Law / Estonia

Estonia

European Union law applies in Estonia Estonia is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Estonia, described on this page below, applies here too.

14 of 18 named instruments researched to a stage, across five of the six areas of law we track: 14 in force. As of 15 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 2 instruments (2 in force) ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 6 instruments (6 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 3 instruments (3 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (96 words)

Estonia's private-sector regime is the General Data Protection Regulation (GDPR) plus the Personal Data Protection Act (Isikuandmete kaitse seadus, RT I, 04.01.2019, 11), enforced by the Estonian Data Protection Inspectorate (AKI). Estonia does not recognize an ordinary administrative fine; AKI pursues a GDPR fine through misdemeanor proceedings instead, per secondary commentary not independently confirmed against primary legislative text.

The Act's own consolidated text is not machine-extractable, because the official gazette serves a client-rendered application shell, so the Act's specific derogation provisions are not restated here beyond the GDPR baseline. As at 24 August 2026; later amendment is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Estonia

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 15 January 2019. Binds public and private bodies.

What this law does

A controller must notify the Estonian Data Protection Inspectorate (AKI) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Estonia-specific narrowing of this timeline is independently confirmed.

What it requires

Comprehensive regime

Personal Data Protection Act (Isikuandmete kaitse seadus)

Isikuandmete kaitse seadus, RT I, 04.01.2019, 11, adopted 12 December 2018Riigi Teataja official gazette listing

In force since 15 January 2019. Binds public and private bodies.

What this law does

The Personal Data Protection Act (PDPA) gives the General Data Protection Regulation (GDPR) domestic effect in Estonia and is enforced by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI). Estonia's official gazette serves the Act's own text as a client-rendered page whose text is not machine-extractable, so the Act's specific derogation sections are not independently confirmed and are not restated here; the regime is instead described at the GDPR-baseline level.

Distinctively, Estonia's Information System Authority (RIA) operates a citizen-facing Data Tracker (Andmejalgija) that lets a person see, in one place, which public-sector systems connected via X-Road have processed their data, an operational implementation of the GDPR Article 15 access right rather than a separate statutory right.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Estonia

Regulation (EU) 2016/679, Arts. 44-50Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 15 January 2019. Binds public and private bodies.

What this law does

Transferring personal data of a person in Estonia outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Secondary commentary reports Estonia imposes no additional derogation beyond this General Data Protection Regulation (GDPR) Chapter V baseline; not independently confirmed against the Act's own text.

What it requires

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Estonia

Regulation (EU) 2016/679, Arts. 15-22; Isikuandmete kaitse seadusOfficial Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 15 January 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect, applied in Estonia through the Personal Data Protection Act.

The public sector's access right is distinctively implemented as unified infrastructure through RIA's Data Tracker service, letting a citizen see which public-sector systems have processed their data in one place rather than requesting this separately from each controller. No Estonia-specific derogation narrowing these rights is independently confirmed.

What it requires

Enforcement supervision

GDPR Articles 82-83 and AKI Enforcement in Estonia

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 15 January 2019. Binds public and private bodies.

What this law does

The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.

Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; Isikuandmete kaitse seadus Sections 66 to 70 and 73 instead make AKI itself the extrajudicial adjudicator of a General Data Protection Regulation (GDPR) Article 83 fine as an Estonian misdemeanor (vaartegu), applying the GDPR's own EUR 20,000,000 or 4 percent ceiling directly; a 2023 amendment reported by secondary commentary to have extended the limitation period is not independently confirmed against primary legislative text.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Estonia

Regulation (EU) 2016/679, Art. 9Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 15 January 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Estonian statutory enumeration or illustrative list narrowing or expanding this definition was read, and none is asserted; the Personal Data Protection Act's own text is not machine-extractable from the official gazette, and the Estonian Data Protection Inspectorate's thematic-inspection page serves no usable content. No AKI guidance or enforcement decision naming facial recognition or voice data specifically was located.

What it requires

Scraping law3 instruments, 3 in force

Research summary (260 words)

Estonia's computer-misuse offense, Karistusseadustik (Penal Code) Section 217, requires circumventing a protective measure before an access is illegal, so crawling a public, unauthenticated page carries no exposure under this section alone. Sections 206 and 207 separately criminalize altering, deleting or blocking computer data and hindering the functioning of a computer system, neither of which is confined to circumvention and both of which could reach an aggressive or disruptive scraper.

The Autoriõiguse seadus (Copyright Act) gives a database maker a sui generis right against extraction or re-utilisation of a substantial part of a database at Sections 75-1 to 75-7, transposing Directive 96/9/EC, running for fifteen years from completion with exceptions for private non-electronic use, teaching and scientific research.

The Act's own text-and-data-mining exception, added in 2022, is described in this jurisdiction's aggregation-topic document rather than restated here, since it is the aggregation profile's tdm_optout family that governs it; the same provision reaches crawling and training.

No Estonian statute or reported decision was located establishing whether a browsewrap or clickwrap restriction against scraping is enforceable as a matter of contract law; ordinary contract-formation rules under the Volaoigusseadus (Law of Obligations Act) are not independently confirmed here, so that dimension is unsettled rather than governed by a specific regime.

Personal data an operator scrapes from a public page is already reached by General Data Protection Regulation (GDPR) and the Isikuandmete kaitse seadus, the subject of this jurisdiction's separately landed privacy-topic document; Estonia records no publicly-available-data exemption from the general lawful-basis requirement. No Estonia-specific robots.txt legal-weight statute or AI-training-specific crawling rule beyond the copyright text-and-data-mining opt-out was located.

Computer misuse

Karistusseadustik (Penal Code) Section 217, Illegal Obtaining of Access to a Computer System

Karistusseadustik, RT I, 12.07.2014, 1, Section 217Riigi Teataja, official English translation of the consolidated Karistusseadustik (Penal Code)

In force since 1 January 2015. Binds public and private bodies.

What this law does

Illegal obtaining of access to a computer system by elimination or avoidance of a means of protection is punishable by a pecuniary punishment or up to three years' imprisonment. The offense escalates to up to five years' imprisonment where the act causes significant damage, reaches a computer system holding a state secret or classified information, or reaches a computer system of a vital sector.

Because the base offense requires eliminating or avoiding an established means of protection, accessing a page that carries no such protection, the ordinary case of public-web crawling, does not fall within Section 217 on the text of the section alone.

What it requires

Karistusseadustik (Penal Code) Sections 206 and 207, Interference with Computer Data and Hindering of Functioning of Computer Systems

Karistusseadustik, RT I, 12.07.2014, 1, Sections 206 and 207Riigi Teataja, official English translation of the consolidated Karistusseadustik (Penal Code)

In force since 1 January 2015. Binds public and private bodies.

What this law does

Section 206 punishes illegal alteration, deletion, damaging or blocking of data in a computer system with a pecuniary punishment or up to three years' imprisonment, rising to five years where the act is committed against numerous systems, by a group, against a vital-sector system, or causes significant damage.

Section 207 punishes illegal interference with or hindering of the functioning of a computer system by uploading, transmitting, deleting, damaging, altering or blocking data on the same three-year and five-year tiers. Unlike Section 217, neither offense is limited to access obtained by circumventing a protective measure, so a scraper that overloads, disrupts or corrupts a target system can fall within these sections even against a page with no access controls.

What it requires

Database right

Autoriõiguse seadus (Copyright Act) Chapter VIII-1, Sui Generis Right of a Maker of a Database

Autoriõiguse seadus, RT I 1999, 97, 859, Sections 75-1 to 75-7, as amended by RT I 2004, 71, 500Riigi Teataja, official English translation of the consolidated Autoriõiguse seadus (Copyright Act)

In force since 6 January 2000. Binds public and private bodies.

What this law does

A maker of a database who has made a substantial investment, evaluated qualitatively or quantitatively, in collecting, obtaining, verifying, arranging or presenting its contents may prohibit extraction or re-utilisation of the whole or a substantial part of that database, per Section 75-3 and 75-4.

The right runs for fifteen years from the first of January of the year following completion of the database, restarting if the database is made available to the public before that term expires, per Section 75-7.

A lawful user of a database made available to the public may extract or re-utilise a substantial part without authorization or payment for private non-electronic use, for teaching or scientific research to the extent justified by the non-commercial purpose and with the source indicated, or for public security or an administrative or judicial procedure, per Section 75-6.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (1,218 words)

Estonia transposed NIS2 by amending its existing Küberturvalisuse seadus (Cybersecurity Act, KüTS), first adopted 9 May 2018 (RT I, 22.05.2018, 1, in force 23 May 2018, with some provisions phased in on 1 January 2020 and 1 January 2022), rather than repealing it and enacting a new standalone law.

The amending Act, Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (küberturvalisuse 2. direktiivi ülevõtmine) (Act Amending the Cybersecurity Act and Other Acts, Transposition of the Second Cybersecurity Directive), was adopted by the Riigikogu on 10 December 2025, proclaimed by the President of the Republic on 18 December 2025 (decision no. 640), published as RT I, 30.12.2025, 4, and entered into force on 1 January 2026 under its own Section 11, so the current consolidated KüTS reads as amended from that date; Riigi Teataja's own consolidated-text header records this wording as valid from 1 January 2026 to 30 September 2026, meaning a further amendment is scheduled to take effect immediately after, whose content is not read here.

Section 3 defines the entity classes: an 'ülioluline üksus' (essential entity) and an 'oluline üksus' (important entity), drawn from sector, size and criticality thresholds that mirror the NIS2 Annex I and Annex II lists, and expressly include a central government public administration entity and a local government public administration entity among essential entities, so the Act reaches both public and private duty-bearers.

Section 2(2) defines 'digitaalse teenuse osutaja' (digital service provider) as an umbrella covering a domain name system service provider, a top-level domain name registry operator, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, a managed security service provider, an operator of an online marketplace, and a provider of an online search engine or social media platform.

Section 7 requires a service provider to apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, built on its own risk analysis, to manage risk to its systems, prevent or minimise a cyber incident's impact, and prevent, detect or resolve a cyber incident, taking into account its needs and security requirements, current European and international standards, implementation cost, proportionality to its risk exposure and to the likelihood and severity of an incident, and a systemic approach protecting both the systems and their physical environment; a service provider that delegates system management or hosting to another person remains responsible for that person applying the measures.

The specific technical, methodological and, where relevant, sector-specific content of those measures, including the Estonian Information Security Standard (Eesti infoturbestandard, E-ITS), is left to a Government or ministerial regulation issued under Section 7(5) to (7), or to a European Commission implementing act under Directive (EU) 2022/2555 Article 21(5) where one applies; that regulation's own content is not read here.

Section 6-1, also added by the 2025 amendment, requires a service provider to designate at least one management board member (or, for a single-member board, that member, or the equivalent office-holder for a provider with no board) who approves the security measures, monitors their implementation, is accountable for that duty, and completes regular training to understand and assess cyber risk.

Section 8 sets a graduated notification clock to the Riigi Infosüsteemi Amet (RIA, the Estonian Information System Authority): an initial report without delay and no later than 24 hours after becoming aware of a cyber incident with, or reasonably expected to have, a significant effect on system security or service continuity; an incident report no later than 72 hours after becoming aware of a significant-impact incident, updating the initial report (a qualified trust service provider instead reports in a single 24-hour stage); an interim report on RIA's request; and a final report within one month of the incident report, treated as interim and followed by a fresh final report within one month of resolution if the incident is still unresolved.

Section 8(2) defines 'significant effect' by six alternative conditions (a risk-analysis severity rating of at least severe, exceeding the maximum permitted service outage, disrupting another provider's service continuity, requiring extraordinary measures from the risk analysis or continuity documentation, causing or risking significant damage, or being significant under a Commission implementing act on Article 23(11)), and Section 8(3) makes an incident always significant if it also disrupts the service in at least one other EU member state; Section 8(5) and (6) require notifying affected persons or the public where relevant, and let RIA itself inform the public, after consulting the provider, or require the provider to do so, where public awareness serves prevention, resolution or the public interest.

Section 8-1 lets a service provider, or any other person, voluntarily notify RIA of a cyber incident, vulnerability or threat below the mandatory threshold, including a vulnerability report submitted anonymously.

Section 5(3) designates RIA as the competent authority and single point of contact under Directive (EU) 2022/2555 Article 8, the authority for large-scale incidents and crises under Article 9, the national CSIRT under Article 10, the coordinated-vulnerability-disclosure coordinator under Article 12, and Estonia's participant in the CSIRTs network under Article 15; Section 5(4) gives Estonia's security authority (julgeolekuasutus) the Article 8 competent-authority role within the scope set out in Section 14, consistent with Section 1(2)'s exclusion of state-secret and classified-foreign-information systems and of systems the Ministry of Defence needs for international military cooperation and national military defence preparation.

Sections 18-2 and 18-3, both introduced by the 2025 amendment, make it a 'väärtegu' (a misdemeanour under Estonian penal-procedure law, prosecuted extrajudicially rather than a purely administrative fine) for an essential entity to violate the Section 7 or Section 8 duties described above, punishable for a legal person by a fine of up to EUR 10,000,000 or up to 2 percent of the entity's total worldwide annual turnover for the preceding financial year, whichever is greater, and for an important entity, punishable by a fine of up to EUR 7,000,000 or up to 1.4 percent of that turnover, whichever is greater; Section 19(1) names RIA as the extrajudicial adjudicator for these misdemeanours, Section 19(2) applies the Isikuandmete kaitse seaduse (Personal Data Protection Act) misdemeanour-procedure rules where a violation also involves personal-data-processing requirements, filed separately in the privacy topic together with Estonia's General Data Protection Regulation (GDPR) Articles 33-34 breach-notification document, and Section 19(4) sets a three-year limitation period.

RIA's own 2 January 2026 announcement states that from 2026 the number of Estonian undertakings subject to mandatory cybersecurity requirements grew by about 3,000, to roughly 6,500, newly reaching sectors such as airlines, rail, electricity, district heating, ports, credit institutions, cloud computing providers and hospitals, alongside size-qualifying food-processing, postal and waste-management undertakings; subjects get a three-year transition period to align their activities and must report their operational data to RIA within three months, except a vital-service provider under the Hädaolukorra seadus (Emergency Act), which instead follows a five-year deadline counted from its designation date.

No instrument reviewed here imposes a Estonia-specific product-security or market-placement duty on a manufacturer of a connected device independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.

No general, sector-agnostic reasonable-security or information-security-programme statute was found; the closest general duty is GDPR Article 32's security-of-processing obligation, which sits in the privacy topic, as does Estonia's GDPR Articles 33-34 breach-notification document already in the corpus.

Sector security regimes

Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 6-1 and 7Consolidated text

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Section 7 requires an essential or important entity to apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, based on its own risk analysis, to manage the risks to the system it uses in its activities or to provide its service, to prevent or minimise a cyber incident's impact on the recipients of its service and on other services, and to prevent, detect or resolve a cyber incident.

It must account for its own needs and security requirements, current European and international standards where relevant, the cost of the measures, their proportionality to its risk exposure and to the likelihood and severity of an incident including its societal and economic impact, and a systemic, comprehensive approach protecting both the systems and their physical environment.

A service provider that delegates system management to, or hosts its system with, another person remains responsible for ensuring that person applies the security measures.

The specific technical, methodological and sector-specific content of these measures, including the Estonian Information Security Standard (Eesti infoturbestandard, E-ITS), is set by a Government or ministerial regulation issued under Section 7, subsections 5 to 7, or by a European Commission implementing act under Directive (EU) 2022/2555 Article 21(5) where one applies to the service; that regulation's own content is not read here.

Section 6-1, also added by the 2025 amendment, requires a service provider to designate at least one management board member, or for a single-member board that member, or the equivalent office-holder for a provider with no board, who approves the security measures, monitors their implementation, is accountable for that duty, and completes regular training to understand and assess cyber risk.

Section 2(2) defines 'digitaalse teenuse osutaja' (digital service provider), an entity class reached by this duty, as an umbrella covering a domain name system service provider, a top-level domain name registry operator, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, a managed security service provider, an operator of an online marketplace, and a provider of an online search engine or social media platform.

Section 3(2) names a central government public administration entity as an essential entity. Section 3(2) also names a local government public administration entity as an essential entity, so this duty reaches both public and private duty-bearers. Section 1(2) excludes state-secret and classified-foreign-information systems from the Act. Section 1(2) also excludes systems the Ministry of Defence needs for international military cooperation and national military defence preparation.

Estonia's security authority (julgeolekuasutus) holds the competent-authority role, instead of RIA, for an entity within the scope set out in Section 14. Both Section 7 and Section 6-1 entered into force on 1 January 2026 as part of Estonia's NIS2 transposition, amending the predecessor wording of Section 7 that had been in force since the Act's original 2018 enactment. A subject is given a three-year transition period to bring its activities into line with these requirements.

A vital-service provider under the Emergency Act instead follows a five-year deadline counted from its designation date. RIA's own account of the amendment states that from 2026 the number of Estonian undertakings subject to these requirements grew by about 3,000, to roughly 6,500.

What it requires

Vulnerability and incident reporting

Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident

Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1Consolidated text

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Section 8 requires an essential or important entity, other than a security authority, to submit an initial report to RIA (Riigi Infosüsteemi Amet, the Estonian Information System Authority) without delay and no later than 24 hours after becoming aware of a cyber incident with a significant effect on system security or service continuity, or one whose significant effect is not obvious but can reasonably be expected.

Section 8(2) defines 'significant effect' by six alternative conditions: the incident rates at least severe under the entity's own Section 7 risk analysis; it prevents continuing the service beyond the maximum permitted outage in a service-level agreement or continuity requirement; it disrupts another service provider's continuity; resolving it requires extraordinary measures identified in the risk analysis or continuity documentation; it has caused or risks significant damage to the entity, another provider or the service's users; or it is significant under a European Commission implementing act adopted under Directive (EU) 2022/2555 Article 23(11).

Section 8(3) makes an incident always significant where it also disrupts the service in at least one other EU member state. Section 8, subsection 4-1, requires an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, except a qualified trust service provider, which instead reports within 24 hours in a single stage under Section 8, subsection 4-2. Section 8, subsection 4-3, requires an interim report on RIA's request.

Section 8(7) requires a final report within one month of the incident report, treated as interim and followed by a further final report within one month of resolution if the incident remains unresolved at that point. Section 8(5) requires the entity to notify, within a reasonable time, a person whom the significant incident or a significant cyber threat may affect, or the public where affected persons cannot be individually notified.

Section 8(6) lets RIA itself inform the public after consulting the entity, or require the entity to, where public awareness serves prevention, resolution of the incident, or the public interest generally. Section 8-1 lets a service provider, or any other person, voluntarily notify RIA of a cyber incident, security vulnerability or cyber threat below the mandatory threshold, including a vulnerability report submitted anonymously, processed under the same Sections 8 and 12 procedure.

Section 5(3) designates RIA as the competent authority and single point of contact under Directive (EU) 2022/2555 Article 8, the authority for large-scale incidents and crises under Article 9, the national CSIRT under Article 10, the coordinated-vulnerability-disclosure coordinator under Article 12, and Estonia's participant in the CSIRTs network under Article 15. All these duties entered into force on 1 January 2026 as part of Estonia's NIS2 transposition.

What it requires

Age gating law1 instrument, 1 in force

Research summary (210 words)

Estonia's Meediateenuste seadus (Media Services Act) Section 19-1, transposing the revised Audiovisual Media Services Directive's Article 28b, requires a video-sharing platform operator to provide, in its terms of service, that the platform may not carry programmes, user-generated videos or commercial communications that incite hatred, violence or discrimination, incite the commission of an offense, or depict child pornography, and to attach a warning and an on-screen symbol to content that may impair a minor's physical, mental or moral development.

Where the operator is aware of such content, it must remove or restrict access to it, and for content merely harmful to minors it must add the warning and symbol or ensure the content is accessible only through personal identification codes or another appropriate technical means that makes it inaccessible to a minor in the ordinary case. A user may complain to the Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA) if these duties are not respected.

The minimum age at which a minor may independently consent to an information-society service such as a social-media account is a privacy-topic finding, already covered in this jurisdiction's separately landed privacy document, and is not restated here. No Estonian adult-content age-verification statute, social-media minimum-registration-age statute, or app-store age-verification statute distinct from the video-sharing-platform duty above was located.

Age-appropriate design code

Meediateenuste seadus (Media Services Act) Section 19-1, Protection of Minors on a Video-Sharing Platform

Meediateenuste seadus § 19-1, RT I, 27.02.2022, 1Riigi Teataja, consolidated text of the Meediateenuste seadus

In force since 9 March 2022. Binds private bodies.

What this law does

A video-sharing platform operator must provide in its terms of service that the platform may not carry a programme, user-generated video or commercial communication that incites hatred, violence or discrimination on a protected ground endangering life, health or property, incites an offense, or depicts child pornography. Content that may impair a minor's physical, mental or moral development must carry a clear warning and an on-screen symbol throughout.

The operator must provide an easy way for users to flag such content, must remove or block access to prohibited content once aware of it, and for harmful-but-not-prohibited content must either add the warning and symbol or ensure the content is accessible only through personal identification codes or another appropriate technical solution that makes it inaccessible to a minor in the ordinary case. A user may complain to the Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA) about how these duties are applied.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (197 words)

Estonia transposed the Digital Single Market (DSM) Directive's (2019/790) press-publisher neighbouring right and text-and-data-mining exceptions through the Autoriõiguse seaduse muutmise seadus (Copyright Act Amendment Act), adopted 8 December 2021 and in force from 7 January 2022.

New Section 73-2 of the Autoriõiguse seadus gives a press publication's publisher an exclusive right to authorize or prohibit online reproduction and making available of the publication by an information society service provider, running for two years from publication, and exempting private non-commercial individual use, hyperlinking, and the use of single words or very short extracts.

New Sections 19-1 and 19-2 create a text-and-data-mining exception: an unconditional, non-waivable right for research organizations and cultural-heritage institutions to reproduce a lawfully accessible work for scientific-research text and data mining, and a general exception for any person to reproduce a lawfully accessible work for text and data mining, defeated by the rightsholder's express reservation of rights including by machine-readable means.

Estonia has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act. No hot-news or misappropriation doctrine distinct from ordinary unfair-competition or copyright law, and no reported Estonian decision on hyperlinking or framing liability, was located in the sources checked.

Press publishers' right

Autoriõiguse seadus (Copyright Act) Section 73-2, Rights of a Press Publication Publisher

Autoriõiguse seadus § 73-2, inserted by Autoriõiguse seaduse muutmise seadus (autoriõiguse direktiivide ülevõtmine), RT I, 28.12.2021, 1Riigi Teataja, original text of the Autoriõiguse seaduse muutmise seadus (autoriõiguse direktiivide ülevõtmine)

In force since 7 January 2022. Binds private bodies.

What this law does

A press publication's publisher holds the exclusive right to permit or prohibit an information society service provider's direct or indirect, temporary or permanent, partial or complete online reproduction of the press publication, and its making available to the public in a manner that lets people access it at a place and time individually chosen by them, per Section 73-2(1).

The right does not reach private, non-commercial use by an individual user, hyperlinking, or the use of single words or very short extracts from a press publication, per Section 73-2(3). The publisher's rights subsist for two years from the publication's publication date, per Section 74(1-1). Authors of works within the press publication are entitled to an appropriate share of the revenue the publisher receives from information society service providers for its use, per Section 73-2(5).

Note and primary source

Text and data mining (TDM) opt-out

Autoriõiguse seadus (Copyright Act) Sections 19-1 and 19-2, Text and Data Mining Exception

Autoriõiguse seadus §§ 19-1 and 19-2 inserted by Autoriõiguse seaduse muutmise seadus (autoriõiguse direktiivide ülevõtmine), RT I, 28.12.2021, 1Riigi Teataja, original text of the Autoriõiguse seaduse muutmise seadus (autoriõiguse direktiivide ülevõtmine)

In force since 7 January 2022. Binds public and private bodies.

What this law does

Without the author's consent and without paying remuneration, a research organization or cultural-heritage institution may reproduce, for scientific-research text-and-data-mining purposes, a work to which it has lawful access, per Section 19-1(1). A contractual term restricting this free use is void, per Section 19-1(4).

Separately, without prejudice to Section 19-1, reproduction of a lawfully accessible work for text-and-data-mining purposes is permitted without the author's consent or payment, but the author may expressly exclude this general free use in an appropriate manner, including by machine-readable means for content made publicly available online, per Section 19-2(1) and (2). Copies made under either section may be retained only as long as necessary for the text-and-data-mining purpose.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.