign-off needed

Who enforces the rules in Estonia, and what can they do?

The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.

High confidenceActive

How long do I have to keep the data?

Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Estonia?

Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.

High confidenceGet a parent's consent for childrenAppoint a data protection officerCriminal liabilityClaims by individuals

What is changing soon in Estonia?

One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.

Medium confidencePartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    1 rule here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

Isikuandmete kaitse üldmäärus — Regulation (EU) 2016/679 (General Data Protection Regulation)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rules apply directly in Estonia. They do not require data to stay in Europe; they set conditions on sending it out. A companion European regulation bans member states from imposing localisation on non-personal data except on public-security grounds.

In force since 25 May 2018

Enforced by Estonian Data Protection Inspectorate

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

National rules1 rule

Isikuandmete kaitse seadus (IKS)

Act of parliament · Personal Data Protection Act, passed 12 December 2018; current consolidated text RT I, 06.03.2026, 2

In forceYes — store it anywhere

Estonia's national privacy act adds detail on top of the European rules rather than replacing them. It imposes no data localisation. Its distinctive features are a digital consent age of 13, protection of a dead person's data for 10 or 20 years, strict pre-transfer pseudonymisation for research, and penalties that run through a minor-criminal process rather than an administrative one.

In force since 15 January 2019

Enforced by Estonian Data Protection Inspectorate

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

High confidence

Industry rules7 rules

Elektroonilise side seadus (ESS), § 111-1

Act of parliament · Electronic Communications Act, section 111-1; retention duty in force since 1 January 2008, internet data from 15 March 2009; current consolidated text in force 17 August 2026 · Telecoms

In forceNo — it stays put

Phone and internet companies must keep a year of connection and location records, and those records may not leave the European Union. Three categories tied to police and court access must be held physically in Estonia. Operators bear the cost themselves — the law says the expense is not reimbursed.

In force since 1 January 2008But only enforceable from 15 March 2009

Enforced by Consumer Protection and Technical Regulatory Authority

Transfer model: Not allowed

High confidence

Hasartmänguseadus (HasMS)

Act of parliament · Gambling Act, sections 23, 30, 55 and 57; current consolidated text in force from 1 January 2026 · Online gaming

In forceYes, with paperwork

An online gambling operator serving Estonia can only place its game server in an approved set of countries, and must give the tax authority a live data connection plus unrestricted law-enforcement access to player identity and session records. The allowlist is real and populated, and the permit can be refused on server location alone.

In force since 1 January 2009

Enforced by Estonian Tax and Customs Board

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Küberturvalisuse seadus (KüTS), as amended by RT I, 30.12.2025, 4

Act of parliament · Cybersecurity Act, sections 3-1, 4, 4-1, 6-1, 7, 8, 18-2 and 28-1; amendment transposing Directive (EU) 2022/2555 published 30 December 2025

Partly in forceYes — store it anywhere

Estonia transposed the European Union's second cybersecurity directive by an amendment in force on 1 January 2026 — over a year late. Registration was due by 1 April 2026, incident reporting runs on a 24-hour, 72-hour and one-month clock, and full compliance with the security requirements is not due until 1 January 2029. There is no localisation duty.

In force since 1 January 2026But only enforceable from 1 January 2029

Enforced by Estonian Information System Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Andmekaitse Inspektsioon

    Personal data protection and freedom of information across all sectors

    Fully operational. Director general Pille Lehis, in post since 19 August 2019 and confirmed for a second term on 16 May 2024; 34 service positions. Published statistics to 22 April 2026 show 1,568 complaints, 13 precepts, 6 concluded misdemeanour cases and 5 penalties in 2025. Four precepts published in 2026 up to 17 June 2026. Penalties are small because they run through misdemeanour procedure rather than administrative fining.

  • Riigi Infosüsteemi Amet (RIA)

    Cybersecurity Act, state information system and data exchange layer, security duties under the Electronic Communications Act and the Emergency Act; hosts CERT-EE

    Actively issuing enforcement orders against schools, municipalities, health providers, utilities and state agencies; most recent published decision 5 June 2026. Became the competent authority under the transposed European cybersecurity directive on 1 January 2026.

  • Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA)

    Telecoms and electronic communications, including the data preservation duty and interception log supervision

  • Maksu- ja Tolliamet (MTA)

    Gambling licensing and supervision, including server location and the live reporting link; tax record keeping

    Runs the electronic gambling reporting system and publishes a list of legal operators and a list of blocked gambling websites.

  • Finantsinspektsioon

    Banks, payment and e-money institutions, insurers, investment firms; outsourcing and cloud guidelines

  • Rahapesu Andmebüroo

    Anti-money-laundering supervision and the five-year record retention duty

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • What law changes Estonian data rules on 1 October 2026

    Riigi Teataja marks the current consolidated texts of the Personal Data Protection Act, Public Information Act, Cybersecurity Act, Electronic Communications Act, Emergency Act, Health Services Organisation Act, Health Insurance Act and Social Welfare Act as valid only to 30 September 2026, which proves an amendment commences on 1 October 2026. The gazette's search interface is a JavaScript application with no reachable search endpoint, so we could not identify the amending act itself. Treat the date as certain and the content as unknown.

  • Whether the one-year blanket telecoms retention duty in section 111-1 of the Electronic Communications Act is still applied in practice

    The text is printed unchanged in the consolidated version in force on 18 August 2026, so a plain reading says it binds. But blanket retention of this design has been repeatedly held incompatible with European Union law, and the Estonian Supreme Court's own reference produced the 2021 Prokuratuur judgment restricting who may authorise access to the data. We could not locate an Estonian court ruling or amendment that removes the retention duty itself, nor confirm current enforcement practice.

  • Estonian minimum retention periods for accounting and tax records

    Widely reported as seven years under the Accounting Act and the Taxation Act, but we could not retrieve either act's text from a government source during this run because the gazette has no machine-readable search and no ministry page we reached links to them. Not asserted in this record.

  • Whether any localisation or export restriction applies to Estonian mapping and geospatial data

    No rule found, checked 18 August 2026. The Land Board's geoportal does not publish licensing or export restrictions on the page we reached, and we could not retrieve the Space Data Act text. Confidence medium, stated as a negative finding rather than a fact.

  • The largest data protection penalty ever imposed in Estonia

    The Inspectorate publishes counts of penalties by year but not amounts. We can evidence that 5 penalties were imposed in 2025 and 7 in 2024, but not their size, so the claim that Estonian penalties stay small is an inference from the misdemeanour procedure, not a verified figure.

  • Exactly when the 24-hour cyber-incident clock starts biting for organisations that already existed on 1 January 2026

    Section 28-1 of the Cybersecurity Act gives existing service providers three years to bring their activities into conformity, while carving out the registration duty at three months. Whether the incident-notification duty falls inside or outside that three-year window is not stated unambiguously in the English text. Plan on the notification duty applying now.

  • Estonia's data embassy in Luxembourg — its current legal basis and what it holds

    Estonia is known for hosting copies of critical state data abroad under diplomatic immunity, which is the reverse of a localisation rule and would be a notable feature of this record. We could not locate a live official page describing it on the Information System Authority's site during this run, so it is deliberately omitted from the rules rather than asserted from memory.

  • Whether Estonian insurance and securities regulation adds any storage-location duty beyond the outsourcing guidelines

    We checked the Financial Supervision and Resolution Authority's published guideline lists for banking and payments and found no localisation rule, but did not retrieve a dedicated insurance or securities guideline index. The finance rule is therefore recorded at medium confidence.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.