Estonia is a strong advocate of technological advancement, and the ICT sector is of major importance to the government. Estonia has become a model for free and open internet access. It is also the EU Member State with the most digital public services,2 with a high level of access and online citizen participation.
Estonia sees ICT as a key to sustained economic growth. The Ministry of Economic Affairs and Communications adopted the Digital Agenda 2020,3 which focuses on creating an environment that facilitates the use of ICT and the development of smart solutions in Estonia in general. The main goals of the Agenda are, among others:
- the completion of the next-generation broadband network, with the aim of that all residents of Estonia will have access to fast (30Mbit/s or faster) internet by 2020 and that at least 60 per cent of households will be using ultrafast (100Mbit/s or faster) internet daily;
- the continuing development of state information systems and public e-services to ensure up-to-date and citizen-friendly solutions; and
- to continue promoting Estonia as a hub for innovation and the development of the information society, and to establish a global information society think tank in Estonia.
The number of internet and mobile telephone users in Estonia has grown rapidly in the past 20 years. The availability of mobile broadband is very good while fixed broadband is less widespread, below the European average, which is mainly because of limited connectivity in sparsely populated rural areas.4 For this reason, a non-profit organisation, the Estonian Broadband Development Foundation (ELA SA), was founded in 2009 by the government and major Estonian communication undertakings to develop Estonia's broadband network and build and operate the EstWin high-speed base network. The project is financed mostly from public sources. In 2018, the Foundation started its 12th and last tender to procure the designing and building of approximately 400km of base network. The Foundation has set its goals to finalise the project in 2019 by bringing broadband no further than 1.5km from 98 per cent of households.5
Separate from the base network project is the government's last mile project. Until 2018, all local municipalities were responsible for mapping out the white areas in their jurisdiction where there is a need for developing the last mile of a high-speed internet network. This approach did not prove to be successful, and in 2018 the Ministry of Economic Affairs and Communications, along with the Estonian Technical Regulatory Authority, initiated the national last mile project, a public competition to find a suitable network builder to bring high-speed internet access to areas where there is no internet access or where the connection is of poor quality and where communications companies would not invest in the next five years (the white area). One service provider will be awarded a subsidy with the obligation to extend broadband access to the largest possible number of households who still lack high-speed internet, with the hope of ensuring nationwide broadband access with high transmission rates. At the time of writing, the application period had just ended.6
The fast-developing ICT sector presents some challenges for policymakers, but generally the regulatory landscape in the ICT sector is in quite good shape. As previously mentioned, the ICT sector is of major importance to the state. Estonia experienced several political changes during the past year, but these are unlikely to heavily impact e-governance or other internet use. The government continues with its strategy to market Estonia as an e-state throughout the world.
i The regulators
ECSs are regulated by the Electronic Communications Act (ECA),7 in force from 1 January 2005 (as amended), which transposes in Estonia the EU's regulatory framework for electronic communications. On basis of the ECA, numerous regulations of the government have been adopted to regulate certain more technical or detailed issues of the framework. Under the ECA, an ECS means a service that consists wholly or mainly in the transmission or conveyance of signals over the ECN under agreed conditions. Network services are also ECSs.8
The ECA provides requirements for public ECNs and publicly available ECSs regarding the use of electronic contact details for direct marketing, the conduct of radiocommunications, and the management of RFs, numbering and apparatus, as well as state supervision over the compliance with these requirements and liability for the violation of these requirements. A publicly available ECS is defined as a service provided by a communications undertaking on the respective communications services market pursuant to the general procedure to all persons, and the persons need not meet any conditions differentiating them from other similar persons. A service is publicly available particularly if provision of the service is continuous and consistent and it is provided essentially under uniform conditions.9 There appear to be no definite (official) criteria available that would help to determine whether a particular service is considered to be publicly available, as there are no official guidelines or case law. However, under a conservative approach from the viewpoint of notification obligations, it does not matter whether the services are offered either on a wholesale level or on a retail level to end users to be considered as publicly available, but rather if the service is open to a particular group of (similar) customers.
The ECA is not applicable to information society services to the extent these are regulated by the Information Society Services Act (ISSA),10 which implements Directive 2000/31/EC into Estonian law. Information society services are services provided in the form of economic or professional activities at the direct request of a recipient of the services, without the parties being simultaneously present at the same location, and such services involve the processing, storage or transmission of information by electronic means intended for the digital processing and storage of data. Information society services must be entirely transmitted, conveyed and received by electronic means of communication.11
Media services are regulated by the Media Services Act (MSA),12 in force from 16 January 2011 (as amended). The MSA provides for:
- the procedure and principles for the provision of audiovisual media services and radio services and the requirements for providers of media services;
- the procedure for the issue of activity licences for the provision of television and radio services to legal persons under private law and the procedure for registration of the provision of on-demand audiovisual media services; and
- the principles of protection of a person who has provided information to a person processing information for journalistic purposes.13
Estonian Public Broadcasting is excluded from the scope of the MSA and is regulated by the Estonian Public Broadcasting Act.14
The electronic communications and media area is supervised by an independent regulatory authority, the Estonian Technical Regulatory Authority (ETRA), which is sometimes also referred to as the Technical Surveillance Authority.15 ETRA supervises the fields of electronic communications, industrial safety and transport. In the field of communications services, the ETRA is tasked with ensuring a sufficient and timely resource of RFs and telephone numbers for the provision of communications services and performing national surveillance of the field of communications.16
Other regulatory bodies that may exercise supervision over ECS providers pursuant to their competence include (not exhaustively) the Consumer Protection Board, the Data Protection Inspectorate, the Competition Authority and the Information System Authority. Note that sector-specific regulation of the competitive situation on the markets for communications services is carried out mainly by the ETRA, while the Competition Authority has general authority (e.g., in merger proceedings).
ii Regulated activities
Under the ECA, each person has the right to commence the provision of communications services. The provision of communications services is subject to a one-off notification obligation. A notice of economic activities for the provision of communications services must, among other required information, set out a description of the provided communications service and the geographical area of activity. Such notice must be filed via the state portal (www.eesti.ee) or via a notary.17 If publicly available communications services are provided by an entity from another EU Member State (cross-border service) on a permanent basis in Estonia, then such entity must also file the notice of economic activities to the ETRA. The current position of the ETRA is that foreign operators also need to establish a branch or subsidiary in Estonia.
For the provision of certain communications services, it is necessary for service providers to apply for licences. Namely, use of radio spectrum and numbering is subject to a RF authorisation and a numbering authorisation respectively. Activity licences are required for the provision of television and radio services. All licences and authorisations are subject to relevant state fees, the amount of which varies according to the type of the licence or authorisation in question. All the relevant licences and authorisations mentioned above are issued by the ETRA.
Frequency authorisations for the use of spectrum are allocated according to the Estonian Radio Frequency Allocation Plan,18 which determines the manner, regime and purpose of using RFs. To receive an authorisation, a standard format application19 to the ETRA must be submitted with the relevant information about the applicant (name, residence or seat, date of birth or personal identification code or registry code, contact details) and the frequency itself (which frequency is being applied for, what is its purpose, conditions of use, area of use, etc.). The ETRA has six weeks from the receipt of a complete application to issue a licence if the use of spectrum does not need international coordination, and eight months if it does. If the use of spectrum is being allocated by way of a public competition or auction, the relevant procedural rules and deadlines are determined by the Minister of Economic Affairs and Infrastructure. The ETRA has the right to refuse an application on certain grounds, for example if the applicant's activities may be hazardous, there is no free spectrum, the use of spectrum is not in line with the Estonian Radio Frequency Allocation Plan or national or international legislation, or if the use of spectrum is ineffective or may cause radio interference.20 The frequency authorisation establishes the conditions and requirements for the use of spectrum. Under certain conditions, the conditions may be amended. If the ETRA has issued a frequency authorisation, the authorisation can be extended by submitting an application not later than one month before the expiry of the authorisation and by paying the relevant state fee.21
Upon grant of spectrum licences by way of public competition, the Minister of Economic Affairs and Infrastructure may determine a one-off authorisation charge of up to €1.597 million, a deposit for participation in the competition, or both. The one-off authorisation charge shall be determined as a fixed charge or, in the case of an auction, as a starting price. The deposit must be equal to all participants and must not exceed the one-off authorisation charge. The deposit will be returned after the winner is ascertained.22
Authorisations for the use of numbering are allocated according to the Estonian numbering plan,23 which determines the location of numbers, short numbers, identification codes and access codes in the numbering space, the requirements for the length, use and dialling procedure of numbers, the conditions of use and the services for the provision of which they may be used. A numbering authorisation can be obtained by submitting a standard format application24 to the ETRA, containing the information on the applicant (name, residence or seat, date of birth or personal identification code or registry code, contact details), the planned use of the number, etcetera. The ETRA will issue a numbering authorisation within 10 working days after receipt of a complete application if there are no grounds for refusal. The numbering authorisation sets out the conditions of use of the allocated number. A numbering authorisation is issued for up to one year and can be extended by up to one year at a time. Numbering authorisations can also be granted by way of an auction on certain conditions.25
Activity licences for television and radio services are provided on the basis of the MSA. All private broadcasters are required to have an activity licence. Estonian Public Broadcasting, which is a legal person in public law, is not required to apply for an activity licence. Different licences are issued for the provision of free access television services, conditional access television services, satellite television services and radio services. Free access television and radio service licences are issued through a public competition. All the other licences are issued on the basis of an application. For the obtaining of licences, the MSA prescribes necessary requirements on programmes, sustainability of a service and the coverage area of the service, among other conditions. A licence for free access television services is issued for up to 10 years, and the rest of the above-mentioned licences for up to five years.26
iii Ownership and market access restrictions
Currently there are no foreign ownership restrictions in the communications sector.
Under the MSA, a television or radio service provider will not be given an activity licence if it holds a dominant influence over the management to the undertaking that has been issued an activity licence for the provision of television and radio service, and the issue of the activity licence may substantially damage competition in the media services market, particularly through the creation or reinforcement of the dominant position in the market.27 Similarly, aggregate holdings of certain types of spectrum may constitute a dominant position, which would trigger the heightened attention of the ETRA and the Estonian Competition Authority. When it comes to trading spectrum, the ETRA has a right to refuse the transfer or grant of right to use RFs if this distorts competition, and it may, if necessary, coordinate the transfer or grant of frequencies with the Estonian Competition Authority.28 These rules apply in addition to the general merger control regime under Estonian and European competition law.
In general, Estonian law does not limit market access, except for the limitations specified above.
iv Transfers of control and assignments
Mergers and acquisitions are reviewed by the Estonian Competition Authority. The procedure of merger reviews is regulated by Chapter 5 (Control of Concentrations) of the Competition Act.29 Council Regulation (EC) No. 139/2004 on the control of concentrations between undertakings applies in cases of mergers with an EU dimension, but the national merger control is very similar to that of the EU. Estonia has a mandatory filing requirement for qualifying transactions. For a transaction to be qualifying, the relevant turnover thresholds must be exceeded. A merger is notifiable if the total annual turnover in Estonia of all companies concerned is more than €6 million and the total annual turnover in Estonia of each of at least two of the companies concerned is more than €2 million.30 The companies concerned include those directly involved in the merger, any other associated companies within the same control group and joint ventures. There is a two phase merger review process, and clearance is required before closing. The length of proceedings is 30 days for a simplified procedure, and will last for four additional months when further investigation is needed. Simplified procedures may end with an approval or a decision to conduct further investigation in Phase II. The latter may conclude with a clearance, a refusal or a conditional clearance.31
While the Competition Authority has general authority over merger proceedings, the sector-specific regulation of ECSs markets is conducted by the ETRA. The Competition Authority used to have wider competences in the communications sector, but now only postal services have remained fully under its regulatory authority. The ETRA and the Competition Authority are under a legal obligation to cooperate in the area of market regulation and exercise supervision in the communications sector, and, if necessary, exchange appropriate information.32 This means that when it comes to mergers in the communications sector, the Competition Authority may involve the ETRA in the merger proceedings. In practice, merely holding a dominant position through an allocated frequency authorisation can be decisive on the outcome of transactions.
As described in subsection iii above, licence transfers may also be subject to competition law concerns. In general, RFs are transferrable or can be granted for use to another person if the Estonian Radio Frequency Allocation Plan allows it, with the RFs for broadcasting being an exception. It is thus necessary to verify the transferability or the permissibility of granting the frequency to the use of another person on a case-by-case basis, based on the Radio Frequency Allocation Plan. The transfer or grant of use must be approved by the ETRA, who may coordinate with the Competition Authority. The ETRA has the right to refuse the transfer or grant of the right to use RFs if it distorts competition.33
iii TELECOMMUNICATIONS and INTERNET ACCESS
i Internet and internet protocol regulation
IP-based services are regulated by the ISSA. ECSs and information society services are mutually exclusive; therefore, information society services are excluded from the scope the ECA. However, state supervision over compliance with the requirements provided for in the ISSA is exercised by the ETRA.
Contrary to the ECA, the ISSA does not contain any registration, authorisation or notification obligations for the service providers. The primary obligation of service providers is to render directly and permanently accessible to recipients of services at least the following information:
- the name of the service provider, its registry code and the name of the corresponding register, the service provider's address and other contact details, including the electronic mail address;
- its registration number if, for operation in the corresponding field of activity, registration in the register of economic activities is required by law, or its activity licence number; and
- if reference is made to the fee charged for the service, information on whether the fee includes taxes and delivery charges.
Information society service providers generally have less obligations compared to communications service providers. An information society service provider is generally not liable for the information transmitted upon mere transmission of information and provision of access to public data communications networks, upon temporary storage of information in cache memory and upon provision of information storage services. There are exceptions to this general rule.34 Additionally, information society service providers are not obligated to monitor information upon the mere transmission thereof or provision of access thereto, temporary storage thereof in cache memory or storage thereof at the request of the recipient of the service; nor is the service provider obligated to actively seek facts or circumstances indicating illegal activity. However, in certain circumstances information society service providers are obliged to provide information about alleged illegal activities undertaken or information provided by recipients of their services, and to communicate to the competent authorities information enabling the identification of recipients of their service.35
ii Universal service
Under the ECA, it is possible to designate universal service providers by way of a public competition, or public procurement if the payable charges exceed the relevant thresholds. When designating universal service providers, it must be taken into account that the end goal is to ensure provision of the service in a cost-effective manner that does not prejudice competition, at an affordable price, and in accordance with the objectives of state organisation in the electronic communications sector, which is to promote competition in the provision of ECSs. A universal service provider may be designated separately for each specified service within a specified territory.36
The following services can be designated as universal services:
- connection to a communications network in a fixed location enabling telephone services (which enables the making and receiving of calls, the sending and receiving of faxes and the use of data communication services at data rates sufficient to permit functional internet access, taking into account the hardware and software used by most end users);
- public payphone services or other publicly accessible communications services enabling calls; and
- the availability of a universal electronic public number directory and directory enquiry services.37
The USO is based on a universal service contract between the communication undertaking and the state, which sets out, inter alia, the obligations, term, charges payable by end users and the territory.38 The costs related to the performance of the USO are compensated for out of the universal service charge payable by communications undertakings whose turnover for communications services exceeds €383,500 per year. The rate of the universal service charge, established each year by the government, is 0.01 to 1 per cent of the turnover of a communications undertaking with the financing obligation in the preceding financial year. A communications undertaking with the USO is entitled to compensation for the unreasonably burdensome costs related to the performance of the obligation.39
Despite the detailed regulation of universal service providers, the competition situation in the markets for communications services is in good shape, all the services that can be designated as universal services are available on the market and no communication undertakings have currently been designated as universal service providers.
iii Restrictions on the provision of service
Obligation to provide access to communications networks and general terms and conditions obligations
The EU directives that require communications undertakings to provide access to their networks have been transposed in national law by the ECA. Generally, communications undertakings are required to enter into a subscription contract with any person who submits an application to this effect. Entry into the contract may only be refused in specified cases, which include:
- the technical impossibility in the requested area or manner to connect terminal equipment to the communications network;
- failure by the applicant to provide information necessary for his or her identification or for communications with him or her, or the address of the location of the connection to the communications network allowing the provision of the requested communications service;
- the provision of incorrect information upon submitting the application or upon entering into a requested subscription contract; or
- an applicant has a debt of collectable arrears for the provided communications services or the applicant is subject to bankruptcy proceedings.
If none of these conditions is fulfilled, the communications service provider is obliged to enter into a subscription agreement with the end user and to create a possibility for the end user to commence the use of the ECS within 10 working days after entry into a subscription contract, provided that the end user has performed the obligations assumed by the subscription contract.40
A communications service contract entered into with the end user must contain certain mandatory provisions. There is also formalised process with a one month prior notice requirement for changes to general terms and conditions. The ECA establishes minimum information and mandatory terms that must be regulated in an ECS contract. These include, among others:
- a description of the communications service and possibilities to use other related services;
- charges for the services, including charges payable for maintenance, procedure for settlement of accounts as well as discounts and other price packages;
- quality requirements set for the communications service, including service quality parameters;
- the procedure and time limit for elimination of faults;
- the procedure and time limit for submission of complaints and claims, and the procedure for resolution of disputes;
- the term of the contract and conditions for cancellation and extension of the contract;
- the measures taken by the communications undertaking to ensure security and integrity of communications networks and services; and
- the terms and conditions of a product or communications service intended for end users with special needs.41
Some of the above contractual information (e.g., information on charges) and any standard terms used by the electronic communications undertaking must be made public on the website of the electronic communications undertaking or, in the absence thereof, in any other reasonable manner.42
Other than the mandatory provisions discussed above, the communications service provider and the end user are free to agree on contract terms.
Regulation (EU) 2015/2120 laying down measures concerning open internet access is directly applicable in Estonia. Thus, all communications service providers in Estonia are under the obligation to treat all traffic equally, when providing internet access services, without discrimination, restriction or interference, and irrespective of the sender and receiver, the content accessed or distributed, the applications or services used or provided, or the terminal equipment used.43 Estonia is a strong supporter of net neutrality, despite not having adopted any national legal acts or guidelines on net neutrality. The freedom and democracy watchdog Freedom House assesses that there are very few restrictions on internet content and communications in Estonia. There are no indications of any increase of restrictions on content or of self-censorship, and online debate is very active and open. Estonians have access to a wide range of content online, and very few resources are blocked or filtered by the government. Following court rulings on intermediary liability for third-party comments, some Estonian media outlets have modified their policies regarding anonymous commenting on their portals.44
Unsolicited phone calls, faxes, emails and texts
Estonia has implemented the e-Privacy Directive45 with the ECA. The requirements regarding marketing communications are different for legal and natural persons. Under the ECA, the use of electronic contact details of a natural person for direct marketing is allowed only with the person's prior consent (opt-in), while the use of electronic contact details of a legal person for direct marketing is allowed if, upon use of contact details, a clear and distinct opt-out opportunity is given to refuse such use of contact details free of charge and in an easy manner, and the person is allowed to exercise its opt-out right over an ECN.
Regardless of the above, if a communications service provider obtains the electronic contact details of a buyer, who is a natural or legal person, in connection with selling a product or providing a service, such contact details may still be used for direct marketing of its similar products to the buyer if the buyer is given, upon the initial collection of electronic contact details and each time when the buyer's electronic contact details are used for direct marketing, a clear and distinct opt-out opportunity free of charge and in an easy manner; and the buyer is allowed to exercise its right to refuse over an ECN.
It is important to note that the requirements described above do not apply to multiparty voice calls in real time, which have been excluded from the scope the implementation of the e-Privacy Directive in Estonia. Multiparty voice calls in real time are instead regulated in the Law of Obligations Act.46 Real-time multiparty calls may be used for communicating an offer only if the consumer has not expressly forbidden the use thereof. Thus, real time multiparty voice calls are subject to an opt-out possibility, while offers made to consumers by automated calling systems without human intervention, fax, telephone answering machine, electronic mail, SMS or other means are lawful only with the prior consent of the consumer.47
On 9 May 2018, the Estonian parliament passed a new legislative act, the Cybersecurity Act,48 which entered into force on 23 May 2018. The Cybersecurity Act transposes into Estonian law the Security of Network and Information Systems Directive.49 The Act provides requirements for the maintenance of network and information systems essential for the functioning of society and state and local authorities' network and information systems, liability and supervision as well as the bases for the prevention and resolution of cyber incidents. The Act is not applied to micro and small enterprises.50 The Act includes obligations, among others, for communications undertakings provided for in the ECA that provide cable distribution services consumed by at least 10,000 end users, and broadcasting network service providers upon providing cable distribution services or broadcasting network services. The Act also applies to Estonian Public Broadcasting and information society service providers within the meaning of the ISSA who offer online marketplaces, search engines or provide cloud computing services.51
The Cybersecurity Act requires the above-mentioned service providers to apply organisational, physical and information technological security measures for preventing and resolving cyber incidents, and preventing and mitigating any impact on the continuity of the service or the security of the system due to a cyber incident, or any possible impact on the continuity of another dependant service or the security of a system. Service providers are required, inter alia, to prepare a risk assessment and ensure its timeliness, ensure the monitoring of systems for detecting compromising actions and reduce the impact of cyber incidents. The Act also provides for an obligation to notify the Estonian Information System Authority (EISA) of cyber incidents. EISA is also responsible for the state and administrative supervision of compliance with the requirements of the Cybersecurity Act. Similarly, the ECA also includes a requirement to notify EISA immediately of all incidents endangering the security and integrity of the communications network and services that to a significant extent affect the functioning of the communications services or network, and of measures taken to eliminate such incidents.52
Under the ECA, a communications undertaking is required to take appropriate technical and organisational measures to manage the risks related to security and integrity of the communications services and network. The measures must be proportionate to the potential emergency situation, must ensure the minimum impact of incidents endangering the security and integrity of users of communications services and related networks, and must ensure continuity of the provided services.53 A communications undertaking must also guarantee the security of a communications network and prevent third persons from accessing (without legal grounds) the following data: information concerning specific details related to the use of communications services; the content and format of messages transmitted over the communications network; and information concerning the time and manner of transmission of messages.
If a specific hazard exists to a communications service or the security of the communications network, the communications undertaking must immediately inform subscribers of such hazard in a reasonable manner and, unless the hazard can be eliminated by measures taken by the undertaking, also of possible remedies and of any costs related thereto.54
In the summer of 2017, the new Emergency Act55 entered into force, which includes a list of emergencies that justify the interruption in vital services. Vital services include, among others, phone services, mobile phone services, data transmission services, and digital identification and digital signing.56 A provider of a vital service is required to, among other things:
- prepare a continuity risk assessment and plan of the vital service provided thereby;
- implement measures that prevent interruptions of the vital service, including reducing the dependency on other vital services, essential contract partners, suppliers and information systems through duplicating technical systems, contracts, staff and other means important to the provision of the service, using alternative solutions, having and stocking necessary resources and other similar actions; and
- ensure the capability to guarantee the continuity and quick restoration of the service provided thereby during an emergency or another similar situation, including in the event of a technical failure or an interruption of the supply or another vital service.57
Privacy and personal data protection
On 25 May 2018, the General Data Protection Regulation (GDPR)58 became applicable. This was of extreme importance in the communications sector, as the general rules set out in the GDPR are applicable in the communications sector. In addition to the GDPR, Estonia still has a Personal Data Protection Act59 in force from the pre-GDPR period, as the new draft Personal Data Protection Act, which was supposed to enter into force with the GDPR, was withdrawn from the parliament in the summer of 2018 owing to public criticism.60 The draft Act is now again pending, but at the time of writing there was no certainty as to when the Act will be passed. However, the rules of the GDPR are applicable in Estonia as in the entire EU, and in the event of discrepancy with the national legislation, the GDPR should be applied.
In addition to the GDPR and the Personal Data Protection Act, some data protection requirements are also set out in the ECA. Under the ECA, a communications undertaking is required to maintain the confidentiality of all information that becomes known thereto in the process of the provision of communications services, and that concerns subscribers as well as other persons who have not entered into a contract for the provision of communications services but who use communications services with the consent of a subscriber. Above all, it must maintain the confidentiality of information concerning specific details related to the use of communications services; the content and format of messages transmitted over the communications network; information concerning the time and manner of transmission of messages.61
This information may be processed only if the undertaking notifies the subscriber, in a clear and unambiguous manner, of the purposes of processing the information and gives the subscriber an opportunity to opt out. Irrespective of whether the subscriber refuses such processing, the undertaking still has the right to collect and process such personal data without the consent of the subscriber:
- that is necessary for the purposes of recording transactions made in the course of business and for other business-related exchange of information;
- if the sole purpose of the processing is the provision of services over the communications network;
- if it is necessary for the provision, upon the direct request of the subscriber, of information society services; or
- that is necessary for billing the subscriber, including for the determination and calculation of interconnection charges.62
If the processing is done for publishing data on subscribers in number directories or through directory enquiry services, the processor must provide the subscribers with an opportunity to decide on whether and to what extent they wish such data to be published. Subscribers must also have an opportunity to verify and amend the data that concerns them, and to terminate the publication of such data.63
The ECA also prescribes other requirements deriving from the e-Privacy Directive, as discussed above in subsection iii above.
Lawful interception and data retention
Under Section 113 of the ECA, a communications undertaking must grant a surveillance agency or security authority access to the communications network for the conduct of surveillance activities or for the restriction of the right to confidentiality of messages, respectively. A communications undertaking is required to preserve the confidentiality of information related to the conduct of surveillance activities, and activities that restrict the right to inviolability of private life or the right to the confidentiality of messages. The electronic communications undertaking may recover the costs it incurs in relation to the provision of access to the communications network under the rules of Section 114 of the ECA.
Under Clause 1111(11)5) and Section 1141 of the ECA, a communications undertaking must provide certain retained data at the request of a court within civil matters.
Obligations to retain data (as per the now-invalid Data Retention Directive64) have been imposed under the ECA and have not been revoked despite the Digital Rights Ireland65 and the Tele2 Sverige66 rulings. Communications undertakings must retain for a period of one year an extensive amount of data under the ECA, and have an obligation to provide information to competent state authorities and courts.67
Protection of children online
Estonia has adopted various laws that aim at protecting children online. For example, the Child Protection Act68 limits the permissibility of certain content to all children below the age of 18 years. It is prohibited to manufacture, show and disseminate to children content that promotes violence or cruelty, or contains pornographic content.69 The same is provided in the Act to Regulate Dissemination of Works which Contain Pornography or Promote Violence or Cruelty.70 This can be enforced in administrative proceedings by issuing a precept to terminate the violation and to restrict or take down the improper content. In the event of failure to comply with the precept, penalty payments can be imposed repeatedly until the precept is complied with. Parental consent cannot override the requirements set for content providers or limit their legal liability.
Note that under Estonian law, there are liability restrictions for information society service providers in the case of mere transmission, caching and storage. The latter is feasible if the service provider does not have actual knowledge of the contents of the information and, as regards claims for compensation for damage, is not aware of facts or circumstances from which the illegal activity or information is apparent. Additionally, the service provider must, upon obtaining knowledge or awareness of the facts specified above, act expeditiously to remove or to disable access to the information.71
Sexual enticement of children below the age of 14 is criminalised and punishable under the Penal Code.72 Sexual enticement means, among others, handing over, displaying or otherwise knowingly making available pornographic works or reproductions to a person less than 14 years of age. This is punishable by a pecuniary punishment or up to three years' imprisonment for natural persons and by a pecuniary punishment of €4,000 to €16 million for legal persons. Showing sexual abuse of a person aged less than 14 years, or engaging in sexual intercourse in the presence of such person or knowingly sexually enticing such person in any other way, are punishable by the same sanctions. Handing over, displaying or knowingly making available of works or reproductions of works promoting cruelty in another manner to a person of less than 14 years of age, or showing the killing or torturing of an animal in the presence of such person without due cause or knowingly exhibiting of cruelty to him or her in another manner, are punishable by a pecuniary punishment the amount of which is up to €3,200 in the case of legal persons.73
The MSA also includes provisions that are aimed at protecting children. Television and radio service providers may not transmit programmes that may cause substantial physical, mental or moral detriment to minors, in particular such programmes that include pornography or that propagate violence or cruelty for the purposes of the Act to Regulate Dissemination of Works which Contain Pornography or Promote Violence or Cruelty. On-demand audiovisual media services that may cause substantial damage to the physical, mental or moral development of a minor must be made accessible by the on-demand audiovisual media service provider by means of personal identification codes or other relevant technical solutions only in a manner that is not accessible to minors under normal circumstances.74
The Advertising Act75 includes several requirements for advertising directed at persons less than 18 years of age. Advertising that targets groups that are primarily made up of children must take into account their unique physical and mental state resulting from their age. Children may not be a target group of advertising if it is prohibited to sell the advertised goods or provide the advertised services to children. Advertising that targets groups that are primarily made up of children may not:
- create the impression that the acquisition of certain goods or the use of certain services will give the child an advantage over other children or that the lack thereof will have the opposite effect;
- create feelings of inferiority in children;
- incite children to behave or act in a manner that has or may have the effect of bringing children into unsafe conditions;
- contain elements that frighten children;
- exploit the trust children place in their parents, teachers or other persons;
- include a direct or indirect appeal to children to demand the acquisition of the advertised goods or the use of the advertised services from other persons; or
- directly incite children to enter into transactions independently.76
These requirements also apply to any online advertising.
iv SPECTRUM POLICY
The Estonian spectrum policy is changing continuously. The demand for spectrum is increasing rapidly with the development of and increasing demand for new technologies and mobile communications services. Currently, the 5G mobile network is being developed. All this proves to be a challenge in conditions where frequency spectrum is a scarce resource.
To tackle this challenge, the Estonian Radio Frequency Allocation Plan is constantly changing to conform to new developments. The use of RFs in Estonia is harmonised with those of the EU, as Estonia takes account of the recommendations of the European Commission to the greatest extent possible.77 The ECA provides that the purpose of regulating the management of RFs is to ensure the purposeful, objective, transparent and proportionate management, and the effective and efficient use, of RFs for the needs of users of RFs and for the provision of communications services, the creation of possibilities for the development of new technologies and fast elimination of radio interference. The Radio Frequency Allocation Plan determines, among other things, the RF bands for the introduction of new technologies together with restrictions on new and existing users. The ETRA reviews the allocation plan at least once a year and submits to the responsible minister proposals for amendments if the development of electronic communications technology requires it.78
ii Flexible spectrum use
As discussed above, the use of spectrum requires its prior allocation by the ETRA. Spectrum is allocated on the basis of the Radio Frequency Allocation Plan, which determines the manner, regime and purpose of using frequency bands. Upon granting a frequency authorisation to a communications undertaking, the ETRA establishes in the authorisation, among other things, the purpose, manner, conditions and area or location of the use of spectrum, as well as the requirements for the shared use of RFs. Therefore the authorisation may include in its conditions the possibility to share the use of spectrum, as well as the possibility to trade frequency or grant it for use on the basis of a contract. Accordingly, the use of spectrum is made more flexible by way of allowing such trading and shared use of spectrum.
In addition, the ETRA carries out spectrum auctions in previously unused frequency ranges and rearranges the use of spectrum, if need be, as discussed further below.
iii Broadband and next-generation mobile spectrum use
The ETRA is also constantly dealing with the need for new uses of mobile spectrum. For example, in 2015 it rearranged the frequency usage of mobile operators in the 900MHz band to enable the introduction of new technologies. In the course of the process, the frequency blocks of each operator were rearranged so that complete frequency ranges were allocated to each operator to create wider bandwidth and create conditions for introducing new 4G and 5G technologies.79
If the ETRA finds that the number of available spectra is not sufficient for their allocation, it can hold a public competition in the form of a spectrum auction. The latest auction of mobile broadband spectrum ended in May 2017. The auction of frequencies in the ranges of 2,540–2,570MHz, 2,660–2,690MHz and 2,575–2,615MHz ended with the selling of three frequency division duplexes (FDD) and two time division duplexes (TDD) that provide the right to use 100MHz-worth of spectrum in Estonia. Two operators, Elisa Eesti AS and Telia Eesti AS, participated. FDD I and II were bought by Telia, bidding €1,601,234 and €3,605,535 respectively. FDD III, TDD I and II were bought by Elisa, bidding €2,608,789, €1,612,346 and €1,597,001 respectively. Accordingly, around €11 million was earned through the auction.80
After the digital switchover occurred on 1 July 2010, the freed-up frequencies were allocated for 4G mobile communication services. It can be therefore said that more and more spectrum is becoming available for mobile services. More specifically, the latest and upcoming auctions are focused on 5G technologies. During the Estonian presidency of the Council of the EU from July to December 2017, a Ministerial Declaration was signed to make 5G a success for Europe.81 It was agreed that 5G is the vision for a fully connected European society and a path towards the European gigabit society. The crucial step in implementing this vision is to make more spectrum available in a timely and predictable manner. To realise this goal, it is necessary to release 5G spectrum bands.82 Currently, a new auction is being planned for a frequency range that would allow the use of 5G technologies in the 3,600MHz range.83
iv Spectrum auctions and fees
The ETRA carries out auctions if it finds that the number of available spectra is not sufficient for their allocation.
Currently, the ETRA is planning to auction spectrum in the 3,600MHz frequency band. The ETRA and the Ministry of Economic Affairs and Communications have started preparations for the auction, and ran a public consultation until the end of April 2018. Allocating the 3,600MHz frequency band will improve access to mobile internet and will help to improve the quality of service in both major cities and rural areas. This frequency band is considered as the most important 5G frequency range in the European 5G Roadmap, which will allow the use of innovative technologies and devices (IoT).84 The ETRA has confirmed that the auction for this range will be announced at the beginning of 2019.
The next crucial auctions for developing 5G are likely to be for selling spectrum in the ranges of 700MHz and 24.25–27.5GHz. The ETRA is preparing to deploy these frequency ranges for 5G systems.85
i Restrictions on the provision of service
Media services are subject to the licensing obligations discussed above. In addition, there are restrictions on content that are one of the pre-requirements for obtaining licences.
For example, the MSA requires a television and radio service provider to reserve at least 5 per cent of the daily transmission time of the programme service on at least six days a week for transmitting self-produced new programmes, except on national holidays. At least 10 per cent of the monthly transmission time must be reserved for transmission of own productions, deducting the transmission time allocated for news, sporting events and games programmes as well as for advertising, teletext services and teleshopping. At least 50 per cent of the minimum capacity of own production must be shown during prime time between 7pm and 11pm. At least 51 per cent of the annual capacity of the television programme service must be reserved for transmission of audiovisual works of European origin, deducting the transmission time allocated for news, sporting events and games programmes, as well as for advertising, teleshopping and teletext services, and at least 10 per cent of such audiovisual works must have been created by producers that are independent of this television service provider. These requirements are subject to certain exceptions; for example, local channels are exempted from some of them.86
The MSA also sets out some requirements for commercial communications, TV and radio advertising, sponsorship and product placements. In addition to the MSA, these are regulated by the Advertising Act.
ii Internet-delivered video content
Besides television services, on-demand audiovisual media services are becoming increasingly popular. On-demand audiovisual media services do not require a licence, but do require a notification of economic activities to be submitted through the state portal or to a notary, as discussed above.
Most of the biggest ISPs in Estonia have started their own video distribution services. However, this does not limit the accessibility of on-demand services of other service providers. Standalone services are also freely accessible. However, generally service providers measure the use of data without taking into account that part of the data that is used for VOD. Still, it must be noted that there are examples on the market of ISPs' own on-demand video distribution services that do not use up mobile data if streamed via the service provider's own networks. Thus, one the strategies used to attract customers to buy video distribution services is that ISPs do not charge for the data used on streaming via mobiles on their own VOD services equally with the data used for other VOD services.
vi THE YEAR IN REVIEW
The most important changes in the legislation concerning the ICT sector in 2017 and 2018 have been regarding the GDPR, the Cyber Security Act and the Emergency Act.
The GDPR became applicable on 25 May 2018, which required companies to adjust their data processing practices and gave people greater control over the use of their personal data.
The Cyber Security Act entered into force on 23 May 2018. The Act provides requirements regarding the maintenance of network and information systems, liability and supervision as well as the bases for the prevention and resolution of cyber incidents, and lays down numerous obligations for communications services and information society service providers to ensure cybersecurity.
The new Emergency Act87 was passed in February 2017 and entered into force in July 2017. Pursuant to the new procedure, the list of emergency situations will now also include extensive interruptions in vital services (electricity, liquid fuel, mobile and data communication, etc.) that may entail severe consequences for the public. The inclusion of interruptions in vital services in the list of emergencies will ensure the state's greater focus on improving their continuity and obligate the authorities organising the services to better prepare for the resolution of crises.88
Significant recent transactions include the acquisition of Starman by Finnish telecommunications group Elisa, and the acquisition of the major TV channel TV3 by Providence Equity Partners.
In the spring of 2017, the Estonian Competition Authority cleared Elisa's acquisition of the 100 per cent share of Starman from Polaris Invest and Com Holding. Starman was the number one service provider in pay-TV services and number two for fixed broadband services in Estonia, accounting for 35 and 20 per cent of market shares, respectively. Elisa announced in mid-December 2016 that it had purchased full ownership of Starman from Polaris Invest and Com Holding for a cash consideration of €151 million.89 At the beginning of 2018, Elisa brought all Starman services under its own brand.90
In March 2017, it was also announced that the Swedish media holding Modern Times Group had signed an agreement to sell its Baltic businesses to the US' Providence Equity Partners. The value of the transaction was approximately €115 million. The transaction concerned the sale of three TV channels in Estonia (TV3, TV3+ and TV6), five TV channels in Latvia and three in Lithuania. The sold entities form the third-largest commercial television operator in the Baltic region, nationwide commercial radio stations, digital assets and an online advertising consultancy operating across the Baltic region. The Baltic TV-channel portfolio had a combined 48.6 per cent commercial share of viewing as of the final quarter of 2016 among the target audience of viewers of ages 15 to 49.91
Most of the major mobile service providers have recently come out with their own VOD services, such as Elisa's Elisa Elamus and Telia's MINU.TV, which includes FOXplay and HBO. This marks a growing demand for VOD among viewers.
Meanwhile, in 2017, several television service providers that had been providing free access television switched to conditional access services. This was the result of growing compliance requirements for free access television service providers regarding advertising, programme selection, etcetera, which markedly raised the costs of said television service providers. As a result, two major previously free-to-air channels, Kanal2 and TV3, became subscription channels.
With VOD and mobile internet becoming increasingly in demand, the EU also saw the growing need for the lowering of roaming charges. Eventually, on 15 June 2017 Regulation (EU) 2017/920 became applicable, which significantly lowered roaming charges in the European Union. The Regulation allows consumers to choose a subscription service that allows them to use mobile services within the EEA on the same conditions as in Estonia.
With the above developments, there is also an increasing demand for spectrum on the market. In 2017, the ETRA held a public auction and sold spectrum in the 2,500MHz frequency band for approximately €11 million. An auction for spectrum in the 3,600MHz frequency range is being planned for the end of 2018 or beginning on 2019 to improve access to mobile internet and allow the use of 5G innovative technologies and devices.
vii CONCLUSIONS and OUTLOOK
Looking ahead, some of the next important developments in the communications, technology and media sector are the following.
From 1 January 2019, the ETRA and the Consumer Protection Board will be joined into one single regulatory authority: the Consumer Protection and Technical Regulatory Authority. The new Authority will resume the obligations of the ETRA and the Consumer Protection Board.92
The upcoming developments will likely include the passing of the new national Personal Data Protection Act and its Implementing Act, which will be in accordance with and will implement the requirements set out in the GDPR. To our knowledge, there are currently no other major legislative reforms or new acts planned that would have a significant effect in the ICT sector.
In November 2019, all the current radio service providers' licences will expire. The ETRA and the Ministry of Culture are already preparing for the upcoming competition for radio licences for 2019 to 2024.93
The Estonian ICT sector is fast-developing and highly important to the legislators. The government's goals include bringing ultrafast internet to more and more end users and to promote Estonia as the world's capital of innovation regarding the communications and information society. However, there are still challenges for policymakers caused by convergence and ultra-fast developments in the sector.
Generally, Estonia follows European policies, and has successfully implemented the various pieces of EU legislation into national law. One shortcoming concerns the rules on data retention by communications service providers, which are based on an invalid directive and have not been revoked from national law.
1 Mihkel Miidla is a partner and Liisa Maria Kuuskmaa is a legal assistant at Sorainen.
7 Available in English at https://www.riigiteataja.ee/en/eli/530052018001/consolide.
8 Clause 2 6) of the ECA.
9 Clause 2 68) of the ECA.
10 Available in English at: https://www.riigiteataja.ee/en/eli/ee/513012015001/consolide/current.
11 Clause 2 1) of the ISSA.
12 Available in English at: https://www.riigiteataja.ee/en/eli/ee/511052015002/consolide/current.
13 Section 1 of the MSA.
14 Available in English at: https://www.riigiteataja.ee/en/eli/ee/527062014005/consolide/current.
17 Sections 3–4 of the ECA.
20 Sections 11–14 of the ECA.
21 Sections 11, 15-16 of the ECA.
22 Subsections 9(22)-9(24) of the ECA.
25 Sections 33–39 of the ECA.
26 Sections 32–40 of the MSA.
27 Clause 32 3) of the MSA.
28 Subsection 17(8) of the ECA.
29 Available in English at: https://www.riigiteataja.ee/en/eli/ee/527122017001/consolide/current.
30 Section 21 of the Competition Act.
31 Section 27 of the Competition Act.
32 Subsections 40(4) and 144(1) of the ECA.
33 Section 17 of the ECA.
34 Sections 8–10 of the ISSA.
35 Section 11 of the ISSA.
36 Section 73 of the ECA.
37 Section 69-70 of the ECA.
38 Subsections 72(3)–72(4) of the ECA.
39 Sections 75, 81–84 of the ECA.
40 Sections 93–94 of the ECA.
41 Subsection 96(1) of the ECA. The full list of mandatory terms can also be found therein.
42 Subsection 96(3) of the ECA.
43 Articles 3 and 4 of Regulation (EU) 2015/2120.
45 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications).
46 Available in English at: https://www.riigiteataja.ee/en/eli/ee/507022018004/consolide/current.
47 Section 60 of the Law of Obligations Act.
48 Available in English at https://www.riigiteataja.ee/en/eli/523052018003/consolide.
49 EU Directive 2016/1148.
50 Subsections 1(1) and 1(3) of the Cybersecurity Act.
51 Clauses 3(1)5), 3(1)10) and Subsection 4(1) of the Cybersecurity Act.
52 Subsection 872(2) of the ECA.
53 Subsection 872(1) of the ECA.
54 Section 101 of the ECA.
56 Section 36 of the Emergency Act.
57 Subsection 38(3) of the Emergency Act.
58 Regulation (EU) 2016/679.
59 Available in English at https://www.riigiteataja.ee/en/eli/ee/۵۰۷۰۳۲۰۱۶۰۰۱/consolide/current.
61 Subsection 102(1) of the ECA.
62 Section 102 and 104 of the ECA.
63 Sections 102–107 of the ECA.
64 Directive 2006/24/EC.
65 Judgement of the Court of Justice of the European Union (CJEU) of 8 April 2014 in case C-293/12.
66 Judgement of the CJEU of 21 December 2016 in joined cases C-203/15 and C-698/15.
67 Section 1111 of the ECA.
68 Available in English at https://www.riigiteataja.ee/en/eli/ee/520122017002/consolide/current.
69 Section 25 of the Child Protection Act.
70 Available in English at https://www.riigiteataja.ee/en/eli/ee/520012015009/consolide/current.
71 Sections 8–10 of the ISSA.
72 Available in English at https://www.riigiteataja.ee/en/eli/ee/509072018004/consolide/current.
73 Sections 179–180 of the Penal Code.
74 Section 19 of the MSA.
75 Available in English at https://www.riigiteataja.ee/en/eli/ee/504042018001/consolide/current.
76 Section 8 of the Advertising Act.
77 Subsections 6(3), 8(3) and 8(4) of the ECA.
78 Subsection 9(2) and Clause 10(1)1) of the ECA.
85 This was confirmed to the authors by the officials of the ETRA. This is also in accordance with the 5G roadmap, available at https://www.mkm.ee/sites/default/files/8.a_b_aob_5g_roadmap_final.pdf.
86 Section 8 of the MSA.