Taro says state data controls work and personal information is protected

Thursday 6th August 2026 on 21:00 in Estonia

data protection, Estonia, Internal Security Service

Estonia’s internal controls over state databases are functioning and people’s personal information is protected, Interior Minister Igor Taro said in an interview published by ERR.

Taro said data protection legislation should be updated because society and technology have changed over the past decade. New channels and challenges have emerged, while some existing rules may be too general and fail to address specific situations.

He said health data queries are not made only in connection with criminal investigations. The Internal Security Service, for example, conducts background checks on people who handle state secrets or apply for security clearances. Checks are also carried out for certain sensitive positions, including in organisations providing vital services.

The Estonian Defence Forces are a significant user of such checks because authorities need to know whether people who handle state secrets have drug addictions that could create problems, Taro said.

After ordering the Police and Border Guard Board and the Internal Security Service to proactively conduct a full review of queries made over more than a year, Taro said he had expanded the scope of the review. Within a month, the Police and Border Guard Board must provide an overview of all databases it uses, the queries made in them and the legal bases for those queries.

He said the purpose is not to examine every query within a month, but to determine whether there are further shortcomings in the databases.

The Internal Security Service identified one query during the year that was made out of curiosity and was unrelated to official duties. However, the query was detected by internal control after two days and was stopped, Taro said.

“It cannot be said that the data are completely unprotected, because internal controls operate every day, even when we are not conducting this analysis,” he said.

The audit also confirmed that every query leaves a trace leading back to its source. It identified some problematic queries involving careless documentation, an incorrect channel or cases where consent should have been considered. Taro said the information systems record logs and traces of all operations.

Source 
(via ERR)