Estonia finds most health data queries by police legally justified

Thursday 6th August 2026 on 17:15 in Estonia

Estonia, health data, police

An internal review found that the vast majority of health data queries made by Estonia’s Police and Border Guard Board and Internal Security Service were justified and lawful, ERR reported. The review also identified errors in the purpose, legal basis and procedure of some queries, as well as breaches of internal rules.

Interior Minister Igor Taro ordered the directors general of both institutions in early June to review all queries made by their officials. The review was intended to establish what data had been requested, who had requested it, why it was needed and on what legal basis it had been sought.

“Employees of Estonia’s largest law enforcement agency and largest security agency do not abuse the opportunity to view their fellow citizens’ health data. Queries are made because of work-related needs,” Taro said while summarising the findings.

The results were presented by Internal Security Service Director General Margo Palloson and Kristi Mäe, deputy director general of the Police and Border Guard Board.

Palloson said the Internal Security Service had made health data queries concerning about 13,000 people over 13 months. The review confirmed that the queries had a legal basis and were connected to the agency’s statutory duties.

About 80 percent of the queries were related to security and background checks, including checks involving the agency’s own officials, candidates and service providers. The remaining 20 percent were made as part of intelligence gathering and criminal proceedings.

Two percent of all queries were incorrectly marked, although their substance was lawful and justified.

The review ordered by the interior minister found no violations at the Internal Security Service. However, the agency had previously identified one violation in which an official made queries concerning a close relative. The case was detected shortly after the violation and before the minister ordered the broader review, because of the agency’s internal control and supervision system. Supervisory proceedings were launched against the official.

The Police and Border Guard Board reviewed all health data queries made this year. The review covered queries made to TEHIK, through X-Road to the Health Insurance Fund’s information system, and directly to healthcare providers. There were 2,139 queries in total.

The review confirmed that all queries were connected to police duties or proceedings and that each had a technical record. Most were lawful and justified. In 135 cases, the queries were deemed incorrect or unlawful, or required further assessment.

Mäe said the police must always weigh the impact of their actions on people’s fundamental rights, adding that trustworthiness was particularly important when handling sensitive data.

“Every query must be justified, necessary and verifiable. We reviewed all more than 2,000 queries and can confirm that they were connected to police duties. Although the review found no processing of health data without a procedural need, we identified queries whose legal basis, purpose or method was not correct. We have ended the problematic practice, are reviewing all relevant cases separately and are changing our work arrangements to prevent such errors,” Mäe said.

Source 
(via ERR)