← Regulators
GDPR EU 2016/679 Estonia

Who is AKI: Estonia's data protection authority

AKI is Andmekaitse Inspektsioon, Estonia's GDPR supervisory authority. What it does, who runs it, how to file a complaint, and how it went from issuing €280 fines to a €3,000,000 fine in 2025.

If you received a letter from Andmekaitse Inspektsioon, saw it mentioned in GDPR fine news, or are just trying to figure out who regulates privacy in Estonia — this is a profile of the body, with every fact sourced.

Quick facts

  • Estonian name: Andmekaitse Inspektsioon (AKI)
  • English name: Estonian Data Protection Inspectorate
  • Founded: 15 February 1999
  • Director General (peadirektor): Pille Lehis — first appointed 19 August 2019, second five-year term confirmed by the Government on 16 May 2024
  • Headcount: 34 civil service positions
  • Mandate: two areas — personal data protection (under GDPR and Estonia’s national data-protection law, abbreviated IKS) and public access to information (under the national freedom-of-information law, abbreviated AvTS)
  • Largest GDPR fine imposed to date: €3,000,000 against Allium UPI OÜ on 5 September 2025 (Apotheka loyalty programme breach affecting >750,000 people) — under appeal, court hearings began 6 April 2026
  • Website: aki.ee

What “AKI” actually stands for

AKI is short for Andmekaitse Inspektsioon — literally “Data Protection Inspectorate” in Estonian. It is Estonia’s national personal-data regulator: the body that enforces GDPR within Estonia.

Every EU country has one (in GDPR’s own language they are supervisory authorities, or DPAs — Data Protection Authorities). For comparison: CNIL in France, DPC in Ireland (where Meta, Google and Apple’s EU HQs sit, so most big-tech enforcement lands there), Garante in Italy, AEPD in Spain, BfDI in Germany (plus one DPA per federal state).

AKI is the Estonian equivalent, scaled to a country of 1,360,745 people (Statistics Estonia, 1 January 2026).

What AKI actually does

Per its own statute on Riigi Teataja (§1(2)) and self-description on aki.ee, the inspectorate operates in two areas: personal data protection and public access to information.

1. GDPR and IKS supervision

IKS (Isikuandmete kaitse seadus) is Estonia’s Personal Data Protection Act — the national companion to GDPR. GDPR is a directly applicable EU regulation; IKS adds Estonian-specific bits (procedures, journalism and research carve-outs, the misdemeanour provisions used to fine). The current text of IKS lives on Riigi Teataja, the official Estonian legal gazette.

Practically AKI:

  • receives and investigates complaints from individuals and companies (for example, an employee whose employer asked for a urine sample without proper basis, or a customer whose data ended up on a leaked database),
  • runs proactive audits — site inspections of how a company processes personal data, without waiting for a complaint,
  • issues precepts (ettekirjutus) — formal written orders to fix a violation by a deadline,
  • fines for non-compliance with a precept and for the underlying breach itself,
  • maintains the register of Data Protection Officers (DPOs — the internal compliance leads that GDPR requires for many public bodies and large data-handling private companies) at Estonian organisations.

2. AvTS supervision

AvTS (Avaliku teabe seadus) is the Public Information Act. This is not about privacy — it is the opposite: government transparency. If a public body refused to release a document that should be open, the complaint goes to AKI.

So AKI is simultaneously the “protector of privacy from the state and business” and the “protector of state transparency from the state itself”. Unusual combination for one body, but that is how it ended up structured in Estonia.

3. EU-level coordination

AKI is a member of the European Data Protection Board (EDPB) — the EU-wide body that coordinates all EEA DPAs. When an Estonian complains about a service headquartered in another EU country (a German cloud provider, an Irish-based US tech company), the case routes through the one-stop-shop mechanism. EDPB also issues guidance that AKI follows when applying GDPR.

Leadership

The inspectorate is led by a Director General (peadirektor), appointed by the Government of the Republic of Estonia on the Justice Minister’s recommendation for a five-year term, after hearing the opinion of the Riigikogu Constitutional Committee (§54 of the Personal Data Protection Act).

The current Director General is Pille Lehis. She first took the role on 19 August 2019; the Government confirmed her for a second five-year term on 16 May 2024, after the parliamentary Constitutional Committee gave its favourable opinion on the Justice Minister’s proposal.

Independence of the regulator is locked in by GDPR itself (Article 52: “complete independence”) — no minister can tell the inspectorate how to investigate a specific case or what to decide. This is universal across EU DPAs, precisely so that the executive cannot lean on the regulator over fines against politically connected companies.

Resources and 2024 in numbers

By EU standards AKI is small. The inspectorate has 34 civil service positions, which goes a long way to explain the historical pattern of a small team unable to run dozens of major investigations in parallel.

For the most recent year on record:

  • 4,162 inquiries received in 2024 (per the inspectorate’s own press release) — a multiple of early-2020s figures, with broadly flat headcount.
  • 184 breach notifications received, affecting roughly 910,000 people in aggregate.
  • 12 misdemeanour proceedings initiated, totalling €79,100 in fines ordered (subject to appeal — see below).

Annual reports going back to 2001 are at aastaraamat.aki.ee.

From €280 to €3,000,000: enforcement history

The most striking thing about AKI is how dramatically its bite has changed in two years.

The toothless years (2018–2022)

From the start of GDPR (25 May 2018) to November 2022, AKI issued 29 fines totalling €1,924 — with the largest being €280 (Sorainen, Statistics on GDPR fines in the Baltics). That is not a typo.

The reason was not regulatory leniency but a hole in the Estonian Penal Code: it was effectively impossible to fine a legal entity directly. The prosecution had to identify the specific individual at fault inside the company and prove their personal guilt. For organisational violations — poor security, malformed consent, leaks caused by general disorder — this was practically infeasible.

The reform (1 November 2023)

The Riigikogu passed the relevant Penal Code amendments on 22 February 2023; they entered into force on 1 November 2023. Two key changes for data protection:

  • A legal entity can now be liable when the violation is caused by deficient organisation or supervision, even if no specific individual can be identified as personally guilty.
  • The previous €400,000 cap on misdemeanour fines was removed for data protection cases — opening the door to GDPR-scale fines (up to €20 million or 4% of global annual turnover).

The first attempt fails in court (Asper Biogene, 2025)

In early 2025 AKI imposed an €85,000 fine on Asper Biogene OÜ — the first substantial post-reform penalty. Two violations: (a) appointing the company’s sole board member as the DPO, who lacked the independence and competence the role requires; (b) insufficient security measures that enabled an autumn 2023 cyberattack exposing special-category data (sensitive personal data under GDPR Article 9 — health, genetics, biometrics, religion, sexual orientation; subject to stricter rules than ordinary personal data).

Tartu County Court annulled the fine on 26 June 2025 and terminated the proceedings, citing minor culpability and lack of public interest in continuing the case. AKI appealed — the Supreme Court (Riigikohus) refused to take the case in August 2025, making the lower court’s annulment final.

The record fine (Apotheka, September 2025) — under appeal

On 5 September 2025 AKI issued a €3,000,000 fine against Allium UPI OÜ — operator of the Apotheka pharmacy chain’s loyalty programme — over a 2024 breach affecting more than 750,000 people. The decision found that Allium UPI had failed to implement basic security measures: no multi-factor authentication, multiple staff sharing the same admin account, insufficient activity logging, and unsafe storage of database backups. The leaked records covered loyalty members from 2014–2020 — names, ID codes, contact details, addresses, and purchase histories.

This is the largest GDPR fine ever imposed in Estonia, but it is not yet final. Allium UPI rejected AKI’s findings and appealed; court proceedings began on 6 April 2026. Given the Asper Biogene precedent (annulled at first instance, AKI’s appeal denied by the Supreme Court), the outcome is far from guaranteed.

A full registry of every publicly known AKI fine — with articles cited, amounts, breach descriptions, and the fate of each ruling in court — is in a separate post: AKI fines: every known case.

How to contact AKI

  • File a complaint: via the GDPR complaint form on aki.ee — submit through the e-portal or download a Word template. Free of charge.
  • Email and postal address: in the “Kontakt” section of the site.
  • Processing times: typically 30 days, extendable to four months in complex cases (an EU-wide GDPR requirement, not Estonia-specific).

You can complain about any organisation processing your personal data in violation of GDPR/IKS — from a local shop with a misaimed CCTV camera to a global service. If the respondent is headquartered in another EU country, AKI will route the case through the EDPB one-stop-shop.

What this means for you

If you run a business that processes Estonian personal data: the era of €280 fines is over. The 2023 reform plus the €3M Apotheka fine make clear that AKI now has — and intends to use — full GDPR-scale enforcement. The most expensive things to get wrong, judging by recent fines, are: leaks of customer databases due to weak security (no MFA, shared admin accounts, unencrypted backups), processing of health/genetic/biometric data without an enhanced legal basis, and treating the DPO role as a paper formality.

If you’re an Estonian resident wanting to complain about how a company handled your data: the GDPR complaint form on aki.ee is free and processed in 30 days (extendable to 4 months for complex cases). If the company is headquartered in another EU country, AKI hands the case to that country’s DPA via the EDPB one-stop-shop — you don’t need to file separately.

If you’re a journalist or researcher tracking GDPR enforcement: AKI’s annual reports on aastaraamat.aki.ee and the live registry of fines at /enforcement/aki-fines cover everything publicly disclosed.

TL;DR

Until November 2023 AKI was a symbolic regulator without working enforcement levers — total fines over five years amounted to €1,924. A Penal Code reform on 1 November 2023 closed that gap. The first court test (Asper Biogene €85k) was overturned. The second — a record €3,000,000 against the operator of Apotheka’s loyalty programme on 5 September 2025 — is under appeal, with hearings begun 6 April 2026. AKI now has the same toolbox as its EU peers and growing willingness to use it; whether the toolbox holds up in court is being tested right now. If your business touches Estonian data, take it seriously.

Sources