Email Marketing Regulatory Compliance — Estonia
Short Definition: What Is Covered by “Email Marketing”
Email marketing in Estonia includes commercial promotional email, newsletters, sales campaigns, product announcements, lead-nurture and lifecycle automations, abandoned-cart or renewal messages that contain promotional content, and prospecting messages sent to consumer or business contacts. A service or transactional email can become regulated as marketing if it includes offers, cross-sells, brand promotion, sponsored content, or other material intended to promote goods, services, events, or reputation.
Estonia does not have a single stand-alone anti-spam act. Email marketing is regulated through a combination of the elektroonilise side seadus (Electronic Communications Act), the infoühiskonna teenuse seadus (Information Society Services Act), the European Union (EU) General Data Protection Regulation, the isikuandmete kaitse seadus (Personal Data Protection Act), the reklaamiseadus (Advertising Act), consumer protection and distance-selling rules, and sector-specific advertising restrictions.
Key Takeaways for Marketers
- Natural-person email marketing is mainly opt-in. Using the electronic contact details of a natural-person subscriber or communications-service user for direct marketing generally requires prior consent. Treat consumer addresses, named personal addresses, and employee addresses that identify an individual as personal data, and keep evidence of the permission or statutory route relied on.
- Legal-person marketing has an opt-out route. Direct marketing to a legal-person subscriber or user may be possible if each use gives a clear, distinct, free, and easy way to refuse use of the contact details and the refusal can be exercised electronically. If the campaign uses a named employee, role profile, engagement score, or customer relationship management record, General Data Protection Regulation duties still apply to that personal-data layer.
- The Estonian soft opt-in is narrow. A seller or service provider that obtained a buyer’s electronic contact details in connection with a sale or service may use them for direct marketing of its similar products or services if the buyer received a clear opt-out at collection and receives the same easy, free opt-out in every message. Do not stretch this route to unrelated brands, affiliate offers, rented lists, dormant prospects, or contacts collected only through competitions, events, or content downloads unless the statutory conditions are genuinely met.
- Sender identity and refusal information are essential. Direct marketing must not conceal the person on whose behalf the message is sent, must include information or instructions enabling refusal, and must stop after refusal. Commercial communications, discounts, gifts, promotional competitions, games, and offer conditions must be recognizable and clear.
- Proof, segmentation, and suppression control reduce risk. The person on whose behalf direct marketing is conducted bears the burden of proving natural-person consent. Marketing operations should segment Estonian contacts by natural person, legal person, customer soft opt-in, source, consent wording, privacy-notice version, tracking status, and suppression status before every send.
Laws and Regulations Governing Email Marketing in Estonia
Elektroonilise side seadus (Electronic Communications Act)
Local Language Name: Elektroonilise side seadus, vastu võetud 08.12.2004, RT I 2004, 87, 593
English Translation: Electronic Communications Act, passed 8 December 2004, RT I 2004, 87, 593
Official Text: https://www.riigiteataja.ee/en/eli/ee/517122020006/consolide/currentThis is the core Estonian statute for the use of electronic contact details for direct marketing. Section 103¹ regulates prior consent for natural-person recipients, the opt-out model for legal-person recipients, the customer soft opt-in, prohibited unidentified or non-transparent direct marketing, refusal mechanisms, and the burden of proof for natural-person consent.
Infoühiskonna teenuse seadus (Information Society Services Act)
Local Language Name: Infoühiskonna teenuse seadus, vastu võetud 14.04.2004, RT I 2004, 29, 191
English Translation: Information Society Services Act, passed 14 April 2004, RT I 2004, 29, 191
Official Text: https://www.riigiteataja.ee/en/eli/ee/503092024004/consolide/currentThis Act regulates information society services and transparency for commercial communications. For email marketers, the practical requirements are that commercial communications must be clearly identifiable, the person on whose behalf they are made must be identifiable, promotional offers and competitions must be clearly identifiable, and participation conditions must be clearly presented.
Euroopa Parlamendi ja nõukogu määrus (EL) 2016/679 (isikuandmete kaitse üldmäärus)
Local Language Name: Euroopa Parlamendi ja nõukogu määrus (EL) 2016/679 füüsiliste isikute kaitse kohta isikuandmete töötlemisel ja selliste andmete vaba liikumise ning direktiivi 95/46/EÜ kehtetuks tunnistamise kohta (isikuandmete kaitse üldmäärus)
English Translation: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
Official Text: https://eur-lex.europa.eu/eli/reg/2016/679/ojThe General Data Protection Regulation (GDPR) applies whenever email addresses, names, customer identifiers, tracking data, behavioral segments, suppression records, or prospect profiles relate to an identified or identifiable natural person. It governs lawful basis, transparency, consent quality, data minimization, retention, security, processor contracts, international transfers, profiling, data subject rights, and objection handling.
Isikuandmete kaitse seadus (Personal Data Protection Act)
Local Language Name: Isikuandmete kaitse seadus, vastu võetud 12.12.2018, RT I, 04.01.2019, 11
English Translation: Personal Data Protection Act, passed 12 December 2018, RT I, 04.01.2019, 11
Official Text: https://www.riigiteataja.ee/en/eli/ee/523012019001/consolide/currentThis Estonian Act supplements the GDPR and identifies the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon (AKI), as the supervisory authority. It is relevant to complaint handling, supervisory powers, non-compliance measures, misdemeanor proceedings, children’s information society services, and Estonia-specific data protection administration.
Reklaamiseadus (Advertising Act)
Local Language Name: Reklaamiseadus, vastu võetud 12.03.2008, RT I 2008, 15, 108
English Translation: Advertising Act, passed 12 March 2008, RT I 2008, 15, 108
Official Text: https://www.riigiteataja.ee/en/eli/509032026001/consolideThe Advertising Act applies where email content is advertising. It requires advertising to be recognizable as advertising, requires identification of the person placing advertising, prohibits misleading advertising, regulates comparative advertising, and imposes special restrictions for sensitive categories such as alcohol, gambling, financial services, tobacco-related products, medicinal products, health services, children-directed advertising, and other regulated goods or services.
Tarbijakaitseseadus (Consumer Protection Act)
Local Language Name: Tarbijakaitseseadus, vastu võetud 09.12.2015, RT I, 31.12.2015, 1
English Translation: Consumer Protection Act, passed 9 December 2015, RT I, 31.12.2015, 1
Official Text: https://www.riigiteataja.ee/en/eli/ee/521082017004/consolide/currentThe Consumer Protection Act affects business-to-consumer campaign claims, prices, invitations to purchase, trial offers, subscription flows, and post-click sales funnels. It prohibits unfair, misleading, and aggressive commercial practices, so marketers should review the email, landing page, order path, cancellation messaging, and customer-support scripts together.
Võlaõigusseadus (Law of Obligations Act)
Local Language Name: Võlaõigusseadus, vastu võetud 26.09.2001, RT I 2001, 81, 487
English Translation: Law of Obligations Act, passed 26 September 2001, RT I 2001, 81, 487
Official Text: https://www.riigiteataja.ee/en/eli/ee/525112025001/consolide/currentThis Act is important when email campaigns lead to consumer contracts, online checkout, subscriptions, digital content, or distance sales. It contains distance-contract and precontractual information rules that affect price presentation, withdrawal information, confirmation notices, and post-click disclosures connected with campaign offers.
Item-by-Item: What Is Regulated, Why and How
Elektroonilised kontaktandmed (electronic contact details): Estonia’s direct marketing rule covers contact details that allow information to be conveyed over electronic communications networks, including email, SMS, MMS, and fax. Marketing teams should classify each email address by recipient type, source, consent or opt-out status, customer relationship, soft opt-in eligibility, and whether the address identifies a natural person.
Otseturustus (direct marketing): Direct marketing includes promotional messages intended to encourage purchases, service use, brand engagement, renewal, reactivation, or similar commercial outcomes. A newsletter, survey invitation, product update, account notice, or lifecycle automation should be treated as marketing if it contains promotional content or sends the recipient to a promotional funnel.
Nõusolek (consent): For natural persons, prior consent should meet GDPR standards: it must be freely given, specific, informed, unambiguous, and withdrawable. The campaign owner should preserve the consent wording, collection context, timestamp, source form, privacy-notice version, and preference changes.
Juriidiline isik (legal person): Direct marketing to legal-person recipients is treated differently from direct marketing to natural persons. Even where the legal-person opt-out route is used, named contacts, role profiles, engagement scores, and customer relationship management notes may still be personal data and should be covered by a lawful basis, transparency notice, and objection process.
Õigustatud huvi (legitimate interest): Legitimate interest may support some business-to-business customer relationship management, segmentation, or prospect-record processing under the GDPR. It does not replace the Electronic Communications Act’s prior-consent rule where natural-person electronic contact details are used for direct marketing.
Keeldumisõigus (right to refuse): Legal-person marketing and customer soft opt-in marketing depend on a clear, distinct, free, and easy refusal mechanism that can be exercised electronically. Opt-outs should feed a suppression list before the next campaign selection, sales-sequence enrollment, retargeting upload, co-branded send, or vendor sync.
Pehme opt-in (soft opt-in): A buyer’s contact details collected in connection with a sale or service relationship may be used for the sender’s similar offerings only when the buyer had an opt-out opportunity at collection and receives one in every message. Marketers should not stretch this exception to unrelated brands, third-party offers, affiliate campaigns, old dormant contacts, or leads collected through competitions or white papers unless the conditions are clearly satisfied.
Kommertsteadaanne (commercial communication): Commercial communications must be recognizable, identify the person on whose behalf they are made, and make discounts, gifts, competitions, games, and participation conditions clear. This affects subject lines, preview text, sender names, email body copy, landing pages, sponsored sends, and co-branded campaigns.
Reklaam (advertising): Advertising must be identifiable, must identify the advertiser in the required manner, and must not mislead. Email campaigns should not hide a commercial purpose inside service messages, exaggerate scarcity, obscure price conditions, omit material limitations, or use comparative claims without substantiation.
Isikuandmed (personal data): Named email addresses, customer identifiers, open and click data, purchase history, behavioral segments, device data, and suppression records may be personal data. Marketers need privacy-notice coverage, lawful-basis documentation, retention limits, access controls, processor contracts, and safeguards for transfers outside the European Economic Area (EEA).
Küpsised ja jälgimine (cookies and tracking): Campaign landing pages that use analytics cookies, advertising cookies, retargeting tags, or similar nonessential tracking should be configured for Estonian and EU consent expectations. Email pixels, click tracking, and audience uploads should be disclosed in privacy notices, minimized where possible, and aligned with the recipient’s consent, objection, and suppression status.
Registrikood (registry code): Estonian companies commonly identify themselves using their legal name, legal form, and registry code. A strong Estonia-facing footer usually includes the legal sender name, brand where different, registry code where applicable, contact route, privacy-notice reference, and a simple unsubscribe mechanism.
Cheat Sheet: What Is Not Allowed in Estonia
- Sending direct marketing emails to natural persons without prior consent, unless a properly limited customer soft opt-in applies.
- Continuing to email a recipient after the recipient has refused or unsubscribed from direct marketing.
- Sending direct marketing that conceals or fails to identify the person on whose behalf the message is sent.
- Omitting clear instructions or information that allow the recipient to refuse further direct marketing electronically.
- Using misleading subject lines, hidden advertising, unclear discounts, vague competition conditions, or landing pages that fail commercial-communication transparency rules.
- Relying on purchased, scraped, or appended personal email lists without defensible consent or lawful basis, source records, and suppression screening.
- Uploading opted-out or unlawfully collected Estonian contacts into advertising platforms, lookalike audiences, enrichment tools, or sales automation systems.
Cheat Sheet: What Is Allowed in Estonia
- Sending marketing emails to natural persons who have given valid, provable prior consent for the relevant sender and communication type.
- Using a buyer’s contact details for the sender’s similar products or services when the Estonian soft opt-in conditions are met and every message includes an easy, free opt-out.
- Sending direct marketing to legal-person recipients on an opt-out basis when refusal is clear, free, easy, and electronically available, subject to personal-data safeguards for named contacts.
- Sending genuine transactional or service emails when they are necessary for the relationship and are not used as a cover for unrelated promotional content.
- Maintaining suppression lists to honor refusals, provided the retained data is limited, secured, and used to prevent further marketing.
Best Practices for Email Marketers — Estonia
Build Estonia audiences around documented permission and list provenance. Use separate fields for consent, soft opt-in eligibility, legal-person status, opt-out status, source, collection language, campaign category, privacy-notice version, tracking status, and last engagement. Write notices, preference-center text, and unsubscribe copy in clear Estonian for Estonia-facing consumer campaigns, price local offers in euros, and ensure that email copy, landing pages, trial terms, discount conditions, subscription cancellation information, and customer-support scripts match.
Use a conservative footer standard: legal sender name, trading brand where different, Estonian registry code where applicable, postal or service address, customer-service contact, privacy-notice reference, and a simple unsubscribe path. For Estonian companies, terms such as OÜ for osaühing (private limited company), AS for aktsiaselts (public limited company), registrikood (registry code), and value-added tax information where relevant help recipients identify the sender and support trust.
Coordinate marketing, legal, information technology, sales, and vendors before campaigns launch. Email service providers, customer relationship management platforms, analytics providers, enrichment vendors, agencies, and call-center or sales-sequence vendors should have data processing agreements, documented subprocessors, security controls, role-based access, deletion or return procedures, and cross-border transfer safeguards. Audit automations so opt-outs suppress newsletters, lifecycle journeys, sales outreach, abandoned-cart flows, retargeting exports, audience uploads, and co-branded sends across all systems.
Enforcement and Risk Management in Estonia
The main practical enforcement channel for privacy, consent, objection, profiling, tracking, and the use of electronic contact details for direct marketing is AKI. The Consumer Protection and Technical Regulatory Authority, Tarbijakaitse ja Tehnilise Järelevalve Amet (TTJA), is important for consumer protection, advertising, information society services, and electronic communications issues within its competence; the Reklaaminõukoda (Advertising Council) advises TTJA on advertising matters. Sector regulators may also matter for financial services, gambling, health, medicines, alcohol, tobacco-related products, and other restricted categories.
Penalty exposure can be significant where email marketing failures also breach data protection rules. Under the GDPR, serious violations such as unlawful processing, invalid consent, rights failures, or unlawful transfers may reach the higher tier of 20,000,000 euros or 4 percent of total worldwide annual turnover, while many controller and processor obligations fall in the lower 10,000,000 euros or 2 percent tier. Under the Advertising Act, legal-person violations of general advertising requirements, advertising prohibitions, or restrictions on advertising of goods and services can reach 400,000 euros, with additional sector-specific exposure in special categories.
Operational risk often appears before a formal fine: complaints to AKI or TTJA, inbox-provider blocking, blacklisting, platform account restrictions, customer-service escalation, public criticism, and loss of trust can follow quickly from poor list sourcing or ignored unsubscribes. The practical takeaway for marketers is simple: segment Estonia by recipient type, obtain and store proof before sending, make the sender and offer obvious, process refusals across every system, and audit vendors as carefully as campaign copy.
Copyright © 1993-2026 World Trade Press. All rights reserved.