GDPR Compliance Principles

Comprehensive Overview of GDPR Compliance Principles and Our Commitment to Data Protection

At Eesti Firma (legal name Eesti Firma OÜ, registration number 14164797, registered address: Vesivärava 50-301, 10152 Tallinn, Estonia), protecting your personal data is our highest priority. As a licensed Estonian Trust and Company Service Provider, we process personal data in full accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus). Our commitment to privacy is built on the data-processing principles established in Article 5 of the GDPR.

These principles guide all our decisions regarding how we process your data and underpin our internal procedures. Below, we explain each principle, how we apply it in practice, the rights you have as a data subject, and how to contact the competent supervisory authority. Detailed information about specific data processing operations and protection measures is provided in our Privacy Policy.

In short

We process your personal data in line with the seven GDPR principles set out in Article 5 — lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. This page explains each principle, lists your rights as a data subject (access, rectification, erasure, objection and more), and tells you how to lodge a complaint with the Estonian Data Protection Inspectorate. Specific processing details are set out in our Privacy Policy.

Lawfulness, Fairness, and Transparency

We process personal data lawfully, fairly, and transparently in relation to you, as required by Article 5(1)(a) of the GDPR. This means any data processing is conducted based on lawful grounds, honestly, and openly toward you as the data subject. Within this principle, we adhere to the following approaches:

  • Lawfulness: We collect and use your personal data only when there is a clear and lawful basis under Article 6 of the GDPR. Our legal grounds include your informed consent (where required), the performance of contractual obligations, compliance with legal requirements (for example, anti-money-laundering and KYC obligations), or our legitimate business interests, which do not override your rights. You will always be informed of the legal basis for processing your data.
  • Fairness: We ensure fairness in data processing. This means we do not collect data deceitfully nor use it to your detriment. We never mislead you about the purposes of collecting information or how it will be used. Furthermore, we consider your interests and rights—for example, we guarantee the non-discriminatory exercise of your rights (such as the right to access your data), regardless of terms of service. Data processing is performed to avoid unjustified harm to your privacy.
  • Transparency: We communicate openly and clearly about why and how your data is used. All processing information is provided in plain language, avoiding excessive legal jargon. Our Privacy Policy and other notices are always easily accessible so you can find out at any time what data we collect, on what grounds, and for what purposes. When necessary, we use a multi-layered approach to informing you—we highlight key points and provide details through additional links or tooltips. We regularly update our information to keep it current and inform you of any significant changes. This transparency ensures you know exactly how your personal data is processed.

Purpose Limitation

In line with Article 5(1)(b) of the GDPR, we collect and use personal data only for specific, pre-defined, and lawful purposes, of which you are notified in advance. This means your data will be used exclusively for the purposes for which it was collected. We do not use personal information in any new way incompatible with the original purposes. For example, if you provide your email address to receive updates about our service, we will not share it with a partner for advertising without your knowledge and consent.

All processing purposes are clearly documented—in our internal records and public documents (such as the Privacy Policy), we specify the reasons for collecting certain data. If there is a need to use data for a new purpose inconsistent with the original one, we will obtain separate consent from you beforehand or ensure another lawful basis for processing. Thus, you can be assured your personal data will not be used unexpectedly or beyond the initially stated purposes.

Data Minimization

We adhere to the principle of data minimization (Article 5(1)(c) of the GDPR), meaning we collect only the personal information truly necessary for the declared processing purposes. In practice, this is implemented as follows:

  • We request only the minimal amount of data necessary to provide the requested service or fulfill a contract. Forms and surveys on our website are designed not to collect unnecessary information. For instance, if registering for a webinar requires only your name and email, we will not request additional unrelated data.
  • The “nothing extra” principle helps us reduce risks to your privacy. The less data stored and processed, the lower the likelihood of leaks or unauthorized access. We do not collect information “just in case,” accumulating data that might someday be useful. All information requests are carefully justified by specific necessity.
  • We also regularly review the data we collect, removing any fields or requests that are not essential. Thus, we ensure that, in all interactions, we request only information genuinely necessary to achieve the specified purposes.

Accuracy

Keeping personal data accurate and up-to-date (Article 5(1)(d) of the GDPR) is another key principle we follow. We make every reasonable effort to ensure the information we hold about you is correct, complete, and current, as this affects the quality of our services and your trust. To ensure accuracy, we implement the following measures:

  • Regular Updates: If your personal data has changed (for example, you’ve updated your contact number or address), we promptly reflect these changes in our systems. We aim to prevent decisions from being based on outdated or incorrect information.
  • Error Correction: If you discover that any of your details are incorrect or outdated, you can always notify us – we will promptly correct the errors. Moreover, you have the right to rectification (correction) of inaccurate data under Article 16 of the GDPR, which we fully respect, providing convenient ways for you to inform us of any inaccuracies.
  • Verification of Critical Data: In cases where data accuracy is particularly important (e.g., for financial transactions or provision of legally significant services), we may undertake additional steps to verify and confirm information. This could involve requesting supporting documents or cross-checking data with you. All these measures ensure our databases contain only accurate information.
  • Deletion of Inaccurate Data: According to GDPR requirements, inaccurate or incomplete data that cannot be corrected must be deleted without undue delay. We adhere to this rule: if any information is found inaccurate in relation to its processing purposes and cannot be corrected, we will delete it promptly to prevent possible negative consequences.

Your cooperation is also crucial in maintaining accuracy: please inform us if any of your personal data has changed or needs correction. We appreciate your proactiveness, as accurate data is essential for effective service delivery and safeguarding your rights.

Storage Limitation

We store personal data for no longer than is necessary to achieve the purposes for which they were collected. This principle of storage limitation (Article 5(1)(e) of the GDPR) means that each category of data has a defined retention period, after which the information is securely deleted or anonymized. Here’s how we ensure this:

  • Clearly Defined Retention Periods: We establish reasonable retention periods for various types of personal data, considering processing purposes, our legal and contractual obligations, and applicable legal requirements. For example, transaction and accounting data is retained for the term required by Estonian tax and accounting law (generally seven years), whereas data collected for a one-time enquiry is kept for a shorter duration. All retention periods are reflected in our internal policies, and we strictly adhere to them.
  • Regular Reviews: We periodically review our data retention policies to ensure they remain current. If business processes change or laws are updated, we adjust data retention periods accordingly. Such audits help identify personal data that is no longer required. We conduct reviews to detect unused or outdated data and delete it if it is not needed for any lawful purpose.
  • Secure Deletion: Upon expiry of retention periods (or earlier, if data becomes unnecessary), we delete personal data in a way that makes it impossible to restore or identify. In some cases, if immediate deletion isn’t possible due to technical constraints, we first anonymize the data (separating it from your identity) and then delete it when feasible. We may also retain data beyond the established retention period only if permitted by law – for instance, if the data is retained for archival purposes in the public interest or for scientific or statistical purposes pursuant to Article 89(1) of the GDPR. Even in these cases, we ensure appropriate confidentiality safeguards.

By minimizing the retention period for personal data, we reduce the risk of data misuse or vulnerability to breaches over time. You can be assured that we do not retain your data longer than necessary and strictly comply with established timelines.

Integrity and Confidentiality

We take all measures to ensure the integrity and confidentiality of your personal data (Article 5(1)(f) of the GDPR), protecting it from unauthorized access, alteration, disclosure, or destruction. This principle of data security is implemented comprehensively – through both technical and organizational means. Here’s how we protect your data:

  • Modern Security Technologies: We apply appropriate technical security measures to protect personal information, including data encryption, firewalls, antivirus solutions, intrusion detection systems, and other cybersecurity tools. These measures are proportionate to the nature and volume of processed data and potential risks. For example, sensitive data may be stored encrypted, and access to systems containing personal data is strictly limited to authorized individuals. We regularly assess risks and update security measures to counter emerging threats. Our IT infrastructure is monitored for vulnerabilities, and we promptly install updates and patches to prevent incidents.
  • Organizational Measures and Access Control: Besides technology, we implement strict organizational rules for data handling. Access to your personal data is limited exclusively to employees or authorized persons who need it to perform their duties (principle of “least privilege”). Each employee acts within their authority and receives training on data security requirements. We enter into non-disclosure agreements (NDAs) with all employees and third-party contractors who may access information, legally binding them to maintain confidentiality. Regular training sessions and briefings on data protection best practices are conducted to ensure staff awareness of current threats and prevention strategies.
  • Incident Response and Monitoring: We have internal procedures in place for responding to security incidents. In the unlikely event of a personal data breach, we follow a response plan: from immediate vulnerability remediation to notifying the supervisory authority within 72 hours and informing affected data subjects where required by Articles 33 and 34 of the GDPR. We maintain records of all personal data incidents, analyzing their causes to prevent recurrence. Additionally, our security system is regularly audited – we conduct internal and external audits, penetration tests, and other assessments to ensure our security standards remain robust and up-to-date.

By adhering to this principle, we ensure that your personal data is stored and processed with high security standards. Data integrity ensures that information remains unchanged and accurate within the system, while confidentiality ensures that unauthorized individuals cannot access it. Together, these measures help us maintain a high level of trust and security.

Accountability

Eesti Firma OÜ fully acknowledges its responsibility for complying with GDPR principles and can demonstrate this compliance. The principle of accountability (Article 5(2) of the GDPR) means we not only adhere to the regulation but can also provide practical and documented evidence of our compliance. Here is how accountability is implemented in our company:

  • Built-in compliance: We have integrated GDPR requirements into all business processes. Every employee who handles personal data understands and adheres to data protection principles. We have clear policies and guidelines regulating data collection, use, transfer, and storage, and these documents are communicated to staff. GDPR principles are embedded into our corporate culture, ensuring consistently high standards of data management at all levels.
  • Designated Data Protection Officer: As part of our commitment to accountability, we have appointed a Data Protection Officer (DPO) – Ilja Nikiforov – whose contact details are provided below. The DPO monitors GDPR compliance within the company, advises our staff on privacy matters, and acts as a point of contact for you and for the supervisory authority. Having a dedicated DPO reflects the seriousness of our commitment to data protection.
  • Internal audits and risk assessments: We regularly conduct internal audits (and involve external auditors when necessary) to ensure our practices comply with GDPR requirements. Potential risks to security and privacy are analyzed, and corrective measures are taken based on audit findings. Where a type of processing is likely to result in a high risk to individuals, we carry out a Data Protection Impact Assessment (DPIA) in accordance with Article 35 of the GDPR. This continuous monitoring and improvement approach helps us keep data protection measures up-to-date and adapt swiftly to changes.
  • Training and awareness: We invest in employee education on data protection topics. Training sessions, newsletters, and knowledge assessments are periodically conducted to ensure everyone is informed of the latest industry developments and requirements. Data security significantly depends on individual actions, so we foster a culture in which everyone understands their role and responsibilities.
  • Readiness for reporting: At any moment, we are prepared to demonstrate GDPR compliance to you as well as supervisory authorities. Our transparency extends to this area: you may request information regarding your data, and we will provide all necessary details. Similarly, in the event of a supervisory audit, we have prepared documentation and processes that confirm our accountability. We recognize client trust depends directly on our accountability, making this principle a cornerstone of our operations.

Your Rights as a Data Subject

The GDPR grants you a range of rights over your personal data. We respect these rights and provide straightforward ways for you to exercise them. Subject to the conditions and exceptions set out in the GDPR, you have:

  • Right to be informed (Articles 13–14): to receive clear information about how and why your personal data is processed.
  • Right of access (Article 15): to obtain confirmation of whether we process your data and to receive a copy of it.
  • Right to rectification (Article 16): to have inaccurate or incomplete personal data corrected.
  • Right to erasure / “right to be forgotten” (Article 17): to request deletion of your data where there is no overriding lawful ground to keep it.
  • Right to restriction of processing (Article 18): to limit how we use your data in certain circumstances.
  • Right to data portability (Article 20): to receive the data you provided in a structured, commonly used, machine-readable format and to have it transferred where technically feasible.
  • Right to object (Article 21): to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Rights related to automated decision-making (Article 22): not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Right to withdraw consent (Article 7(3)): where processing is based on consent, to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint (Article 77): to contact the competent supervisory authority (see the section below).

To exercise any of these rights, please contact us using the details in the Contact Information section. We will respond within one month, as required by the GDPR. This period may be extended by up to two further months for complex or numerous requests, in which case we will inform you of the reasons. Handling your request is free of charge unless it is manifestly unfounded or excessive. We may need to verify your identity before acting on a request.

Supervisory Authority and the Right to Complain

If you believe we have processed your personal data in breach of data protection law, we encourage you to contact us first so we can address your concerns directly. You also have the right, under Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority. In Estonia, this is the Data Protection Inspectorate (Andmekaitse Inspektsioon):

  • Authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
  • Address: Tatari 39, 10134 Tallinn, Estonia
  • Email: [email protected]
  • Phone: +372 627 4135 (advisory line +372 5620 2341, Mon–Thu 13:00–16:00)
  • Website: www.aki.ee

If you reside or work in another EU/EEA country, you may alternatively lodge a complaint with the supervisory authority in that country.

Conclusion

Our fundamental commitment to protecting your privacy and maintaining your trust means GDPR compliance is more than a formality – it is integral to our daily operations. Adhering to all the principles mentioned above – lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, as well as accountability – ensures your personal data is processed in the most correct and secure manner possible. We go beyond legal requirements because we value your trust.

In keeping with the spirit of the GDPR, we continue to enhance our data protection practices and respond swiftly to changes in regulatory requirements. You can be confident your personal information is in safe hands, and we continuously work to ensure this remains true.

We reserve the right to periodically update or modify this document to reflect changes in our data processing practices, legislation, or regulatory requirements. All updates will be published on this page, and the date of the last revision will be updated accordingly. We recommend periodically reviewing this page to stay informed about the current version of our GDPR compliance principles.

Note

This document supplements our Privacy Policy and other related documents but does not replace them. In the event of any discrepancies, the Privacy Policy shall prevail. This document is for informational purposes and aims to clarify our approach to GDPR compliance.

Contact Information

If you have any questions, comments, or requests concerning personal data protection or how we process your information, please contact us. We are always ready to assist you and appreciate your feedback.

  • Company: Eesti Firma OÜ
  • Registration Code: 14164797
  • VAT Number (KMKR): EE102081480
  • Activity Licence (TCSP): FIU000144
  • Data Protection Officer (DPO): Ilja Nikiforov
  • Email: [email protected]
  • Phone: +372 641 7777
  • Address: Vesivärava 50-301, 10152 Tallinn, Estonia

We strive to respond promptly and comprehensively to all inquiries. If you request information about your data or the exercise of your rights, we will respond within the timeframe established by the GDPR (typically within one month). Thank you for entrusting Eesti Firma OÜ with your data protection – we, in turn, do everything possible to justify that trust.

These GDPR Compliance Principles were developed and approved by a lawyer, Data Protection Officer (DPO), and co-founder of Eesti Firma OÜ – Ilja Nikiforov, who oversees the company’s adherence to personal data protection laws and implements best compliance practices. The provisions of this document apply to every client of the company without exception. Should you have questions or require further clarification, please contact Eesti Firma support directly.