Field Notes

source

Data tracker

The Estonian Information System Authority’s page describing the Data Tracker (andmejälgija), the arrangement by which a person logged in to the eesti.ee state portal sees which public-sector databases handled their personal data. The saved copy is a text extraction taken through pure.md after the origin returned HTTP 403 to a direct fetch, so unlike the other captures in this set it has no .raw.html companion and preserves the page’s wording rather than its markup.

What the page establishes

The Data Tracker is a protocol rather than an application. RIA publishes a specification and supplies each database owner with a protocol for submitting usage information; the owner then implements the corresponding X-Road service itself. Uniformity is the reason RIA gives for insisting on the specification: every register’s log has to arrive in the same shape for eesti.ee to display them together. Implementation therefore requires X-Road membership, and the technical solution was funded through the European Regional Development Fund.

RIA grounds the service in the subject’s existing right under the GDPR and the Estonian Personal Data Protection Act to an overview of the operations performed on their data, and addresses it to public-sector systems that store and process personal data.

The benefits it claims divide by audience, and the split is worth reading:

Audience What RIA promises
The citizen A current overview of operations on their personal data, in one place, and a way to help monitor its use
The implementing register No new software to build, a lighter burden answering access requests, an internal-auditor view of internal queries, and increased citizen trust

The implementer’s column is a cost argument. RIA sells subject-visible logging partly as a cheaper way to discharge a duty the register already owes, which is a more durable adoption incentive than an appeal to transparency.

Limitations

This is the operator’s description of its own service, and it establishes the architecture rather than its reach. The page does not say which registers have implemented the tracker, how many have not, when it went live, what a logged entry actually records, or how long entries are retained. Coverage is the load-bearing question a page like this cannot answer: a transparency surface some registers implement and others do not tells a subject nothing about the ones that stayed out, and the tracker’s silence is indistinguishable from a register that never adopted it. The page carries a last-updated date of 30 April 2026.

Claims the wiki attaches to the tracker beyond this page — its arrival on eesti.ee in 2017, the logging duty in § 36 of the Estonian Personal Data Protection Act, and the 2025-26 bill extending adoption across nearly all public databases holding personal data — rest on the sources cited alongside it, not on this one.

Significance for the wiki

Grounds the Estonian instance in Access-transparency: a state that runs a universal identifier and total e-government while logging queries against the subject’s data and showing the log to the subject. Anchors the Estonian row of Public-by-default identity in international comparison, where it marks the architecture that inverts Sweden’s — exposing who looked rather than what they looked at.

Built on 1 source (1 external).

Working out connections…