Estonia Chancellor Slams Illegal Data Collection

Estonia Chancellor investigating illegal data collection.
Photo source: Chancellor of Justice

Estonian Chancellor of Justice Ülle Madise has condemned illegal data collection by the Police and Border Guard Board (PPA) involving foreign nationals. Officials reviewing residence permit applications have systematically and unjustifiably demanded unfiltered, multi-year bank statements from applicants. Madise ruled these actions a direct violation of the Constitution, demanding an immediate end to the practice and the deletion of all unlawfully gathered financial information.

The ombudsman intervened following numerous complaints from foreign nationals. Investigations revealed that PPA officials systematically require applicants to submit complete bank statements for all personal, business, and investment accounts, often spanning more than two years. If an applicant refuses to disclose their full financial history, the PPA leaves their residence permit application unreviewed.

PPA officials defend the practice as a necessary screening measure. They argue that reviewing full bank statements helps verify whether an applicant actually resides in Estonia and helps identify sham marriages. However, the agency admitted it already obtains official income data directly from the Estonian Tax and Customs Board.

Ülle Madise rejected these methods, calling them a direct violation of the right to privacy guaranteed by the Estonian Constitution. She emphasized that banking histories reveal highly sensitive personal details, including income levels, daily habits, lifestyle choices, and social connections.

The Chancellor of Justice reminded officials of the data minimization principle, which dictates that the state may only request information strictly necessary for making a decision. To verify income and residency status, Madise suggested the PPA use proportionate tools:

  • Data from the Tax and Customs Board.
  • Official employer certificates.
  • Documents or receipts confirming specific transactions and fund transfers.

In exceptional cases, the PPA may request statements for specific transactions if they are critical to the case. However, demanding an entire transaction history is an unacceptable and excessive intrusion into private life.

Following her investigation, Ülle Madise issued strict demands to the Police and Border Guard Board. The agency must immediately revise its administrative practices and stop withholding application reviews to pressure applicants. Additionally, the PPA must notify all current applicants that demanding full statements is unjustified, and permanently delete all unlawfully collected financial records.


NEWSROOM IN notes that this dispute over bank statements is not the first time Estonian law enforcement and intelligence services have been caught excessively or illegally collecting personal data.

Despite its reputation as an advanced digital nation (e-Estonia), Estonian authorities frequently face criticism from local human rights advocates and European courts for failing to balance security with individual privacy. Several prominent systemic cases highlight unauthorized access to correspondence, phone records, and metadata.

This major scandal affected the fundamental operations of the Estonian police and prosecutor\’s office.

  • The Issue: For years, Estonian investigators and police made bulk requests to telecommunications companies for call logs, phone locations, and internet traffic. Authorization for this access was granted by the prosecution itself, which was simultaneously leading the investigations.
  • CJEU Intervention: In March 2021, the Court of Justice of the European Union (CJEU), ruling on the H.K. v Prokuratuur case, ruled that Estonia\’s practices violated EU law, including the EU Charter of Fundamental Rights.
  • The Outcome: The CJEU determined that the prosecutor\’s office is not an independent authority, ruling that access to metadata (who called whom, when, and from where) can only be authorized by an independent court. This decision disrupted the Estonian law enforcement system, putting numerous criminal cases reliant on illegally gathered evidence at risk.

For years, Estonia practiced preventive telecommunications data retention. Operators were legally required to store the call records and geolocations of all subscribers for a full year in case law enforcement needed them.

This system appeared to collapse in June 2021, when the Supreme Court of Estonia, citing the CJEU ruling, declared the rules unconstitutional. Metadata obtained through these bulk retention programs began to be widely ruled inadmissible in criminal proceedings, except for the most severe crimes. Legislative amendments restricted the use of this data, and the Ministry of Justice began drafting laws to transition toward targeted data collection limited to specific suspects.

However, a scandal in the spring of 2026 revealed that these reforms were largely cosmetic, and bulk data collection continued. A high-profile, €1 million lawsuit filed by Bigbank co-owner Parvel Pruunsild against telecom giant Telia exposed the inner workings of Estonian security practices.

How the Truth Was Revealed

The details emerged after the businessman launched his own investigation. The Internal Security Service (Kapo) had previously accused Pruunsild of corruption, but courts of two instances fully acquitted him. Following his acquittal, he sent an official inquiry to Telia to find out exactly what personal data the operator had handed over to investigators.

The response was unexpected: Telia and the Data Protection Inspectorate admitted they did not know who had accessed the data or when. The operator did not process court requests manually; instead, it provided security services with a direct, unmonitored gateway to its servers. Using this direct connection, law enforcement officials extracted not only call metadata, which had judicial authorization, but also downloaded Pruunsild\’s location history without a warrant. Realizing the scale of the privacy breach, the businessman filed a lawsuit.

The lawsuit exposed three systemic issues that allow bulk surveillance practices to persist:

  • National Law vs. European Law: Telia representatives testified in court that they had no choice. Under the Estonian Electronic Communications Act, operators remain legally obligated to retain customer metadata. Until the Riigikogu (parliament) amends this law, corporations continue to comply with it, ignoring European court rulings.
  • Direct Access for Kapo: Pruunsild\’s lawsuit does not merely concern the release of logs upon request. It revealed that the Internal Security Service has direct, automated, and continuous real-time access to Telia\’s communication and location servers. Intelligence officers can access the operator\’s databases as if they were their own, leaving no record of specific search queries.
  • Reading Emails on Simple Request: The extent of the issue was highlighted in a parallel case. In June 2026, the Supreme Court of Estonia acquitted defendants in another case, ruling that security agencies had spent years reading citizens\’ emails from Telia\’s databases using simple written requests from investigators, without a warrant from an independent judge.

Current Developments

The state is already attempting to retroactively legalize these practices. The Ministry of Justice has drafted new legislation designed to bypass the CJEU prohibitions. However, defense attorneys warn that the draft bill contains loopholes that, under the guise of national security, would allow intelligence services to continue bulk, unmonitored data collection:

  • “Targeted” Retention as a Cover: The new draft proposes replacing mass collection with “targeted storage” of communications data. Defense attorney Andri Rohtla argued in his expert analysis that the new bill leaves a loophole for bulk data collection under pressure from the Ministry of the Interior.
  • Geographical and Situational Exceptions: The bill allows authorities to temporarily institute total data collection during national security threats and to maintain continuous collection in border zones. Critics view this as a legal loophole allowing the collection of metadata for nearly all residents under the pretext of geopolitical risks.
  • Saving Past Cases: A primary concern of the legal community is the state\’s effort to legalize the use of evidence gathered over the years without judicial warrants. Both the CJEU and the Supreme Court of Estonia require such illegally obtained data to be excluded from proceedings.

The collection of foreign nationals\’ bank data, total communications data retention, and unauthorized access to call logs share a common origin. Estonia\’s highly advanced digital infrastructure and databases, such as the X-Road, have fostered a perception of absolute access among officials and security services.

Accessing detailed personal data requires only a few clicks, making it highly convenient for authorities. Consequently, law enforcement agencies—including the PPA, the Tax and Customs Board, and the prosecutor’s office—frequently opt for broad data collection, gathering excessive information “just in case.” This practice violates the constitutional principle of proportionality until challenged by the Chancellor of Justice or European courts.