Bailiff Rannar Liitmaa – Complaint Upheld (Estonia, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Estonian Data Protection Authority upheld a complaint against bailiff Rannar Liitmaa for not providing requested personal data. The bailiff failed to explain why the data could not be disclosed, which is required by law. This case shows that service providers must be transparent when handling personal data requests.
What happened
A person asked bailiff Rannar Liitmaa for information about their personal data but did not receive a proper response.
Who was affected
The individual who submitted access requests regarding their personal data in enforcement proceedings.
What the authority found
The Data Protection Authority found that the bailiff did not comply with legal requirements to provide reasons for denying access to personal data.
Why this matters
This case reinforces the obligation for service providers to be clear and transparent when responding to personal data requests. It highlights the need for compliance with data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
In May 2025, the DPA received a complaint from the data subject. The data subject had submitted several access requests under Article 15 GDPR to bailiff Rannar Liitmaa, the controller, concerning the processing of their personal data in enforcement proceedings. The data subject asked why their personal data had been collected, from which sources the controller had obtained information about a restricted Facebook group, and under what circumstances their personal data had been shared with third parties. The controller replied that the requested information was not subject to disclosure. In June 2025, the DPA forwarded the request to the controller and asked for a copy of the response. The controller relied on §11(1) of the Bailiffs Act, arguing that bailiffs are bound by professional secrecy and may not disclose information obtained in connection with official duties. The DPA initiated supervisory proceedings in August 2025. The controller provided explanations to the DPA, but did not answer the data subject’s questions and did not explain the legal basis or reasons for restricting their rights. The DPA sent several reminders and clarified that a blanket statement that the information was not subject to disclosure was insufficient. If the controller refused access in whole or in part, they had to provide the applicable legal basis and reasons. The controller did not comply with the recommendation or request an extension. The DPA issued a mandatory order against the controller to ensure the exercise of the data subject’s rights. The DPA held that the controller had failed to properly respond to the access request under Article 15 GDPR. Providing explanations only to the DPA did not satisfy the controller’s obligations, as the response had to be addressed to the data subject. The DPA noted that the controller’s duty of confidentiality under §11(1) of the Bailiffs Act was not absolute. Under §11(3)(1) of the Bailiffs Act, a bailiff must disclose information obtained i
Outcome
Complaint Upheld
A data subject complaint that was upheld by the DPA.
Related Enforcement Actions (0)
No other enforcement actions found for Bailiff Rannar Liitmaa in EE
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Bailiff Rannar Liitmaa - Estonia (2026). Retrieved from cookiefines.eu
Last updated: