{
 "jurisdiction_id": "EE",
 "jurisdiction": "Estonia",
 "url": "https://dataprotection.gi/jurisdictions/estonia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 37,
  "sub_modules": 57,
  "source_register": 21
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned EU Member State regime with an operational, EDPB-integrated supervisory authority and a settled national implementing act in force since 2019.",
   "claims": [
    {
     "statement": "The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), based at Tatari 39, 10134 Tallinn, is Estonia's EDPB-member supervisory authority, currently headed by Ms Pille Lehis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data protection in Estonia is primarily governed by the GDPR, implemented into Estonian law via the Personal Data Protection Act (PDPA), which entered into force on 15 January 2019.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/estonia-privacy-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR rules applicable in Estonia, non-EU-established businesses must apply the same rules when they offer goods or services, or monitor the behaviour, of individuals in the EU.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/ET/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI adopted (per EDPB Opinion 6/2018) a national list of processing operations subject to the mandatory DPIA requirement under GDPR Article 35(4), in place of a general controller-registration/filing regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/consistency-findings/register-decisions/2019/estonia-sas-list-kind-processing_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category rules are GDPR-aligned and actively enforced; only prospective, non-binding EU-level reform (Digital Omnibus) is pending.",
   "claims": [
    {
     "statement": "In a 2022 own-initiative proceeding, the Estonian DPA found that a ride-hailing controller lacked a valid legal basis for processing rider ratings and disagreed that Article 6(1)(b) GDPR (contractual necessity) applied to that processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AKI / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/ee-sa-05-25-decisionpublic_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI held that another person's self-declared justification for viewing a prescription is not equivalent to the voluntary consent of the prescription holder, because the controller cannot verify the purpose or voluntariness of that consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/estonian-data-protection-inspectorate-obliged-e-pharmacies-immediately_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS have welcomed the Digital Omnibus proposal's aim to introduce a specific, conditional derogation to the prohibition on processing special-category data, covering incidental/residual processing in AI system development and operation, while recommending narrower scope and lifecycle safeguards.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS strongly urged co-legislators not to adopt the Commission's proposed narrowing of the GDPR Art 4(1) personal-data definition (relative identifiability for pseudonymised data), and a leaked February 2026 Council compromise text removed that proposed change entirely.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/eu-member-states-leaked-digital-omnibus-compromise-proposal-eliminates-revised-gdpr-definition-of-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "GDPR rights framework in force with clear escalation path to AKI/courts; no Estonia-specific restriction identified.",
   "claims": [
    {
     "statement": "Where an access/rectification/erasure request is submitted in English to an Estonian controller, the controller responds to the applicant in Estonian.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=2026-04%2Fcsc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "If the requester is not satisfied with a controller's reply, or receives no reply within 30 days of sending the request, the requester has the right to lodge a free complaint with AKI or an administrative court.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=2026-04%2Fcsc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core GDPR controller/processor obligations are enforced and operative; only prospective Digital Omnibus amendments to ROPA and breach thresholds remain unresolved.",
   "claims": [
    {
     "statement": "AKI's national list of processing operations requiring a DPIA under GDPR Art 35(4) was adopted following EDPB Opinion 6/2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/consistency-findings/register-decisions/2019/estonia-sas-list-kind-processing_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI selected 19 public- and private-sector organisations (municipalities, ministries, banks, hospitals) to assess, via questionnaires and potential formal investigation, whether their DPOs meet GDPR Articles 37-39 conditions and have adequate resources, as part of the EDPB's 2023 Coordinated Enforcement Framework action.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/estonia-participates-pan-european-role-public-and-private-data-protection-officers-joint_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU Digital Omnibus proposal would modify GDPR Art 30(5) to extend the ROPA-keeping derogation from organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk; this is a pending proposal, not yet in force.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/targeted-modifications-gdpr-edpb-edps-welcome-simplification-record-keeping_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI issued a precept with a one-day compliance deadline and a 100,000 EUR penalty payment to three e-pharmacy chains for a security/access-control failure allowing viewing of another person's current prescriptions via personal identification codes without consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/estonian-data-protection-inspectorate-obliged-e-pharmacies-immediately_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS support the Digital Omnibus proposal's increase of the risk threshold triggering mandatory breach notification to the competent DPA and the extension of the notification deadline, assessing this would meaningfully reduce administrative burden without affecting individuals' protection.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI's self-initiated monitoring of a credit-information portal (taust.ee) identified privacy-policy shortcomings and directed the controller to address data-minimisation and retention principles and the accuracy of processed non-payment data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/estonian-sa-krediidiregister-ou-legal-basis-disclosure-non-payment-data_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are the standard EU GDPR toolkit with no identified Estonian derogation; localisation-specific findings are absent and flagged rather than assumed.",
   "claims": [
    {
     "statement": "The GDPR offers a range of tools for transferring data outside the EU, including European Commission adequacy decisions, pre-approved standard contractual clauses, binding corporate rules, codes of conduct, and certification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/ET/TXT/?uri=celex:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission's renewed EU-GDPR adequacy decision for the UK applies to transfers from all EEA countries, including Estonia, and lasts until 27 December 2031.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the CJEU's Schrems II ruling invalidating the EU-U.S. Privacy Shield, the EDPB issued FAQs and Recommendations setting out a six-step process for supplementary measures, applicable to Estonian data exporters using SCCs to non-adequate third countries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-06/edpb_aar_2020_final_27.05.21.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays exist mainly through case law/enforcement rather than distinct statutes; a live CJEU reference on AML/GDPR interplay introduces near-term legal uncertainty for the financial sector overlay.",
   "claims": [
    {
     "statement": "Estonia's Supreme Court (Riigikohus) lodged a preliminary reference (Case C-222/25) with the CJEU on 21 March 2025 concerning a dispute between an individual and the Estonian Financial Intelligence Unit (Rahapesu Andmebüroo), with the Estonian DPA (Andmekaitse Inspektsioon) named as an involved party.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / Official Journal",
     "source_url": "https://eur-lex.europa.eu/eli/C/2025/2847/oj/eng",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI initiated an own-initiative procedure under clause 56(3)(8) of the PDPA against three e-pharmacy chains for unlawfully displaying another person's valid prescriptions based on personal identification codes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/estonian-data-protection-inspectorate-obliged-e-pharmacies-immediately_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU Digital Omnibus proposal, formally consulted with the EDPB/EDPS from 25 November 2025, includes targeted amendments concerning the GDPR, the EUDPR, and the ePrivacy Directive.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI found that a private individual's Facebook groups disclosing other people's debt data to 4,600-14,800 unidentified members lacked a legitimate-interest or journalistic-purpose basis and issued a precept with a 5,000 EUR penalty payment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/estonian-sa-private-person-legal-bases-disclosure-data-unidentified-persons_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI issued a precept with a 10,000 EUR penalty payment per unfulfilled point against Krediidiregister OÜ over legal-basis and privacy-policy shortcomings in disclosing non-payment data of legal representatives.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/estonian-sa-krediidiregister-ou-legal-basis-disclosure-non-payment-data_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/ePrivacy rules are GDPR/ePrivacy-aligned and in force; several US-style adtech constructs (dark patterns codified separately, GPC, clean rooms) have no confirmed Estonian equivalent, driving amber/red sub-module ratings and explicit gaps.",
   "claims": [
    {
     "statement": "Article 5(3) of the ePrivacy Directive requires users' prior consent for storing information, or gaining access to information already stored, in their terminal equipment, as clarified by EDPB Guidelines 2/2023 on the technical scope of Art 5(3), applicable directly in Estonia as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_letter_20260626_spyware_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Baseline Art 22/ADM and surveillance carve-out rules are settled GDPR/LED law, but the AI Act's implementation timeline and scope are actively being renegotiated via the pending Digital Omnibus on AI.",
   "claims": [
    {
     "statement": "AKI issued a formal injunction on 17 February 2022 requiring a ride-hailing data controller to suspend processing of rider-rating data until compliance measures were implemented and to delete related personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AKI / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/ee-sa-05-25-decisionpublic_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI criticised the ride-hailing controller's compliance with the fairness/transparency principle (GDPR Art 5(1)(a)) and Articles 12-14, finding the obligation to inform data subjects about how their rating data was collected, used, stored and shared had not been met.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AKI / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/ee-sa-05-25-decisionpublic_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the pending AI Act simplification package, entry into application of high-risk AI processing obligations (originally due August 2026) faces an extension capped at December 2027, pending confirmation of implementation standards and support tools.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-proposes-significant-reforms-to-gdpr-ai-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB has stated that investigation and enforcement of data-protection rules regarding alleged private-entity spyware use falls under GDPR competence, while processing by competent authorities for criminal-law purposes falls under the Law Enforcement Directive, and national-security processing falls outside the scope of EU law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_letter_20260626_spyware_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "EU baseline (Art 8 GDPR) is confirmed, but the Estonia-specific national age-of-consent figure and minor/vulnerable-group specifics could not be confirmed from available sources in this pass; escalation recommended.",
   "claims": [
    {
     "statement": "Under GDPR Article 8(1), processing of a child's personal data in relation to information-society services is lawful where the child is at least 16 years old, but Member States may set a lower age by law provided it is not below 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/FI/TXT/?uri=uriserv%3AOJ.L_.2016.119.01.0001.01.ENG",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a child is below the applicable age threshold under Article 8(1) GDPR, processing is lawful only if consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify this taking into account available technology.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/FI/TXT/?uri=uriserv%3AOJ.L_.2016.119.01.0001.01.ENG",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/estonia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "AKI has active, EDPB-integrated enforcement powers and a functioning complaint/court escalation path, but its fine mechanism structurally departs from the direct-administrative-fine model used elsewhere in the EU (GDPR Recital 151 carve-out), and the surrounding EU legislative framework (Digital Omnibus) is in active flux.",
   "claims": [
    {
     "statement": "In Estonia, administrative fines are not directly applicable according to GDPR Recital 151; when a controller demonstrates compliance with AKI's guidance and takes corrective action, AKI may close proceedings with a reprimand rather than an administrative fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AKI / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-08/ee-sa-05-25-decisionpublic_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI issued a precept with a 100,000 EUR penalty payment and a one-day compliance deadline to three pharmacy chains in a 2020 e-pharmacy prescription-access case.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/estonian-data-protection-inspectorate-obliged-e-pharmacies-immediately_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AKI issued a precept with a 5,000 EUR penalty payment against a Facebook-group administrator for unlawfully disclosing individuals' debt data to thousands of unidentified group members.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / AKI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/estonian-sa-private-person-legal-bases-disclosure-data-unidentified-persons_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data subject dissatisfied with, or receiving no reply to, a rights request within 30 days may lodge a free complaint with AKI or bring proceedings directly before an administrative court.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=2026-04%2Fcsc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS adopted a Joint Opinion on the Digital Omnibus Regulation proposal, strongly urging co-legislators not to adopt the Commission's proposed changes to the GDPR's definition of personal data, while supporting simplification of breach-notification thresholds and deadlines.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A leaked 20 February 2026 Council compromise text on the Digital Omnibus, circulated by the Cypriot presidency, eliminated the Commission's proposed new definition of 'personal data' under the GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/eu-member-states-leaked-digital-omnibus-compromise-proposal-eliminates-revised-gdpr-definition-of-personal-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}