It is becoming increasingly clear that technological development is moving faster than society’s ability to consider its potential impact fully. On the one hand, new technologies make our lives more convenient. For example, artificial intelligence can help identify risks, cameras can help prevent theft, and the state has increasingly more opportunities to automate services. On the other hand, this development means that more data about us is being collected, combined and analysed than ever before. As AI agents become increasingly autonomous, so does the risk that these capabilities may be used in ways that people themselves can no longer fully control. Recent cases show that as AI systems develop, increasing attention must be paid to their security, controllability and potential misuse. Read more here.
How much should the state know about us?
One of the most significant data protection issues this summer was the extensive collection of mobile communications metadata. Attorney-at-law Silver Reinsaar’s legal battle once again brought into focus how far the state may go in collecting and using metadata stored by mobile operators. Metadata does not reveal the content of a conversation, but it can be used to infer where a person moves, whom they communicate with and what their daily habits are. What may technically appear to be mere metadata can therefore quickly become a highly detailed picture of a person’s life.
A similar question arises in surveillance involving people who are not themselves the targets of an investigation. Information collected or disclosed about one person can very quickly reveal details about people around them, including individuals who have done nothing wrong and have not sought public attention. This is particularly important in the case of victims, because their experiences should not become public simply because they have been recorded in the course of an investigation or included in a court judgment. The example of Malluka’s website illustrates clearly how information compiled from publicly available court judgments and made easily searchable can very quickly lead to the identification of a victim and details of their private life. The fact that information is formally public does not automatically mean that its widespread dissemination, stripped of context, is justified from the perspective of a person’s rights.
This reflects one of the central principles of data protection: the fact that data can be collected does not mean that it may be collected in every possible situation or without limits. Processing must be necessary, purpose-specific, lawful and proportionate, and there must be effective mechanisms for oversight.
If data exists, should it also be accessible?
The same question arose in relation to health data. Attorney-at-law Carri Ginter drew attention to problems concerning officials’ access to people’s sensitive health information. This raised the question of whether such queries are sufficiently controllable and transparent, and whether people can find out at all that their data has been accessed.
The issue also concerns other highly personal data. For example, an experiment by Geenius and Delfi TV showed that the Estonian Population Register allows users to view the names and personal identification codes of mothers of newborn children, including women who had not publicly announced that they had become mothers or shared the information on social media. This demonstrates that even information that is seemingly lawfully accessible can be unexpectedly revealing for the person concerned. The question is not merely whether data may be accessed, but also who is accessing it, why they are doing so, and whether the individual can exercise any control over that access.
A similar contradiction has emerged in relation to financial data. Olavi Lepp, CEO of Swedbank, has pointed out that the state has electronic access to people’s bank account data, while the bank itself has no overview of who accesses this data, when they do so, or how it is used. On the one hand, banks have an obligation to protect their customers’ banking secrecy and personal data; on the other hand, the state has direct access to this information, over which the bank has no meaningful control.
The existence of data and access to it should not mean a loss of control. This is an important reminder for companies as well. Technical access does not automatically confer the right to use data. A well-designed system should be able to answer three questions: who has access, why do they need it, and can that use be audited afterwards? Secure storage alone is not enough. It is equally important to ensure that data is used only for a justified purpose and only by those who have a genuine need to access it.
Who is responsible when an algorithm makes the decision?
A recurring theme in many of this summer’s discussions was artificial intelligence. AI is increasingly entering different areas of life. It is being used, for example, in financial decision-making, retail video surveillance, marketing and creative work. The capabilities of AI are undoubtedly significant, but it is equally important to consider in which situations human decision-making authority and control must remain. As AI agents become more autonomous, the question of how reliably we can keep their activities within predefined boundaries becomes increasingly important.
In the financial sector, a case came to public attention in which a system identified risks when assessing a loan application from a pensioner, but those warnings were not followed by sufficient human oversight. This example illustrates that having a risk model is not enough. When an algorithm identifies a potential problem, it must be followed by meaningful assessment and, where necessary, human intervention.
The same principle applies to video surveillance systems used in retail. AI can help identify anomalies or suspicious behaviour, but using the technology does not remove the requirements of data protection law. The situation becomes particularly sensitive when biometric identification is involved. The greater the impact of a decision on an individual, the more important it is that the final assessment and responsibility remain with a human. This can be described as the human-in-the-loop principle: technology may assist decision-making, but it cannot take responsibility away from people. This is especially important where a decision may have a significant impact on a person’s well-being or health.
AI is also changing what privacy means to us
The impact of artificial intelligence is not limited to systems used by organisations. One of the summer’s most striking cases showed how easily a publicly shared photograph can take on an entirely new life in the age of AI. Photographs of a schoolgirl posted in a sales advertisement were stolen and used to create intimate deepfakes with AI, which were then distributed under her name. This case is a reminder that social media privacy settings, thoughtful sharing of photographs and awareness of what personal material is publicly available are becoming increasingly important.
A similar issue arose in the creative sector, where artists’ faces were altered using AI without their prior consent. When a person’s face, voice or other identifying material is used, data protection concerns do not simply disappear because the processing is carried out using artificial intelligence. AI does not make our rights disappear, but it does make them increasingly difficult to protect.
Digital sovereignty is also a data protection issue
From a broader perspective, data protection is not only about individuals’ personal data. It also concerns how much control Estonia has over its own digital infrastructure. An analysis by the Cybersecurity Commission of the Estonian Academy of Sciences highlighted the need to assess not only the reliability of IT systems, but also our dependence on major technology and cloud service providers and the impact of artificial intelligence on society.
When critical services and data depend on a small number of technology providers, the issue is no longer simply one of cybersecurity. It also concerns Estonia’s digital independence and its ability to make autonomous decisions about its data and critical infrastructure. As reliance grows on individual technology providers, the more important it is to assess the risks that could arise if a provider changes its terms, a service becomes unavailable, or access to data is disrupted. The strength of a digital state lies not only in functioning technological solutions, but also in maintaining sufficient control over them and preserving trust.
Five principles to take away from the summer
All of these cases may seem very different, but together they allow us to formulate a few simple principles that apply to governments, companies and individuals alike.
1. Collect only what you genuinely need.
The technical possibility of collecting data is not, in itself, a sufficient reason to do so.
2. Know who has access to your data.
Access must be justified, limited and auditable afterwards.
3. Keep people involved in important decisions.
When an algorithm assesses risks or makes decisions, a human must review the outcome, especially when it impacts a person’s rights or life.
4. Be transparent.
People must be able to understand what data about them is being used and why.
5. Think one step further before publishing.
A photograph or other personal information published online can, in the age of AI, spread and acquire new uses in ways the person who published it could never have anticipated.
The examples discussed here are not really only about technology. They are about trust. We do not have to choose between innovation and privacy. The question is under what conditions we use innovation and what boundaries we set. The same applies to the state. Greater capacity to collect and use data should not mean greater powers at the expense of people’s privacy. The convenience of surveillance and access to data must not override fundamental rights. Trust in a digital society emerges when technological and state capabilities go hand in hand with clear boundaries, transparency, accountability and respect for people’s rights.
Is the processing of data necessary? Can people understand what is happening to their data? Is there human oversight of system decisions? Can access to data be audited afterwards, and who is responsible when an algorithm makes a decision? These questions will become increasingly important in the years ahead. Trust in a digital society does not come simply from technology working. Trust comes when technology works while also respecting people’s rights.