Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
Estonia's Personal Data Protection Act (Isikuandmete kaitse seadus, IKS) of 2019 supplements the EU GDPR with national provisions. The Data Protection Inspectorate (Andmekaitse Inspektsioon) oversees enforcement. Estonia's Act includes provisions for processing of national identification codes (isikukood), processing of personal data in employment relationships, video surveillance, scientific research and statistics, and the age of digital consent (13 years). Estonia is notable for its advanced e-government and digital identity infrastructure (X-Road, e-Residency).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Chapter 1 — General Provisions
| Code | Title |
|---|---|
| 152FZ-1 | Scope of the Federal Law (Article 1) |
| 152FZ-2 | Purpose of the Federal Law (Article 2) |
| 152FZ-3 | Basic Terms (Article 3) |
| 152FZ-4 | Legislation on Personal Data (Article 4) |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| EPDPA-1 | Scope of Regulation (§1) |
| EPDPA-2 | Specifications for Application (§2) |
| EPDPA-3 | Application of Administrative Procedure Act (§3) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Chapter 2 — Specific Grounds for Processing of Personal Data
| Code | Title |
|---|---|
| EPDPA-4 | Processing for Journalistic Purposes (§4) |
| EPDPA-5 | Academic, Artistic and Literary Expression (§5) |
| EPDPA-6 | Scientific and Historical Research (§6) |
| EPDPA-7 | Archiving in Public Interest (§7) |
Chapter 3 — Other Cases of Processing Personal Data
| Code | Title |
|---|---|
| EPDPA-10 | Processing in Connection with Violations (§10) |
| EPDPA-11 | Processing in Public Places (§11) |
| EPDPA-8 | Children's Data for Information Society Services (§8) |
| EPDPA-9 | Processing After Death of Data Subject (§9) |
Chapter 4 — Processing by Law Enforcement Authorities
| Code | Title |
|---|---|
| EPDPA-12 | Application and Terms (§12–§13) |
| EPDPA-13 | Processing Principles (§14–§21) |
| EPDPA-14 | Rights of Data Subjects (§22–§28) |
| EPDPA-15 | Obligations of Controllers and Processors (§29–§39) |
| EPDPA-16 | Data Protection Specialist (§40–§42) |
| EPDPA-17 | Security Measures and Breach Notification (§43–§45) |
| EPDPA-18 | Transmission to Third Countries (§46–§50) |
Chapter 5 — State and Administrative Supervision
| Code | Title |
|---|---|
| EPDPA-19 | Supervisory Authority (§51–§55) |
| EPDPA-20 | Exercise of Supervision (§56–§61) |
Chapter 6 — Liability
| Code | Title |
|---|---|
| EPDPA-21 | Violations and Proceedings (§62–§73) |
Chapter 7 — Implementing Provisions
| Code | Title |
|---|---|
| EPDPA-22 | Register and Entry into Force (§74–§76) |
Maps to 580 other frameworks
Frequently Asked Questions
What is Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)?
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) is a compliance framework from Estonia with 7 domains and 34 controls. Estonia's Personal Data Protection Act (Isikuandmete kaitse seadus, IKS) of 2019 supplements the EU GDPR with national provisions. The Data Protection Inspectorate (Andmekaitse Inspektsioon) oversees enforcement. Estonia's Act includes provisions for processing of national identification codes (isikukood), processing of personal data in employment relationships, video surveillance, scientific research and statistics, and the age of digital consent (13 years). Estonia is notable for its advanced e-government and digital identity infrastructure (X-Road, e-Residency). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) have?
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) has 34 controls organised across 7 domains. The largest domains are Chapter 1 — General Provisions (15 controls), Chapter 4 — Processing by Law Enforcement Authorities (7 controls), Chapter 2 — Specific Grounds for Processing of Personal Data (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) map to?
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) maps to 580 other compliance frameworks. The top mapping partners are ASEAN Data Management Framework (29% coverage), Australia Consumer Data Right — Banking (CDR) (29% coverage), Barbados Data Protection Act 2019 (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) compliance?
Start your Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required