Menu

Summary


The legal regulation of personal data protection began in Estonia in 1996 when the first Personal Data Protection Act entered into force. To date, the Ministry of Internal Affairs has, in co-operation with the Data Protection Authority, drafted a new Personal Data Protection Act. The article focuses on some of the shortcomings of the new draft Act.
One of the problems as seen by the author is that the draft Act seeks to regulate almost all cases of processing personal data while are only automated and/or structured processing of data are subject to adequate rules. Also, the division of personal data provided by the draft Act is misleading in the author's opinion. For the sake of clarity, the author puts forward a proposal to include in the draft Act a provision corresponding to § 42 of the Constitution expressly prohibiting the processing of data pertaining to religious, philosophical, political and other beliefs by state and local government agencies without the consent of the person concerned. Further, the author calls for the amendment of the provision under which data on a proceeding regarding an offence are, as a rule, treated as delicate data only until an open court session. The author proposes that data concerning penalties should also qualify as delicate data. The provisions on the interbase cross-usage of personal data, restrictions on the processing of personal identification codes and the registration of cases of processing personal data are also criticised.

Close

Enter