AKI (Estonia) - 2.1.-4/26/1106-2333-4
Estonian DPA orders website to implement safeguards for republished public register documents.
Summary
The Estonian Data Protection Inspectorate (AKI) has ordered a website operator to implement safeguards for personal data republished from public registers. The website continued to display documents even after original authorities imposed access restrictions, and failed to adequately address data subject requests. The AKI found the operator lacked sufficient technical and organizational measures to comply with GDPR, particularly regarding the ongoing legal basis for processing and handling special categories of data.
Full text
Help AKI (Estonia) - 2.1.-4/26/1106-2333-4: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 13:43, 23 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators334 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 13:43, 23 September 2026 AKI - 2.1.-4/26/1106-2333-4 Authority: AKI (Estonia) Jurisdiction: Estonia Relevant Law: Article 5(2) GDPR Article 6(1)(f) GDPR Article 9 GDPR Article 24 GDPR Article 25 GDPR Type: Investigation Outcome: Violation Found Started: Decided: 19.06.2026 Published: Fine: n/a Parties: n/a National Case Number/Name: 2.1.-4/26/1106-2333-4 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Estonian Original Source: AKI (in ET) Initial Contributor: bms The DPA ordered a website republishing public-register documents to implement safeguards, verify legal bases and ensure compliance with data-subject rights. No fine was imposed. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller, operated a website which copied and republished documents from public authorities' document registers, including documents containing personal data. The DPA found that some documents remained available on the website even after the original authorities had imposed access restrictions. Authorities and data subjects had also contacted the controller requesting removal of personal data. The controller relied on Article 6(1)(f) GDPR, arguing that the processing served the legitimate interest of making public information easier to find. He also argued that continuously checking all republished documents for later access restrictions was technically difficult. Holding The DPA held that the controller was independently responsible for ensuring that the republication of personal data complied with the GDPR. The fact that personal data had previously been published by a public authority did not automatically provide a legal basis for its further publication. The DPA found that the controller lacked sufficient technical and organisational measures under Articles 5(2), 24 and 25 GDPR to prevent personal data from remaining publicly accessible after the original source had restricted access. Regarding Article 6(1)(f) GDPR, the DPA held that a general legitimate-interest assessment could not justify the republication of all documents containing personal data. The controller had to assess whether a valid legal basis existed for the specific processing, particularly where access restrictions had subsequently been imposed. Where special categories of personal data were involved, Article 9 GDPR also had to be satisfied. The DPA also required the controller to ensure proper handling of requests under Articles 15 to 22 GDPR. Under Article 58(2)(c) and (d) GDPR, the DPA ordered the controller to implement safeguards preventing unlawful publication, stop processing personal data when no legal basis existed, review documents for subsequent access restrictions, and adopt written procedures for data-subject requests. No administrative fine was imposed. However, failure to comply could result in a €500 penalty payment for each unfulfilled requirement. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Estonian original. Please refer to the Estonian original for more details. ERAEU FOR DEFENSE AND GOVERNMENT TRANSPARENCY ORDER-WARNING Regarding the protection of personal data, Case No. 2.1.-4/26/1106-2333-4 RESOLUTION Pursuant to § 56(1) of the Personal Data Protection Act and Article 58(2)(c) and (d) of the General Data Protection Regulation, the Data Protection Inspectorate issues the following binding order to Karl-Sander Erss: The Data Protection Inspectorate sets August 31, 2026, as the deadline for compliance with points 1 and 3 of the order, and June 29, 2026, as the deadline for compliance with points 2 and 4 of the order. Notification of compliance with the order must be submitted no later than the respective deadlines to the Data Protection Inspectorate’s email address: info@aki.ee. Implement systematic technical and/or organizational security measures that enable consistent and immediate monitoring and verification to ensure that no personal data is published on the website https://dokumendiregistrid.karlerss.com/ without a legal basis; 1) confirm and ensure that, upon notification of or becoming aware of the publication of personal data, the further processing (re-publication and storage) of such personal data on the website https://dokumendiregistridkarlerss.com/ any further processing (re-publication and storage) of such personal data if there is no legal basis for the further processing of personal data; 2) review every document published on the website and determine whether the original publisher has subsequently imposed any access restrictions related to the disclosure of personal data in the document; and, if so, immediately cease the further processing (republication and storage) of such personal data if there is no legal basis for doing so; 3) submit to the Data Protection Inspectorate internal written procedures for handling requests from data subjects pursuant to Articles 15–22 of the General Data Protection Regulation, which demonstrate the traceability of requests and the verifiability of compliance with response deadlines. 4) Issued by Helen Laane, Attorney at the Data Protection Inspectorate Date and place of issuance Recipient of the order—data controller Karl-Sander Erss (personal identification code 39412110212) Email address: karl.erss@gmail.com June 19, 2026, in Tallinn DATA PROTECTION INSPECTION 2 (16) NOTICE OF APPEAL This order may be appealed within 30 days by submitting either: Challenging the order does not suspend the obligation to comply with it or the implementation of measures necessary for compliance. WARNING REGARDING A PENALTY PAYMENT If the order has not been complied with by the specified deadline, the Data Protection Inspectorate shall impose on the addressee of the order, pursuant to § 60 of the Personal Data Protection Act: a penalty of 500 euros for each unfulfilled provision. The penalty payment may be imposed repeatedly until the order is complied with. If the addressee fails to pay the penalty payment, the matter will be referred to a bailiff to initiate enforcement proceedings. In such a case, the bailiff’s fee and other enforcement costs will be added to the penalty payment. WARNING REGARDING ADMINISTRATIVE PENALTIES Failure to comply with an order issued pursuant to Article 58(2) of the General Data Protection Regulation may result in the initiation of administrative proceedings under § 69 of the Personal Data Protection Act. A natural person may be fined for this offense. The Data Protection Inspectorate is the authority responsible for conducting out-of-court proceedings for this offense. FACTUAL CIRCUMSTANCES The Data Protection Inspectorate (AKI) previously conducted a supervisory proceeding in 2024 regarding the website https://dokumendiregistrid, which is managed by you, Karl-Sander Erss .karlerss.com/ (hereinafter the “website”), which aggregates the content of various agencies’ public document registries and makes it readable/viewable directly in the browser. Data processing is carried out using a script that copies documents from the public view of the registry and publishes them on the website. Among other things, documents containing personal data are made public in this manner. If, after a document has been initially made public, the agency subsequently imposes an access restriction on the document in the registry (e.g., in connection with the disclosure of personal data), then, to the best of AKI’s knowled