Back to Feed
PolicyOct 1, 2026

AKI (Estonia) - 2.1.-4/26/1106-2333-4

Estonian DPA finds website operator violated GDPR by republishing restricted public documents.

Summary

Estonia's Data Protection Inspectorate (AKI) found a private website operator in violation of GDPR. The operator republished documents from public registers, including some that had later had access restrictions imposed by authorities. The DPA ruled that legitimate interest could not serve as a blanket legal basis for all publications and that the operator failed to implement sufficient technical and organizational measures to respect subsequent access restrictions.

Full text

Help AKI (Estonia) - 2.1.-4/26/1106-2333-4: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:11, 30 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators344 editsTag: Visual edit← Older edit Latest revision as of 07:28, 1 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators106 editsmTag: Visual edit Line 96: Line 96: }}}} A private website operator published documents they collected from public registers. The DPA held that the operator failed to ensure that later access restrictions imposed by the authorities are considered and that a legitimate interest could not be blanket legal basis for all publications.A private website operator published documents they collected from public registers. The DPA held that the operator failed to ensure that later access restrictions imposed by the authorities are considered and that a legitimate interest could not be a blanket legal basis for all publications. == English Summary ==== English Summary == Latest revision as of 07:28, 1 October 2026 AKI - 2.1.-4/26/1106-2333-4 Authority: AKI (Estonia) Jurisdiction: Estonia Relevant Law: Article 5(2) GDPR Article 6(1)(f) GDPR Article 9 GDPR Article 24 GDPR Article 25 GDPR Type: Investigation Outcome: Violation Found Started: Decided: 19.06.2026 Published: Fine: n/a Parties: n/a National Case Number/Name: 2.1.-4/26/1106-2333-4 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Estonian Original Source: AKI (in ET) Initial Contributor: bms A private website operator published documents they collected from public registers. The DPA held that the operator failed to ensure that later access restrictions imposed by the authorities are considered and that a legitimate interest could not be a blanket legal basis for all publications. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller was a private individual who operated a website that collected documents from public authorities’ document registers and made them easier to search and access online. The DPA found that some documents remained available on the website even after the original authorities had imposed access restrictions. Public authorities and data subjects had also contacted the controller requesting the removal of personal data. The controller relied on Article 6(1)(f) GDPR, arguing that the processing served the legitimate interest of facilitating access to public information. He also argued that continuously checking all republished documents for subsequent access restrictions was technically difficult. Holding The DPA held that the controller was independently responsible for ensuring that the republication of personal data complied with the GDPR. The fact that personal data had previously been published by a public authority did not automatically provide a legal basis for its further publication. The DPA found that the controller lacked sufficient technical and organisational measures under Articles 5(2), 24 and 25 GDPR to prevent personal data from remaining publicly accessible after the original source had restricted access. Regarding Article 6(1)(f) GDPR, the DPA held that a general legitimate-interest assessment could not justify the republication of all documents containing personal data. The controller had to assess whether a valid legal basis existed for the specific processing, particularly where access restrictions had subsequently been imposed. Where special categories of personal data were involved, Article 9 GDPR also had to be satisfied. The DPA also required the controller to ensure proper handling of requests under Articles 15 to 22 GDPR. Under Article 58(2)(c) and (d) GDPR, the DPA ordered the controller to implement safeguards preventing unlawful publication, stop processing personal data when no legal basis existed, review documents for subsequent access restrictions, and adopt written procedures for data-subject requests. No administrative fine was imposed. However, failure to comply could result in a €500 penalty payment for each unfulfilled requirement. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Estonian original. Please refer to the Estonian original for more details. ERAEU FOR DEFENSE AND GOVERNMENT TRANSPARENCY ORDER-WARNING Regarding the protection of personal data, Case No. 2.1.-4/26/1106-2333-4 RESOLUTION Pursuant to § 56(1) of the Personal Data Protection Act and Article 58(2)(c) and (d) of the General Data Protection Regulation, the Data Protection Inspectorate issues the following binding order to Karl-Sander Erss: The Data Protection Inspectorate sets August 31, 2026, as the deadline for compliance with points 1 and 3 of the order, and June 29, 2026, as the deadline for compliance with points 2 and 4 of the order. Notification of compliance with the order must be submitted no later than the respective deadlines to the Data Protection Inspectorate’s email address: info@aki.ee. Implement systematic technical and/or organizational security measures that enable consistent and immediate monitoring and verification to ensure that no personal data is published on the website https://dokumendiregistrid.karlerss.com/ without a legal basis; 1) confirm and ensure that, upon notification of or becoming aware of the publication of personal data, the further processing (re-publication and storage) of such personal data on the website https://dokumendiregistridkarlerss.com/ any further processing (re-publication and storage) of such personal data if there is no legal basis for the further processing of personal data; 2) review every document published on the website and determine whether the original publisher has subsequently imposed any access restrictions related to the disclosure of personal data in the document; and, if so, immediately cease the further processing (republication and storage) of such personal data if there is no legal basis for doing so; 3) submit to the Data Protection Inspectorate internal written procedures for handling requests from data subjects pursuant to Articles 15–22 of the General Data Protection Regulation, which demonstrate the traceability of requests and the verifiability of compliance with response deadlines. 4) Issued by Helen Laane, Attorney at the Data Protection Inspectorate Date and place of issuance Recipient of the order—data controller Karl-Sander Erss (personal identification code 39412110212) Email address: karl.erss@gmail.com June 19, 2026, in Tallinn DATA PROTECTION INSPECTION 2 (16) NOTICE OF APPEAL This order may be appealed within 30 days by submitting either: Challenging the order does not suspend the obligation to comply with it or the implementation of measures necessary for compliance. WARNING REGARDING A PENALTY PAYMENT If the order has not been complied with by the specified deadline, the Data Protection Inspectorate shall impose on the addressee of the order, pursuant to § 60 of the Personal Data Protection Act: a penalty of 500 euros for each unfulfilled provision. The penalty payment may be imposed repeatedly until the order is complied with. If the addressee fails to pay the penalty payment, the matter will be referred to a bailiff to initiate enforcement proceedings. In such a case, the bailiff’s fee and other enforcement costs will be added to the penalty payment. WARNING REGARDING ADMINISTRATIVE PENALTIES Failure to comply with an order issued pursuant to Article 58(2) of the General Data Protection Regulation may result in the initiation of administrative proceedings under § 69 of the Personal Data Protection Act. A natural person may be fined for this offense. The

Entities

AKI (vendor)