What does AKI compliance look like for Magento, and how strict is it vs other EU DPAs?
AKI (Andmekaitse Inspektsioon) is Estonia’s Data Protection Inspectorate, the local GDPR enforcer. Estonia follows GDPR + the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus, IKS 2018, last updated 2024).
AKI is relatively pragmatic compared to France’s CNIL or Italy’s Garante. Fines are smaller (max €20k for most offences, GDPR-level for systemic abuse), enforcement is mostly complaint-driven, and guidance is reasonable. But the basics still apply:
- Cookie consent banner, GDPR + ePrivacy compliant. AKI accepts standard banners (Cookiebot, OneTrust, native Magento cookie module). No pre-ticked boxes for non-essential cookies. “Reject all” equally prominent as “Accept all”.
- Privacy policy, in Estonian (mandatory for EE storefronts) and ideally Russian + English mirrors. Must list AKI as the supervisory authority and link to AKI’s complaint form.
- DSAR (data-subject access request) routing, we add a contact form scoped to
privaatsus@yourstore.eewith 30-day SLA tracking. - Data-processing register, required for stores > ~250 customers (most Magento stores).
- Breach notification, within 72h to AKI via their portal (etteandmine.aki.ee).
- EU hosting preferred, AKI doesn’t mandate EU residency but recommends it (Frankfurt / Stockholm / Tallinn are common picks).