Estonia law enforcement data requests

Estonia's Justice Ministry Delays a Fix for a Data-Retention Law Its Own Courts Called Unlawful in 2021

A draft ending blanket retention of Estonians' phone and location data was pulled hours after submission, pushing the fix to an August 13 cabinet vote.

Estonia's Data-Retention Reform, By the Numbers People of Internet Research · Estonia 1 year Current blanket retention period Every resident's phone and locatio… 5 Years since court ruled it unlawful Estonia's Supreme Court struck dow… Aug 13 Rescheduled cabinet vote The withdrawn draft returns to gov… peopleofinternet.com
Estonia's Data-Retention Reform, By th… People of Internet Research · Estonia 1 year Current blanket retention period 5 Years since court ruled it unlawful Aug 13 Rescheduled cabinet vote peopleofinternet.com

Key Takeaways

On July 14, 2026, Justice and Digital Affairs Minister Liisa Pakosta sent a draft law to the Estonian government that would have ended one of the EU's longest-unresolved compliance failures: the state-mandated, blanket year-long retention of every resident's phone and location metadata. Within hours, the ministry withdrew it "for possible clarification." The bill is now rescheduled for the government's August 13 session — another month's delay on a problem Estonia's own Supreme Court flagged as unlawful back in 2021 (ERR News).

The stakes are not abstract. Under Estonia's Electronic Communications Act, telecom operators have been required since 2008 to retain traffic and location data on every subscriber, guilty or not, for up to a year, available to prosecutors on request. Pakosta's draft would replace that with a tiered system: only user-identification data and IP addresses would still be retained on a blanket basis. For everything else, investigators would draw on data telecoms already keep for commercial purposes, or use a case-specific "quick freeze" mechanism to preserve data tied to an active investigation. Misdemeanor cases would only get access for serious or organized offenses, and a narrow national-security exception would permit short-term broader retention only via a government decision with the Riigikogu's involvement (ERR News).

Why the Old System Is Already Illegal

This isn't a policy preference Estonia is free to keep or discard. In June 2021, the Estonian Supreme Court ruled in case 1-16-6179 that the blanket retention and prosecutorial access regime under §111¹ of the Electronic Communications Act and §90¹ of the Code of Criminal Procedure conflicted with the EU's e-privacy directive and the Charter of Fundamental Rights, holding that "general and indiscriminate retention of telecommunications data is not allowed" even with procedural safeguards attached (FRA case-law reference). That ruling built on the Court of Justice of the EU's March 2021 judgment in Prokuratuur (Case C-746/18), which found that Estonia's public prosecutors could not serve as the independent authority EU law requires before granting access to traffic and location data, since prosecutors direct the same investigations they'd be approving access for (eucrim). Five years on, the underlying statute is unamended — a gap Estonian courts have kept papering over case by case while the legislature hasn't acted.

The Case for Caution

Before dismissing the delay as bureaucratic drift, it's worth taking seriously why police and telecom firms pushed back on the draft as written. Leho Laur, head of the Central Criminal Police, warned that stripping investigators of routine access to historical call records doesn't eliminate the need for that information — it just forces police toward more invasive substitutes, like real-time surveillance, to compensate for what they can no longer reconstruct after the fact. That's a genuine proportionality trade-off, not a talking point: a narrower rule that pushes law enforcement toward more intrusive tools in individual cases could leave targeted suspects worse off even as it protects the general population's data. Estonia's telecom industry group ITL separately warned that carving retention into multiple data categories, each with different access rules, replaces "one broad road" with "ten different winding ones" — real compliance cost that gets passed to consumers (ERR News).

Why the Reform Direction Is Still Right

Those costs are real, but they're the price of doing something EU law has required for five years — not a reason to keep the current regime, which a supranational court and a national supreme court have both already invalidated. The Bar Association's Andri Rohtla raised the sharper objection: the draft's national-security carve-out lets the government authorize broader retention on its own say-so, without prior judicial review, effectively rebuilding a backdoor into the system the bill is meant to dismantle (ERR News). That's the part of the draft worth fixing before August 13 — not the core shift toward commercially-retained data plus quick freeze, which is the same model the CJEU has repeatedly signaled is compatible with EU law. Even Pakosta has conceded the trade-off is real: as the ministry put it in defending the draft, the reform means police lose some routine convenience against fraud in exchange for a legal footing the current system doesn't have.

"General and indiscriminate retention of telecommunications data is not allowed" — Estonian Supreme Court, case 1-16-6179 (2021)

Quick freeze is not a novel or untested compromise — versions of it operate across the EU precisely because it lets investigators secure evidence in live cases without requiring telecoms to hold every resident's movements on file by default. Estonia doesn't need a perfect bill by August 13; it needs one that closes the security-exception loophole, keeps quick freeze intact, and finally gets a five-year-old court order off the books. Another withdrawal past August would mean Estonia enters year six of operating a data-retention regime its own Supreme Court struck down before most of today's smartphone users had upgraded their handsets.

Sources & Citations

  1. ERR News — Estonia weighs limits on bulk communications-data retention
  2. ERR — Critics say the draft could make things worse
  3. Estonian Supreme Court press release, case 1-16-6179
  4. EU Fundamental Rights Agency — case-law reference, Estonia Supreme Court 1-16-6179
  5. eucrim — CJEU confirms strict limitations of data retention