GDPR Compliance

Last updated: July 24, 2026

eBusiness Solutions OÜ processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act.

This page explains how the seven principles of Article 5 of the GDPR are applied in the daily operations of a licensed corporate service provider, what rights you possess as a data subject, and how to exercise them. It also explicitly clarifies a question clients ask most frequently: why certain data cannot be erased upon request—even if explicitly demanded—and on what statutory grounds.

Specific processing activities (which exact data categories are collected, from whom, for what purpose, and to whom they are transferred) are detailed in our [Privacy Policy]. This document explains the core principles and serves to complement, rather than replace, that policy.

1. Who Is the Controller of Your Data?

ParameterValue
Legal NameeBusiness Solutions OÜ
Registry Code16618432
VAT Number (KMKR)EE102672239
TCSP LicenceFIU000421
Registered AddressTornimäe tn 7-169, 10145 Tallinn, Estonia
Data Protection Supervisory AuthorityEstonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

Key distinction in our operations:

In certain processes, we act as a Data Controller (when we determine the purposes of processing: entering into a contract with you, conducting KYC checks, marketing). In other processes, we act as a Data Processor (when we maintain bookkeeping for your company and process personal data of your employees and counterparties on your instructions). In the second scenario, you determine the processing purposes, and our relationship is governed by a separate Data Processing Agreement (DPA). This document outlines our role exclusively as a Data Controller.

2. The Seven Article 5 GDPR Principles in Practice

2.1. Lawfulness, Fairness, and Transparency

We process data only when at least one legal basis under Article 6 GDPR applies. In our operations, four primary legal bases are utilized:

Legal BasisApplicable Circumstance
Performance of a Contract (Art. 6(1)(b))Service delivery: registered office address, contact person, company registration, accounting.
Legal Obligation (Art. 6(1)(c))Client identification and verification under RahaPTS, sanctions screening, regulatory reporting.
Legitimate Interests (Art. 6(1)(f))System security, website analytics, fraud prevention.
Consent (Art. 6(1)(a))Newsletters, marketing communications, non-essential cookies.

This breakdown is not a mere technicality: your rights directly depend on the legal basis invoked. Data processed under a Legal Obligation cannot be erased upon your demand, whereas data processed based on Consent can be withdrawn at any time.

Transparency for us means specific, clear disclosures rather than vague statements. We state precisely which data categories we collect, on what basis, and for what retention periods, providing advance notice if additional documents are needed to deliver a service.

2.2. Purpose Limitation

Data collected for one purpose is not reused for another incompatible purpose.

Practical industry example: Documents provided to pass KYC compliance checks (passport copies, proof of source of funds, ownership diagrams) are used strictly for compliance and disclosure to supervisory authorities upon their lawful request. They are never entered into marketing databases, used to formulate commercial offers, or shared with third parties for advertising purposes.

If a new processing purpose arises, we will either obtain explicit consent or establish another lawful basis—notifying you prior to initiating processing.

2.3. Data Minimization

We request only the volume of data strictly necessary for a specific service, proportionate to the client’s assigned risk profile.

In practice, requested documentation varies: for a dormant company’s zero annual report, requirements are minimal; for a client operating with crypto-assets or complex corporate layers, documentation requirements are significantly broader as mandated by the risk-based approach under RahaPTS. We do not collect documents “just in case” and justify every request with a specific legal or operational necessity.

If it is unclear why a specific document is requested, you have the right to request—and receive—a formal explanation.

2.4. Accuracy

Inaccurate data in our field carries direct consequences: an error in a board member’s personal data submitted to the Commercial Register leads to application rejection, while an outdated address risks missing statutory notices.

Therefore, we periodically request confirmation of data accuracy (also mandated by ongoing AML monitoring rules), promptly apply updates upon your notification, and verify details against public registers where appropriate.

Your cooperation is essential: please inform us immediately of changes to contact details, board composition, ownership structures, or business operations. This ensures both service quality and regulatory compliance.

2.5. Storage Limitation

A specific retention period is assigned to each data category, after which data is securely erased or anonymized:

CategoryRetention PeriodStatutory / Legal Basis
KYC/AML Records & Client Screening Data5 years after termination of business relationshipMoney Laundering and Terrorist Financing Prevention Act (RahaPTS)
Accounting Files & Primary Vouchers7 years from the end of the financial yearEstonian Accounting Act (Raamatupidamise seadus)
Contracts & Business Correspondence3 years after contract terminationGeneral statutory limitation period under civil law
Consent-based Data (Marketing)Until consent is revokedArt. 6(1)(a) GDPR
Inquiries Not Leading to ContractGenerally up to 12 monthsLegitimate interest

Retention periods may only be extended in explicitly defined statutory cases—such as by order of a supervisory authority or during active litigation.

2.6. Integrity and Confidentiality

  • Technical Measures: Encryption of transmission channels and storage of sensitive documents, access rights management, automated backups, infrastructure security, and patch monitoring.

  • Organizational Measures: Access to client data is restricted exclusively to personnel requiring it for service execution; all employees and contractors operate under strict Non-Disclosure Agreements (NDAs); personnel undergo routine data protection training.

  • Incident Response: In the event of a personal data breach, we follow internal incident protocols: mitigating the cause, assessing risks, notifying the Data Protection Inspectorate within 72 hours (Art. 33 GDPR), and informing affected data subjects if the risk to their rights is high (Art. 34 GDPR).

2.7. Accountability

The principle under Article 5(2) GDPR requires not only complying with rules, but being able to demonstrate compliance. To ensure accountability, we maintain:

  • A formal Record of Processing Activities (Art. 30 GDPR);

  • Internal Data Protection and AML/CFT Procedure Manuals;

  • Data Processing Agreements (DPAs) with sub-processors having data access;

  • Data Protection Impact Assessments (DPIAs) for high-risk processing operations (Art. 35 GDPR);

  • Periodic internal audits of processing workflows and retention schedules.

3. When GDPR and AML Legislation Conflict

This is the most frequent practical question raised by corporate service clients.

The right to erasure is not absolute. Article 17(3)(b) GDPR explicitly provides that the right to erasure does not apply where processing is necessary for compliance with a legal obligation to which the controller is subject.

Documents collected during Customer Due Diligence (CDD) procedures must be retained for 5 years following the termination of a business relationship under RahaPTS. This means:

  1. Requests for erasure of such compliance records will be refused—citing the statutory legal obligation;

  2. Instead of erasure, restriction of processing applies: data is stored securely but cannot be processed for any operational purpose other than legal compliance;

  3. Upon expiry of the statutory 5-year retention period, data is automatically deleted without requiring a separate request.

Similarly, the tipping-off prohibition under AML laws overrides GDPR disclosure obligations: if a Suspicious Activity Report (SAR) regarding a transaction is submitted to the Financial Intelligence Unit, the law strictly prohibits us from informing the client. In such scenarios, the data subject’s right to information under GDPR is limited by direct statutory provisions.

4. Your Rights as a Data Subject

Subject to the conditions and exceptions established under the GDPR, you possess the following rights:

RightArticleDescription
Right to be Informed13–14To know what data is processed, for what purposes, and on what legal grounds.
Right of Access15To receive confirmation of processing and obtain a copy of your personal data.
Right to Rectification16To correct inaccurate or complete incomplete personal data.
Right to Erasure17To request data erasure in the absence of a legal basis for retention (see Section 3).
Right to Restriction18To temporarily pause data processing under specific legal conditions.
Right to Portability20To receive provided data in a structured, machine-readable format or transfer it to another controller.
Right to Object21To object to processing based on legitimate interests; object to direct marketing unconditionally at any time.
Automated Decisions22To request human review, express your point of view, and contest automated outcomes.
Withdrawal of Consent7(3)To revoke consent at any time without affecting the lawfulness of prior processing.
Right to Lodge Complaint77To submit a complaint to a supervisory authority (see Section 6).

5. How to Exercise Your Rights

To exercise any of your rights, submit a written request using the contact details in Section 7.

  • Identity Verification: Before disclosing data, we must verify that the request originates from you to prevent unauthorized data exposure. For active clients, an email sent from a registered address or a qualified electronic signature is sufficient.

  • Response Timeline: Within 1 month of receipt (Art. 12(3) GDPR). For complex or high-volume requests, this period may be extended by an additional two months with prior notification explaining the delay.

  • Cost: Requests are handled free of charge, unless requests are manifestly unfounded, excessive, or repetitive.

  • Refusals: If a request is declined, we state the precise statutory legal basis and outline appeal options, including your right to lodge a complaint with supervisory authorities.

6. Supervisory Authority and Right to Lodge a Complaint

If you believe your privacy rights have been infringed, we encourage you to contact us first—most matters can be resolved directly and promptly. You also retain the right to lodge a complaint with the supervisory authority:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

  • Address: Tatari 39, 10134 Tallinn, Estonia

  • Email: info@aki.ee

  • Website: www.aki.ee

If you reside or work in another EU/EEA member state, you may lodge a complaint with your local national data protection authority.

7. Contact Details

  • Company Name: eBusiness Solutions OÜ

  • Registry Code: 16618432

  • TCSP Licence: FIU000421

  • Email: info@legaladdressinestonia.com

  • Phone: +372 5691 0000

  • Address: Tornimäe tn 7-169, 10145 Tallinn, Estonia

  • Website: legaladdressinestonia.com (also legaladdress.ee)

8. Relationship to Other Documents

This document is explanatory in nature and complements, but does not replace:

  • [Privacy Policy] — details specific data processing operations;

  • [AML/CFT Policy] — details Customer Due Diligence measures;

  • [Cookie Policy] — details tracking technologies and cookie usage.

In the event of any conflict between this document and the [Privacy Policy], the terms of the Privacy Policy shall prevail.

9. Amendments

We update this page periodically to reflect changes in legislation, regulatory guidance, or internal compliance protocols. The active version is published on this page displaying the latest revision date.