Discuss project

Case 2.1.-6/21/4: the data protection precept and how it ended

The Estonian Data Protection Inspectorate precept in case 2.1.-6/21/4: what I violated, what I fixed, and why the case closed with a reprimand.

Vladislav KrivorutskoJuly 19, 202611 min read
Contents

TL;DR - key points

  • On 23.02.2021 the Estonian Data Protection Inspectorate issued me a precept-warning in case no. 2.1.-6/21/4 over GDPR violations on my own finance websites intral.ee and 44finance.com
  • I met every requirement in 13 days against a 10.03.2021 deadline, reporting on each of the 29 domains registered in my name
  • On 18.03.2021 the Inspectorate closed the supervisory proceeding and issued a reprimand — the mildest measure applied for an infringement that has already occurred
  • There was no fine, no court case, no misdemeanour proceeding. The 20,000,000 euros mentioned in the precept is a quote of the Article 83 GDPR ceiling in a boilerplate warning, not an amount imposed
  • The core violation was not technical: the sites had no privacy policy, no named controller and no working contacts, and visitor messages were published together with their names

Short answer

In February 2021 the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) issued me a precept-warning in case no. 2.1.-6/21/4 over GDPR violations on my own finance websites. I met every requirement in 13 days, and on 18 March 2021 the Inspectorate closed the supervisory proceeding with a reprimand under Article 58(2)(b) GDPR — the mildest measure applied for an infringement that has already occurred. No fine, no court case.

The precept itself is publicly available and resurfaces from time to time. The trouble is that it is usually read halfway: people see the 20 million euros mentioned and draw a conclusion the document does not support. So I am going through the substance of the case: what happened, what I actually violated, how it ended, and what I took from it into my work.

Case timeline

DateWhat happened
28.09.2020A private individual complained to the Inspectorate about their message being published on 44finance.com
23.02.2021Precept-warning issued, compliance deadline 10.03.2021
08.03.2021I reported on both sites and on all 29 domains registered in my name
09.03.2021Confirmed deletion of all collected personal data
16.03.2021Sent a supplement to the report
18.03.2021Proceeding closed, reprimand issued

The closing decision puts it this way: "Tänaseks on Vladislav Krivorutško inspektsiooni ettekirjutuses toodud nõuded täitnud" — as of today the requirements of the precept have been met. And then: "Lähtuvalt eeltoodust lõpetame järelevalvemenetluse" — accordingly we close the supervisory proceeding.

About the closing document and why I do not publish it

The first document, the precept of 23.02.2021, carries no restriction. That is the one circulating online.

The second one — the very document stating "complied" and "we close" — is marked ASUTUSESISESEKS KASUTAMISEKS, for internal use, under section 35(1) points 2 and 12 of the Estonian Public Information Act (AvTS), restricted as to personal data until 18.03.2096. The restriction protects the complainant's data as well as mine.

I therefore give the letter's reference details — 18.03.2021, no. 2.1.-1/20/3467 — and quote individual passages concerning my own case, but do not publish the document in full. The official response from the Inspectorate exists; if needed, its authenticity can be verified by querying the Inspectorate with the case number.

What the precept does not say

Let me start with what gets assumed most often.

Common readingWhat the documents actually say
"Fined 20 million euros"A quote of the Article 83 GDPR ceiling in a boilerplate warning block. No fine was imposed
"Fined 1,000 euros"Sunniraha is a conditional measure: 1,000 euros per point, only if the precept was not complied with by 10.03.2021. It was complied with
"Criminal or misdemeanour case"The text says "may be initiated". None was
"Found guilty in court"There was no court case. This is an administrative act of a supervisory authority
"Fraud, data theft or data selling"No such allegations appear anywhere in the documents. The case concerns GDPR transparency and minimisation requirements

One more detail worth knowing: the precept was issued without hearing my explanations, under an expedited procedure — the Inspectorate cites section 40(3)(1) of the Administrative Procedure Act directly. I was not heard before the act was issued. That does not make the requirements any less justified, but it explains why the first document reads harsher than the final outcome of the case.

What I actually violated

Now the uncomfortable part, and I am not going to soften it. The Inspectorate states the basis for the reprimand verbatim: I collected personal data on the websites while the GDPR requirements went unmet — in particular, the sites lacked privacy terms compliant with Articles 12-14, from which the controller, its contact details, the purpose and the legal basis of processing would be apparent.

Three components.

1. No privacy policy, no owner's name, no working contacts

The most indisputable violation and entirely mine. A person who left their data on the site could not tell who was processing it and physically could not reach anyone to demand deletion. Judging by the case file, that is precisely what caused the complaint: the complainant simply could not find who to write to, and went to the regulator instead.

The obligation here is unconditional and no marketing consideration overrides it: the controller's name and working contact details are required by Article 13(1)(a) GDPR, and for a service provider also by section 4 of the Information Society Services Act — where the requirement applies even when no personal data is processed at all.

Today I build everything the other way round. The site you are reading runs under my name and face, with ADLAB OÜ registration details and a working email on the contacts page.

2. Publishing visitor messages together with their names

Both sites had visitor message texts publicly available and indexed, together with the senders' names. Some of them came from people in difficult circumstances and contained details of their personal and family situations. The Inspectorate noted separately that publishing such information also affects children's rights, and that the content of one message had already been republished by a third-party company on its own site.

There is nothing to fall back on here: those texts did not come with the domain and did not appear through oversight. The messages were published to the page automatically because that is how I designed the site — I thought an open feed of real enquiries showed the service was alive and inspired more trust than a page with no feedback at all. The intention was transparency; what it produced was the publication of personal data with no legal basis and no informed consent from the people involved.

The mistake was that I never thought of those messages as personal data at all. A name together with the text of an enquiry is personal data, and the decision to display it publicly required a legal basis, a way to withdraw it, and a warning at the moment of submission. None of that existed. At the Inspectorate's demand all comments were anonymised and the collected data deleted.

3. Collecting more data than was needed

The forms asked for considerably more fields than the stated purpose required: I sent offers by email only, yet collected a phone number among other things. The Inspectorate pointed to the minimisation principle in Article 5(1)(b) GDPR: an email address alone is normally sufficient, and a phone number is inherently superfluous when you deliver by email. Individual extra fields can be justified where they genuinely determine the outcome, but then it must be spelled out clearly in the privacy terms, with defined retention periods.

What the Inspectorate confirmed in my favour

Since I am going through the substance of the case, this belongs here too.

Affiliate links are lawful. The Inspectorate confirmed outright that linking to lending companies' websites is not prohibited — a comparison site is entitled to earn from affiliate programmes.

Rebuilding expired domains does not in itself breach GDPR. I asked directly whether the previous site's content may be used where no personal data is processed. The answer: "Kui isikuandmeid ei töödelda, siis IKÜM ka ei kohaldu" — if no personal data is processed, GDPR does not apply; assessment under other laws is outside the Inspectorate's competence. So the data protection regulator did not declare the practice unlawful. I did separately report that I had stopped putting sites up on someone else's content before the proceeding began.

The concern about the remaining domains was not borne out. The Estonian Internet Foundation told the Inspectorate that I register expired domains, and the Inspectorate considered it "doubtful" that my other sites complied with GDPR, requiring all 29 to be reviewed. I reviewed them and reported on each: most collected no personal data at all, some domains no longer worked or only redirected, and on the rest the forms were disabled and collected data deleted. The assumption remained an assumption.

Checklist: GDPR when rebuilding an expired domain

This is the part worth reading to the end if you work with expired domains. Everything below follows directly from my case.

  1. Open the web archive before buying the domain. Look past the backlink profile at whether there is user-generated content: comments, reviews, questions, applications, a forum. If there is, you are buying someone else's personal data along with the domain.
  2. Delete or anonymise user content before launch, not after. Controller responsibility begins the moment the page becomes reachable on your domain. "The content was there before me" is not a legal basis.
  3. Do not publish incoming enquiries on the site automatically. A "live feed of requests" looks convincing and builds trust, but a name together with the text of an enquiry is personal data. Publishing it requires its own legal basis, a warning at the moment of submission, and a way to withdraw the message. If you really need social proof, publish it anonymised and without details that could identify the person.
  4. Disable or remove every form you do not intend to service. A broken form that still accepts something is data collection without a basis and without notice.
  5. Publish privacy terms before collection starts, not after the first lead. Article 13 GDPR requires the person to understand, at the moment of entry, who the controller is, on what basis, for what purpose and for how long.
  6. Name yourself. The controller's name and working contact details are mandatory. Under section 4 of the Information Society Services Act, a service provider states its name and contacts even where no personal data is processed at all.
  7. Collect exactly as many fields as the stated purpose requires. If you deliver by email, you do not need a phone number. Every additional field must be defensible.
  8. Set up a working channel for deletion requests and actually answer it. A person must be able to demand deletion at any time, even if they knew when writing that the message would be published.
  9. Do not create the impression that you provide a service you do not provide. A comparison site is a comparison site, and it should say so in plain words.

A separate word on rebuilt domains. I still work with them and consider them a perfectly normal instrument. But since 2021, checking for someone else's personal data is the first thing I do after buying a domain — before I even look at its SEO metrics.

What changed in my work

Without any pathos, only the verifiable.

All my projects and all client projects launch today with a privacy policy, a named owner and working contacts. Forms carry explicit consent to the data processing terms — as a separate checkbox, not fine print under the button, and never pre-ticked: in my teardown of Estonian affiliate sites I found a form where all three consent boxes were checked by default — exactly the same mistake, only on a site that does not know it yet. User-generated content on rebuilt domains is checked before launch, not after a complaint.

On the matter of the name specifically. Today my entire business is built on public authorship: I work alone, under my own name, and clients can see exactly who they are dealing with. That turned out to be an asset rather than a cost — including for SEO, because search engines have shifted noticeably towards verifiable authorship in the years since.

I would put the main lesson from this case like this: when the regulator is right, there is nothing to argue about. The requirements were justified on the merits, so I did not file a challenge or play for time — I fixed everything in 13 days against a 15-day deadline, and clarified what I did not understand along the way. The proceeding lasted under a month precisely because it never became a dispute.

I would prefer this story did not exist. But since it does and it is findable in search, telling it myself and with my own conclusions is more honest than hoping nobody reads it. And my mistake produced a checklist that will save someone considerably more than this proceeding cost me.

Frequently asked questions

Was Vladislav Krivorutsko fined by the Data Protection Inspectorate?
No. The supervisory proceeding in case no. 2.1.-6/21/4 was closed on 18.03.2021 with a reprimand under Article 58(2)(b) GDPR. That is the mildest measure a supervisory authority applies for an infringement that has already occurred. No administrative fine under Article 83 GDPR was imposed, no penalty payment was collected, and no misdemeanour proceeding was initiated.
Where does the 20,000,000 euro figure in the document come from?
It is boilerplate the Estonian Inspectorate includes in every precept: it quotes the maximum penalties set out in Article 83 GDPR and section 70 of the Estonian Personal Data Protection Act, applicable if the precept is not complied with. It has no bearing on my case — the precept was complied with on time and no fine was imposed.
What exactly was violated?
Three things. The sites intral.ee and 44finance.com lacked privacy terms compliant with Articles 12-14 GDPR: the controller, its contact details, the purpose and the legal basis of processing were not stated. Visitor messages were publicly available together with their names. And more data was collected than the stated purpose required, which breaches the data minimisation principle in Article 5(1)(b).
Was the precept appealed?
No. I had 30 days to file a challenge with the Inspectorate or an appeal with the Tallinn Administrative Court. I did not use that right: the requirements were substantively justified and complying was more sensible than arguing. The proceeding was closed before the appeal period expired.
Is it legal to register expired domains and reuse the previous site's content?
Asked directly, the Inspectorate replied that GDPR does not apply where no personal data is processed, and that assessing the practice under other laws falls outside its competence. So the data protection regulator did not find the practice unlawful in itself. However, the moment a rebuilt site retains someone else's user-generated content with names, or runs a form, you become the controller with every GDPR obligation attached, and 'the content came with the domain' is not a defence.
Can the case documents be reviewed?
The precept of 23.02.2021 carries no access restriction — that is the one circulating online. The closing letter of 18.03.2021, which terminates the proceeding and issues the reprimand, is marked FOR INTERNAL USE (ASUTUSESISESEKS KASUTAMISEKS) under section 35(1)(2) and (12) of the Estonian Public Information Act, restricted as to personal data until 18.03.2096. I therefore quote key wording and cite the reference details — dated 18.03.2021, no. 2.1.-1/20/3467 — but do not publish the document in full.

Conclusion

This is the most uncomfortable article on my blog, which is exactly why it is here. In 2021 I ran my own finance websites without stopping to consider that an ordinary feedback form made me a data controller with every obligation that entails. I complied, the case closed with a reprimand, and since then no project of mine or my clients' launches without a privacy policy, a named owner and working contacts. If you rebuild expired domains or collect leads on your site, read the checklist section — it is written from my mistakes and it is cheaper than repeating them.

About the author

Vladislav Krivorutsko — founder of ADLAB
Vladislav Krivorutsko

Founder of ADLAB OÜ · SEO and Google Ads

Over 20 years in search traffic and monetization, and on the Estonian market since 2017. I work solo: I run the audit, build the strategy and deliver the project myself — no subcontractors, no templates. I only write about what I have tested on my own and client sites.

  • 20+ years in search traffic
  • 50+ end-to-end projects
  • Own sites in competitive niches
  • SEO for ru/et/en in one market
More about me

Read next