Short answer
In February 2021 the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) issued me a precept-warning in case no. 2.1.-6/21/4 over GDPR violations on my own finance websites. I met every requirement in 13 days, and on 18 March 2021 the Inspectorate closed the supervisory proceeding with a reprimand under Article 58(2)(b) GDPR — the mildest measure applied for an infringement that has already occurred. No fine, no court case.
The precept itself is publicly available and resurfaces from time to time. The trouble is that it is usually read halfway: people see the 20 million euros mentioned and draw a conclusion the document does not support. So I am going through the substance of the case: what happened, what I actually violated, how it ended, and what I took from it into my work.
Case timeline
| Date | What happened |
|---|---|
| 28.09.2020 | A private individual complained to the Inspectorate about their message being published on 44finance.com |
| 23.02.2021 | Precept-warning issued, compliance deadline 10.03.2021 |
| 08.03.2021 | I reported on both sites and on all 29 domains registered in my name |
| 09.03.2021 | Confirmed deletion of all collected personal data |
| 16.03.2021 | Sent a supplement to the report |
| 18.03.2021 | Proceeding closed, reprimand issued |
The closing decision puts it this way: "Tänaseks on Vladislav Krivorutško inspektsiooni ettekirjutuses toodud nõuded täitnud" — as of today the requirements of the precept have been met. And then: "Lähtuvalt eeltoodust lõpetame järelevalvemenetluse" — accordingly we close the supervisory proceeding.
About the closing document and why I do not publish it
The first document, the precept of 23.02.2021, carries no restriction. That is the one circulating online.
The second one — the very document stating "complied" and "we close" — is marked ASUTUSESISESEKS KASUTAMISEKS, for internal use, under section 35(1) points 2 and 12 of the Estonian Public Information Act (AvTS), restricted as to personal data until 18.03.2096. The restriction protects the complainant's data as well as mine.
I therefore give the letter's reference details — 18.03.2021, no. 2.1.-1/20/3467 — and quote individual passages concerning my own case, but do not publish the document in full. The official response from the Inspectorate exists; if needed, its authenticity can be verified by querying the Inspectorate with the case number.
What the precept does not say
Let me start with what gets assumed most often.
| Common reading | What the documents actually say |
|---|---|
| "Fined 20 million euros" | A quote of the Article 83 GDPR ceiling in a boilerplate warning block. No fine was imposed |
| "Fined 1,000 euros" | Sunniraha is a conditional measure: 1,000 euros per point, only if the precept was not complied with by 10.03.2021. It was complied with |
| "Criminal or misdemeanour case" | The text says "may be initiated". None was |
| "Found guilty in court" | There was no court case. This is an administrative act of a supervisory authority |
| "Fraud, data theft or data selling" | No such allegations appear anywhere in the documents. The case concerns GDPR transparency and minimisation requirements |
One more detail worth knowing: the precept was issued without hearing my explanations, under an expedited procedure — the Inspectorate cites section 40(3)(1) of the Administrative Procedure Act directly. I was not heard before the act was issued. That does not make the requirements any less justified, but it explains why the first document reads harsher than the final outcome of the case.
What I actually violated
Now the uncomfortable part, and I am not going to soften it. The Inspectorate states the basis for the reprimand verbatim: I collected personal data on the websites while the GDPR requirements went unmet — in particular, the sites lacked privacy terms compliant with Articles 12-14, from which the controller, its contact details, the purpose and the legal basis of processing would be apparent.
Three components.
1. No privacy policy, no owner's name, no working contacts
The most indisputable violation and entirely mine. A person who left their data on the site could not tell who was processing it and physically could not reach anyone to demand deletion. Judging by the case file, that is precisely what caused the complaint: the complainant simply could not find who to write to, and went to the regulator instead.
The obligation here is unconditional and no marketing consideration overrides it: the controller's name and working contact details are required by Article 13(1)(a) GDPR, and for a service provider also by section 4 of the Information Society Services Act — where the requirement applies even when no personal data is processed at all.
Today I build everything the other way round. The site you are reading runs under my name and face, with ADLAB OÜ registration details and a working email on the contacts page.
2. Publishing visitor messages together with their names
Both sites had visitor message texts publicly available and indexed, together with the senders' names. Some of them came from people in difficult circumstances and contained details of their personal and family situations. The Inspectorate noted separately that publishing such information also affects children's rights, and that the content of one message had already been republished by a third-party company on its own site.
There is nothing to fall back on here: those texts did not come with the domain and did not appear through oversight. The messages were published to the page automatically because that is how I designed the site — I thought an open feed of real enquiries showed the service was alive and inspired more trust than a page with no feedback at all. The intention was transparency; what it produced was the publication of personal data with no legal basis and no informed consent from the people involved.
The mistake was that I never thought of those messages as personal data at all. A name together with the text of an enquiry is personal data, and the decision to display it publicly required a legal basis, a way to withdraw it, and a warning at the moment of submission. None of that existed. At the Inspectorate's demand all comments were anonymised and the collected data deleted.
3. Collecting more data than was needed
The forms asked for considerably more fields than the stated purpose required: I sent offers by email only, yet collected a phone number among other things. The Inspectorate pointed to the minimisation principle in Article 5(1)(b) GDPR: an email address alone is normally sufficient, and a phone number is inherently superfluous when you deliver by email. Individual extra fields can be justified where they genuinely determine the outcome, but then it must be spelled out clearly in the privacy terms, with defined retention periods.
What the Inspectorate confirmed in my favour
Since I am going through the substance of the case, this belongs here too.
Affiliate links are lawful. The Inspectorate confirmed outright that linking to lending companies' websites is not prohibited — a comparison site is entitled to earn from affiliate programmes.
Rebuilding expired domains does not in itself breach GDPR. I asked directly whether the previous site's content may be used where no personal data is processed. The answer: "Kui isikuandmeid ei töödelda, siis IKÜM ka ei kohaldu" — if no personal data is processed, GDPR does not apply; assessment under other laws is outside the Inspectorate's competence. So the data protection regulator did not declare the practice unlawful. I did separately report that I had stopped putting sites up on someone else's content before the proceeding began.
The concern about the remaining domains was not borne out. The Estonian Internet Foundation told the Inspectorate that I register expired domains, and the Inspectorate considered it "doubtful" that my other sites complied with GDPR, requiring all 29 to be reviewed. I reviewed them and reported on each: most collected no personal data at all, some domains no longer worked or only redirected, and on the rest the forms were disabled and collected data deleted. The assumption remained an assumption.
Checklist: GDPR when rebuilding an expired domain
This is the part worth reading to the end if you work with expired domains. Everything below follows directly from my case.
- Open the web archive before buying the domain. Look past the backlink profile at whether there is user-generated content: comments, reviews, questions, applications, a forum. If there is, you are buying someone else's personal data along with the domain.
- Delete or anonymise user content before launch, not after. Controller responsibility begins the moment the page becomes reachable on your domain. "The content was there before me" is not a legal basis.
- Do not publish incoming enquiries on the site automatically. A "live feed of requests" looks convincing and builds trust, but a name together with the text of an enquiry is personal data. Publishing it requires its own legal basis, a warning at the moment of submission, and a way to withdraw the message. If you really need social proof, publish it anonymised and without details that could identify the person.
- Disable or remove every form you do not intend to service. A broken form that still accepts something is data collection without a basis and without notice.
- Publish privacy terms before collection starts, not after the first lead. Article 13 GDPR requires the person to understand, at the moment of entry, who the controller is, on what basis, for what purpose and for how long.
- Name yourself. The controller's name and working contact details are mandatory. Under section 4 of the Information Society Services Act, a service provider states its name and contacts even where no personal data is processed at all.
- Collect exactly as many fields as the stated purpose requires. If you deliver by email, you do not need a phone number. Every additional field must be defensible.
- Set up a working channel for deletion requests and actually answer it. A person must be able to demand deletion at any time, even if they knew when writing that the message would be published.
- Do not create the impression that you provide a service you do not provide. A comparison site is a comparison site, and it should say so in plain words.
A separate word on rebuilt domains. I still work with them and consider them a perfectly normal instrument. But since 2021, checking for someone else's personal data is the first thing I do after buying a domain — before I even look at its SEO metrics.
What changed in my work
Without any pathos, only the verifiable.
All my projects and all client projects launch today with a privacy policy, a named owner and working contacts. Forms carry explicit consent to the data processing terms — as a separate checkbox, not fine print under the button, and never pre-ticked: in my teardown of Estonian affiliate sites I found a form where all three consent boxes were checked by default — exactly the same mistake, only on a site that does not know it yet. User-generated content on rebuilt domains is checked before launch, not after a complaint.
On the matter of the name specifically. Today my entire business is built on public authorship: I work alone, under my own name, and clients can see exactly who they are dealing with. That turned out to be an asset rather than a cost — including for SEO, because search engines have shifted noticeably towards verifiable authorship in the years since.
I would put the main lesson from this case like this: when the regulator is right, there is nothing to argue about. The requirements were justified on the merits, so I did not file a challenge or play for time — I fixed everything in 13 days against a 15-day deadline, and clarified what I did not understand along the way. The proceeding lasted under a month precisely because it never became a dispute.
I would prefer this story did not exist. But since it does and it is findable in search, telling it myself and with my own conclusions is more honest than hoping nobody reads it. And my mistake produced a checklist that will save someone considerably more than this proceeding cost me.
