<?xml version="1.0" encoding="UTF-8"?>
<oigusakt id="44fab03e-e767-4773-a613-8b1360a37099" xsi:schemaLocation="tyviseadus_1_10.02.2010 http://xmlr.eesti.ee/xml/schemas/oigusakt/tyviseadus_1_10.02.2010.xsd" xmlns="tyviseadus_1_10.02.2010" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
	<metaandmed>
		<valjaandja>Riigikogu</valjaandja>
		<dokumentLiik>seadus</dokumentLiik>
		<tekstiliik>terviktekst</tekstiliik>
		<dokumentEtapp>avaldamine</dokumentEtapp>
		<dokumentStaatus>avaldatud</dokumentStaatus>
		<vastuvoetud>
			<aktikuupaev>2018-05-09</aktikuupaev>
			<avaldamismarge>
				<RTosa>RT I</RTosa>
				<avaldamineKuupaev>2018-05-22</avaldamineKuupaev>
				<RTartikkel>1</RTartikkel>
				<aktViide>122052018001</aktViide>
			</avaldamismarge>
			<joustumine>2018-05-23</joustumine>
			<tavatekst>, in part 01.01.2020 and 01.01.2022</tavatekst>
		</vastuvoetud>
		<avaldamismarge><RTosa>RT V</RTosa><avaldamineKuupaev>2024-08-19</avaldamineKuupaev><RTaasta>2024</RTaasta><RTartikkel>19</RTartikkel><aktViide>519082024019</aktViide></avaldamismarge><kehtivus>
			<kehtivuseAlgus>2024-07-01+03:00</kehtivuseAlgus>
			<kehtivuseLopp>2025-12-31+02:00</kehtivuseLopp>
		</kehtivus>
		<versioon>
			<dokumentVersioon>1</dokumentVersioon>
			<dokumentVersioonKuupaev>2024-08-12</dokumentVersioonKuupaev>
		</versioon>
		<skeemiNimi>tyviseadus_1_10.02.2010.xsd</skeemiNimi>
		<globaalID>519082024019</globaalID>
		<metaandmedVersioon>6</metaandmedVersioon>
		<metaandmedVersioonKuupaev>2025-12-30</metaandmedVersioonKuupaev>
		<metaandmedVersioonPohjustaja>Mari Peetris</metaandmedVersioonPohjustaja>
		<terviktekstiGrupiID>100704</terviktekstiGrupiID><eesmark>Tüviseaduse raamskeem XML struktuuri koostamiseks</eesmark>
	</metaandmed>
	<aktinimi id="cb9ec11c-19ed-4f4d-94b7-d2c854ae6a7f">
		<nimi id="ff6a5234-f33c-4117-8bd3-393f6d131d6b">
			<pealkiri id="a3c8c219-5c87-457c-b7d1-848f9ac8ae8a">Cybersecurity Act</pealkiri>
			<normtehnmarkus id="0aa5df45-e59c-4546-98a4-b91f9faf1fbe" kuuluvus="6e3cf8b1-d1fd-4bb6-85f9-f43def7c1fac">
				<normtehnmarkusNr id="37bd23b8-685f-4705-a97d-fa4a09bab31a">1</normtehnmarkusNr>
			</normtehnmarkus>
		</nimi>
	</aktinimi>
	<muutmismarge id="11b0d724-fcb1-4ad4-9a7b-67d0f8a13e28">
		<aktikuupaev id="f04b73a8-dbfc-49f0-903a-4b7177b1d632">2022-07-19</aktikuupaev>
		<avaldamismarge id="3aaa3f2e-efc8-4c31-a092-624d75c4e652">
			<RTosa id="1f349c12-3146-46ed-a2fa-a20a2594fa3f">RT I</RTosa>
			<avaldamineKuupaev id="63539823-7979-4cca-966a-32174312f8c6">2022-08-06</avaldamineKuupaev>
			<RTartikkel id="b006e2f9-c1af-4d3d-9b8f-4b6418d6cda3">2</RTartikkel>
			<aktViide id="92299b5a-938e-4a24-8be8-4a69f440be90">106082022002</aktViide>
		</avaldamismarge>
		<joustumine id="e10d7e23-f0a7-4069-a3dd-06beffd1758b">2022-08-16</joustumine>
		<tavatekst id="3b91370a-e96f-40b7-8454-a5c2a9f9cce7">, in part 01.01.2027</tavatekst>
	</muutmismarge>
	<muutmismarge>
		<aktikuupaev>2024-06-04</aktikuupaev>
		<avaldamismarge>
			<RTosa>RT I</RTosa>
			<avaldamineKuupaev>2024-06-21</avaldamineKuupaev>
			<RTartikkel>2</RTartikkel>
			<aktViide>121062024002</aktViide>
		</avaldamismarge>
		<joustumine>2024-07-01</joustumine>
	</muutmismarge>
	<sisu id="a69b32d8-0378-41a4-97d3-b3a6eab1a6dc">
		<peatykk id="0df78498-679b-4551-ac96-23bb16de5fcc">
			<peatykkNr id="1c10c8e2-13be-455f-b8ba-03f6d01f8292">1</peatykkNr>
			<kuvatavNr id="0508f8c4-9b02-4c1a-9266-37a76106458d"><![CDATA[Chapter 1]]></kuvatavNr>
			<peatykkPealkiri id="c7bd2fbc-1ba3-4bf6-884d-272f53d9c81b">General Provisions</peatykkPealkiri>
			<paragrahv id="para1">
				<paragrahvNr id="bc88e5a2-bd81-4aa6-a062-6fc2aa844f82">1</paragrahvNr>
				<kuvatavNr id="56feac2b-7ef8-4701-86bb-9d94e0a8c06e"><![CDATA[§ 1. ]]></kuvatavNr>
				<paragrahvPealkiri id="7cc118d7-8b2a-4b09-a4dc-e3105a624b6d">Scope of regulation and scope of application of Act</paragrahvPealkiri>
				<loige id="para1lg1">
					<loigeNr id="2fb5970e-0fc1-44eb-bad8-c1cbf7ec3ff6">1</loigeNr>
					<kuvatavNr id="4d70a882-7267-4b9e-8ef4-7179906d99d6"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="9c722cd2-604e-4aa6-a370-4c36253a4f6a">
						<tavatekst id="30dcd4b6-cc16-497e-8d12-84cf2f8966a6">This Act provides for requirements for the maintenance of network and information systems essential for the functioning of society, including network and information systems of the public sector, liability and supervision as well as bases for the prevention and resolution of cyber incidents.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg2">
					<loigeNr id="2a819522-227a-49f5-a6df-25a3ec8d879f">2</loigeNr>
					<kuvatavNr id="d1c50e05-570d-4ce5-b62a-ed8ec289e201"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="f7c5b76e-9a87-48cb-ac1d-1c849e5a1bce">
						<tavatekst id="9a119b7d-b5c5-4e92-ae6d-0383a00b4f30">This Act is not applied to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para1lg2p1">
						<alampunktNr id="20938b56-ae34-487c-aa84-4a852f5c97c7">1</alampunktNr>
						<kuvatavNr id="116337ad-42c5-4a76-ad78-a9089a1112e2"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="126d78bf-3f6e-455a-853c-3c59ab407d33">
							<tavatekst id="e629f528-23ea-4935-949a-f3f808144496">the processing of state secrets and classified information of foreign states or to the maintenance of processing systems for such information;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg2p2">
						<alampunktNr id="fa7775b1-7ce5-4dd8-a3cb-c71556b29f1b">2</alampunktNr>
						<kuvatavNr id="9ad091e8-ce21-4faf-813a-36b4e256a1dd"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="7419f30f-43a9-4dc7-8dd4-42b5dbe8e09f">
							<tavatekst id="62d1e048-e7f5-4b67-a45c-1fd9b9ddbe58">the maintenance of systems necessary for international military co-operation and for preparations for national military defence within the area of government of the Ministry of Defence.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para1lg3">
					<loigeNr id="e67ec567-9d57-4600-98eb-0ddd22b1ea49">3</loigeNr>
					<kuvatavNr id="bbd4ee5a-ccf9-4804-acf9-eaeeb8802705"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="6543ea43-c982-4df8-af42-b59ae1f3c0da">
						<tavatekst id="40e03cc3-83af-4663-91c3-4984fba9da30">This Act is not applied to digital service providers which employ on average fewer than 50 persons during a financial year and whose annual balance sheet total or annual turnover does not exceed 10 million euros, taking into account the definitions of micro and small enterprises in European Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.05.2003, pp 36–41).</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg4">
					<loigeNr id="03d09756-6f0d-4e5d-93db-5d511c90090b">4</loigeNr>
					<kuvatavNr id="501b3794-ddfd-4aae-9d52-dde9c816e395"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="96fc366d-564e-42c3-8b9a-29bfade4bca1">
						<tavatekst id="85cfcecd-e47f-4945-a879-189fd3c51926">If the requirements for the maintenance of network and information systems are provided by an international agreement or another Act, this Act is applied with the specifications arising from the international agreement or other Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg5">
					<loigeNr id="16d3e524-1440-448b-ac45-6b88039b3095">5</loigeNr>
					<kuvatavNr id="e1cc3ea3-ff21-4e9b-b392-dba3b2ed85cc"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="944380ba-3292-4c3f-90a1-8c2e8a3dee0d">
						<tavatekst id="79a11e38-4d99-472f-9664-216871041235">The provisions of the Administrative Procedure Act apply to administrative proceedings prescribed in this Act, taking into account the specifications provided in this Act.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para2">
				<paragrahvNr id="3bafdc3e-8cb4-4c7d-8db7-f32a2ed356be">2</paragrahvNr>
				<kuvatavNr id="bb76060f-2d56-4f8b-9359-56fce10c68ed"><![CDATA[§ 2. ]]></kuvatavNr>
				<paragrahvPealkiri id="b9e04f26-dab7-4f4a-b4f8-92f8394971bb">Definitions</paragrahvPealkiri>
				<loige id="para2lg1">
					<loigeNr id="6de271cb-fe7e-42f3-b9e9-8bb5f8f1e7e7"/>
					<kuvatavNr id="92007e31-a00e-4cee-bf7a-6a99c25aa783"/>
					<sisuTekst id="f69a0b06-bdb5-41d7-8a47-3452587a9b35">
						<tavatekst id="562a0e60-c887-43c6-939b-4ee11883bd7b">For the purposes of this Act, definitions have the following meanings:</tavatekst>
					</sisuTekst>
					<alampunkt id="para2lg1p1">
						<alampunktNr id="8617befa-dad2-45ec-a019-b8d57bc22e66">1</alampunktNr>
						<kuvatavNr id="9427076a-c4d5-4db2-a28f-ac7cd7659d5b"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="526e7f02-2247-4caa-b9bd-ffcd6cc9a701">
							<tavatekst id="643e44b5-fab1-408b-b53d-c01b08420957">‘network and information system’ (hereinafter <i>system</i>) means an electronic communications network within the meaning of subsection 8 of § 2 of the Electronic Communications Act, any device or group of interconnected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data, or digital data stored, processed, retrieved or transmitted by aforesaid elements for the purposes of their operation, use, protection and maintenance;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p2">
						<alampunktNr id="b0662e98-5e9d-4488-9a22-0acafad56348">2</alampunktNr>
						<kuvatavNr id="e2366564-a675-46a3-b588-142dbbb202e8"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="82f619d5-908b-4b79-8a91-72865424c6c3">
							<tavatekst id="0ce7b910-ef63-4979-9921-1686d26c632c">‘security of systems’ means the ability of systems to resist any action that compromises the availability, authenticity, integrity or confidentiality of data processed in the systems or the services offered by, or accessible via, those systems;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p2b1">
						<alampunktNr id="7bfe48f1-666b-43a9-a09b-b442a3525606" ylaIndeks="1">2</alampunktNr>
						<kuvatavNr id="2347d577-d5db-4095-814b-dfb1aec1a584"><![CDATA[2<sup>1</sup>) ]]></kuvatavNr>
						<sisuTekst id="9ebcbbb3-d4cd-40ad-9aee-8f9b79b6a40a">
							<tavatekst id="ded41eb7-163a-4566-9ae3-245ecda3f0d0">’security measures’ means organisational, physical and information technological operations or resources applied for achieving and maintaining the security of data and systems;<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p3">
						<alampunktNr id="52e90ba6-cd9c-4881-8b84-110816d6e3b6">3</alampunktNr>
						<kuvatavNr id="529ed043-8614-46cc-a10e-8a5f02d6a90f"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="da3d4a4d-c90f-4beb-aa8b-074d6c6efb27">
							<tavatekst id="52dbc9d4-b5b6-477c-a8a2-ea4e20d1767e">‘cyber incident’ means any event in the system compromising or having an adverse effect on the security of the system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p4">
						<alampunktNr id="0279ab86-9784-47e8-9041-faa31914fb83">4</alampunktNr>
						<kuvatavNr id="4ab5d034-bd87-46f1-be5e-648b6870eab2"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="123967ea-2b57-4a47-a5e0-62d872ca3e0b">
							<tavatekst id="9ccfbbd0-90cb-456b-bd20-cb5a6cbb243d">‘representative of digital service provider’ (hereinafter <i>representative</i>) means any natural or legal person established in the European Union designated to act on behalf of a digital service provider not established in the European Union, which may be addressed by a national competent authority or a computer incident response team instead of the digital service provider with regard to the obligations of that digital service provider under this Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p5">
						<alampunktNr id="8ea67810-70a8-4cf6-bef7-d003aa55e096">5</alampunktNr>
						<kuvatavNr id="061c2a38-8e46-4867-9683-02cdffbd2566"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="8c2d31f9-7460-4b3c-b426-85f90403dd10">
							<tavatekst id="dd44b4e9-ba40-417b-bd40-c3c977f7fc8c">‘online marketplace’ means an information society service that allows consumers and traders, for the purposes of the Consumer Protection Act, to conclude online sales or service contracts either on the online marketplace’s website or on a trader’s website that uses computing services provided by the online marketplace;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p6">
						<alampunktNr id="06730348-7f7d-48ff-be41-28097a20e070">6</alampunktNr>
						<kuvatavNr id="19d20de0-4780-4ce6-b130-01bc564cb54b"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="f03c7658-81c6-4015-a356-61765c431c6b">
							<tavatekst id="fb619263-68da-4b42-b002-b2c54613c1a7">‘online search engine’ means an information society service that allows users to perform searches of all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p7">
						<alampunktNr id="e9dc1582-0e10-42d9-bef7-fe43ef289c12">7</alampunktNr>
						<kuvatavNr id="9c6cbf60-0a69-4a44-bab2-cd6266351fe4"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="e3492784-0068-45d3-a93e-f58d1042d99b">
							<tavatekst id="c62ff7ad-e0ca-4884-b9e5-934151881298">‘cloud computing service’ means an information society service that enables access to a pool of flexibly shareable and scalable computing resources without modifying the system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p8">
						<alampunktNr id="e73ada2e-195a-4518-99db-abf828189f5e">8</alampunktNr>
						<kuvatavNr id="14b02b08-2111-48b8-9854-03d2c5d5aadc"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="429bdabd-a2e3-4f96-b668-7ef8248b5dc0">
							<tavatekst id="1a775505-6bbd-4e26-8704-233bce8a4d7f">‘computer incident response team’ means a group of experts who are tasked with operations supporting the detection, analysis and containment of a cyber incident and the response thereto.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
			<paragrahv id="para3">
				<paragrahvNr id="f54a29c3-27bb-4d07-b6ca-7b5c921612f7">3</paragrahvNr>
				<kuvatavNr id="f39f798c-aaa2-4c17-9f56-7bd6b6325988"><![CDATA[§ 3. ]]></kuvatavNr>
				<paragrahvPealkiri id="8854e678-a72c-47a7-9486-31496ffe4730">Service provider</paragrahvPealkiri>
				<loige id="para3lg1">
					<loigeNr id="5b30344a-2efb-4f9e-9de1-7964f61dd7a3">1</loigeNr>
					<kuvatavNr id="3cce7a6c-fd48-4ac4-8be5-d0500fa3151f"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="f1774a6d-cef9-42d1-b6f7-6755539f993b">
						<tavatekst id="a118fcdc-af1d-487f-ac02-bb9a132c9fe6">For the purposes of this Act, ‘service provider’ means a person who uses a system as follows:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg1p1">
						<alampunktNr id="9d9d33a2-eb9c-4731-add2-4d35e33b0c84">1</alampunktNr>
						<kuvatavNr id="9d78cab7-6741-4afe-8c7a-9497921831fe"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="1f8468fd-5254-488a-8c8f-9fa706dd6495">
							<tavatekst id="baab1da6-5469-4926-a6dd-f5b4c0f45a2f">a provider of a vital service provided in the Emergency Act upon providing the vital service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p2">
						<alampunktNr id="edd70bee-06ac-4c34-98f0-60fab6ab3dc9">2</alampunktNr>
						<kuvatavNr id="74435943-7589-456c-9aeb-f5bb69d6236a"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="2573565c-35de-4746-959c-3ead280933ba">
							<tavatekst id="b927027a-8f93-4875-bc32-c7a1ab65489f">an infrastructure manager / railway undertaking provided in the Railways Act who manages public railway infrastructure or whose market share of transport of cargo or transport of passengers forms at least 20 per cent of the market share of transport of cargo or transport of passengers upon providing the service of the functioning of public railways and the functioning of rail transport and public transport of passengers;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p3">
						<alampunktNr id="7d3f6425-d290-40e1-9770-338d6def62ad">3</alampunktNr>
						<kuvatavNr id="aa349d5c-0c73-419d-a911-d88f413b3fd4"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="537e3d57-3ad1-46df-91ce-3ab0cdbd1616">
							<tavatekst id="db728c2a-4fbb-4ddb-bba9-44120cef47f3">an aerodrome operator provided in the Aviation Act who operates an aerodrome which is open for international scheduled air traffic and the air navigation service provider who ensures air navigation services in the Tallinn flight information region upon providing the service of the functioning of an aerodrome and air navigation service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p4">
						<alampunktNr id="f0350462-bd71-4a9e-a363-b3a18f0ab9e7">4</alampunktNr>
						<kuvatavNr id="9da84657-7c47-4d7d-a970-32d4e387c91b"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="313cfae0-1783-4de2-b570-8ad3c5d7267c">
							<tavatekst id="cdb6f708-c7d9-48d4-87fa-6e64bc6e6bca">a port service provider who is, for the purposes of the Ports Act, the port authority of a port or the port facility authority of a port facility that services ships of a gross tonnage of 500 and more or passenger ships in international marine navigation upon providing the service of the functioning of a port;<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p5">
						<alampunktNr id="49f9d148-143f-4d0f-bde2-9be97e3fc535">5</alampunktNr>
						<kuvatavNr id="ee81f4b1-6f99-4262-80a1-60fce06094e6"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="2d71628c-dad7-4dad-b89a-a36ed6ec0da4">
							<tavatekst id="37c8aab8-2fc5-41ca-bb52-67bd84afc2b0">a communications undertaking provided in the Electronic Communications Act who provides cable distribution services consumed by at least 10,000 end-users and a broadcasting network service provider upon providing cable distribution services or broadcasting network services;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p6">
						<alampunktNr id="7e1ca778-68ed-47a7-869e-5f14ed1d6b70">6</alampunktNr>
						<kuvatavNr id="dfb28120-8ceb-4184-9d6a-b196d0290c3c"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="01c58d92-a41d-472f-add7-fee2440769c4">
							<tavatekst id="7acdc3fc-4328-43c1-8566-ac9ce5bd3b0a">an owner of a regional hospital and central hospital of the hospital network provided in the Health Services Organisation Act upon providing in-patient specialised medical care and an owner of an ambulance crew upon providing emergency care;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p7">
						<alampunktNr id="151a2308-b5b9-44e5-a8c2-77a8884286a8">7</alampunktNr>
						<kuvatavNr id="bf40264f-80c9-4288-82b4-5b61a9c08faa"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="af949030-1b37-46af-b19b-d9cbb5570106">
							<tavatekst id="71ec3a49-0218-4ddc-bf99-2e9b989fc71f">a provider of family physician care provided in the Health Services Organisation Act upon providing family physician care;<reavahetus/>[RT I, 21.06.2024, 2 – entry into force 01.07.2024]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p8">
						<alampunktNr id="e1068895-335e-463f-8619-cf09489eb731">8</alampunktNr>
						<kuvatavNr id="ac7cf04d-1d0a-4fb7-b1ee-15eb46ae6e70"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="6df01846-499e-4769-98c3-d97c8cbbf53b">
							<tavatekst id="7654fd08-a3fc-4a5b-9bf9-8cb4ed257392">the administrator of the top-level domain name registry associated with the Estonian country code upon providing the service of the system and top-level name server used for the maintenance of the registry;<reavahetus/>[RT I, 22.05.2018, 1 – entry into force 01.01.2020]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p9">
						<alampunktNr id="de495578-4dcd-42be-abd8-fa1b8238971a">9</alampunktNr>
						<kuvatavNr id="e71f4a0e-0a26-4919-9d67-2cd50a442e8d"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="4ffb5ff0-188b-4eab-ad9c-48bfe3896bb0">
							<tavatekst id="eee62b56-fd5b-4901-94b7-241375890607">a provider of critical communications services, marine radio communications services and operational communications network services for the purposes of the Electronic Communications Act upon providing those services;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg1p10">
						<alampunktNr id="85e0293f-731e-4063-a67d-dfe4c5e51443">10</alampunktNr>
						<kuvatavNr id="2938e634-ef51-4c17-8300-307b020062a0"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="78048ebf-dcfa-4ba3-acf6-4c5402aa7fc9">
							<tavatekst id="dce069dc-b4fa-4b0a-914c-71d9780b1b69">Estonian Public Broadcasting upon performing the function provided in clause 10 of subsection 1 of § 5 of the Estonian Public Broadcasting Act.<reavahetus/>[RT I, 22.05.2018, 1 – entry into force 01.01.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3lg2">
					<loigeNr id="54669f20-bbaf-49a3-857d-049ac3afbb6c">2</loigeNr>
					<kuvatavNr id="82d6bb56-5c29-42f1-b5ed-6da88852cf6e"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="2584069d-98a9-4a01-a9a2-c9fd2dcc6391">
						<tavatekst id="644b2ad3-05bc-4573-bbc8-269221ae2f6d">Service providers specified in subsection 1 of this section who operate in sectors set out in Annex II to Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.07.2016, pp 1–30) are deemed to be operators of essential services for the purposes of said Directive.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3lg3">
					<loigeNr id="fdbd8e52-57eb-4a87-a79d-1f26ef2d435b">3</loigeNr>
					<kuvatavNr id="6900a51e-8283-4ee5-8c91-be6bf096637e"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="cc4244e2-988e-4920-a0c1-55704f8e877e">
						<tavatekst id="5abcd7d9-24d6-458c-87ff-1a7fb2203860">Every two years the Estonian Information System Authority identifies the service providers who fall in the scope of this Act and operate in sectors set out in Annex II to Directive (EU) 2016/1148 of the European Parliament and of the Council.<reavahetus/>[RT I, 22.05.2018, 1 – entry into force 01.01.2020]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3lg4">
					<loigeNr id="77fae8b1-6bc5-4438-b8b7-d81fb7524f2c">4</loigeNr>
					<kuvatavNr id="762257a0-0eff-41f2-acbf-91a40242096b"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="a4bb9277-c7e1-4b6b-898c-6a4f6e63bafd">
						<tavatekst id="20de2340-49d7-437c-8b83-8d99afa08716">The provisions of this Act concerning service providers are also applied to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg4p1">
						<alampunktNr id="cf6f48f5-1fc5-4ae8-bdc8-0f726afa06ba">1</alampunktNr>
						<kuvatavNr id="efc2755c-527f-4b16-aefe-d2fcc241bee8"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="7cf18605-44f4-4f43-8e81-56e84d401926">
							<tavatekst id="045df7ad-0005-4a46-81be-9ea9300bd8ed">a database controller and processor;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p2">
						<alampunktNr id="6ba4517f-01f9-4fcd-ab69-782a5acf02c9">2</alampunktNr>
						<kuvatavNr id="91383c4a-1619-4485-965e-c3794cc91fdf"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="6f844431-897d-4f1e-814e-94967856c70a">
							<tavatekst id="c7a17005-5321-4604-9b26-77d473402fa5">the Foresight Centre;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p3">
						<alampunktNr id="3914694a-78fa-4fd0-9af4-62c52e7cfa56">3</alampunktNr>
						<kuvatavNr id="f50da0d5-76f7-4ae8-95be-fddd4c2fab1f"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="a9f2a550-105e-49e3-bf31-a1dbbbba4242">
							<tavatekst id="3cbf7fe0-3b52-4534-9ee0-28a3f93d90e3">Eesti Pank (Bank of Estonia);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p4">
						<alampunktNr id="575b9804-2854-4ea2-9523-19e151bf3ac2">4</alampunktNr>
						<kuvatavNr id="ac83161c-c660-4973-bf8c-259b905ed79c"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="d844053a-3410-4f10-818f-26211b9ab885">
							<tavatekst id="57bcb12b-f151-46ad-b5c1-d2b2a197d524">a local authority and a local authorities association;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p5">
						<alampunktNr id="97352313-66bf-4cd2-8519-97aef5b7f6e6">5</alampunktNr>
						<kuvatavNr id="1ffae187-c155-4d79-a370-7bf5b7124ee8"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="7893681a-042c-4a89-b9b1-50596c4f4abf">
							<tavatekst id="a9b9de3f-3105-4c89-895e-ea5572b8d74c">a judicial body;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p6">
						<alampunktNr id="3b5e449c-2a57-433e-a717-7156018aab28">6</alampunktNr>
						<kuvatavNr id="52e8c97d-2b0f-4c37-8562-9736d6616ecc"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="0c35d2e2-bd21-4485-b15a-ff504c897f94">
							<tavatekst id="e5dffed2-3e49-4256-8276-b014486df947">the State Electoral Office;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p7">
						<alampunktNr id="65b0887e-75ed-4b68-b7b9-3f091dd4e0b8">7</alampunktNr>
						<kuvatavNr id="30982f45-9c48-46ab-bfd9-9719b987cde0"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="11ec6f5a-4587-4be4-b009-e092a7b55835">
							<tavatekst id="ad1400cd-1856-4380-9aa7-467fd1f0edfa">the Chancellery of the Riigikogu;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p8">
						<alampunktNr id="435a98b6-46f2-4e19-8e06-f71d99b45b1b">8</alampunktNr>
						<kuvatavNr id="7bf5765b-758e-46fe-b6ee-d3181c6b2cb5"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="3edf3392-ff02-4a32-9d1a-94c7aebf1f27">
							<tavatekst id="022b381f-7c81-46b8-8ba9-e8fd9475141f">the State Audit Office;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p9">
						<alampunktNr id="a90f8af0-066c-41a3-95fa-da5dc03f29d1">9</alampunktNr>
						<kuvatavNr id="9a55a635-cf9b-41d8-9fad-01f445d28c01"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="a9bc46a3-e9ef-4a0c-857b-80554943e54d">
							<tavatekst id="d34dcfdf-3e20-4137-aed5-03810c3ec2d1">the State Forest Management Centre;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p10">
						<alampunktNr id="f97fb109-89c1-4701-b4e4-5d8cf5e86e1b">10</alampunktNr>
						<kuvatavNr id="5e336d45-763e-4930-8881-45fa0467ecac"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="de3dbc89-f58c-4a5c-bc3b-ae58c816b860">
							<tavatekst id="cc994249-d17e-4b17-9d58-adb4c00977e9">a legal person governed by public law founded on the basis of law;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p11">
						<alampunktNr id="abb1657f-6786-41d9-99ac-baa810f8c837">11</alampunktNr>
						<kuvatavNr id="ed428980-b8f9-4ba8-b67f-0bfad3536399"><![CDATA[11) ]]></kuvatavNr>
						<sisuTekst id="ba33b874-22c3-4a42-a85f-7d9305f24a12">
							<tavatekst id="f1a76913-8ea8-422f-8465-23f17d9e1ec3">the Office of the President of the Republic;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p12">
						<alampunktNr id="6a44d7f2-0b1a-4a27-834f-0127d62e6379">12</alampunktNr>
						<kuvatavNr id="a5018f1f-37ac-436b-8549-ab60c4bcb638"><![CDATA[12) ]]></kuvatavNr>
						<sisuTekst id="f5537353-384b-441e-868c-030d152e9a46">
							<tavatekst id="257b8b35-1f5c-425a-9fe7-afb02343aa76">a governmental authority and a state agency governed by a governmental authority;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p13">
						<alampunktNr id="1344d072-13a1-4a49-abd1-b4e5b0932031">13</alampunktNr>
						<kuvatavNr id="89539970-ad1f-4f2a-9a6b-23c76437a830"><![CDATA[13) ]]></kuvatavNr>
						<sisuTekst id="35134f4e-a0ff-4f2a-90b6-2fdb19ec47e3">
							<tavatekst id="38a94ec0-152d-4856-80d1-16e26dbed172">a rural municipality or city administrative agency, an agency under the administration of a rural municipality or city administrative agency, a rural municipality district, a city district, an administrative agency of a rural municipality district or city district, an agency under the administration of an administrative agency of a rural municipality district or city district, and a joint administrative agency and joint agency of local authorities;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p14">
						<alampunktNr id="9f41451f-b8e7-4876-a628-ab8afe38542e">14</alampunktNr>
						<kuvatavNr id="89fc8d95-fd81-41fd-bb70-40833dd84b5b"><![CDATA[14) ]]></kuvatavNr>
						<sisuTekst id="85dd3f59-70d4-4f64-b79e-73c488785520">
							<tavatekst id="ab1ca376-f7b7-4d40-8410-1cc3fd9bab60">the Office of the Chancellor of Justice.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
			<paragrahv id="para4">
				<paragrahvNr id="de293fd7-3dd2-41c7-b085-a96682f3034d">4</paragrahvNr>
				<kuvatavNr id="c931d0dd-3a58-46c5-b5d8-cf4945189392"><![CDATA[§ 4. ]]></kuvatavNr>
				<paragrahvPealkiri id="473f9718-7d10-4a50-966c-b24a0d5ee557">Digital service provider</paragrahvPealkiri>
				<loige id="para4lg1">
					<loigeNr id="42af165e-219b-4566-a9de-af9bfad02803">1</loigeNr>
					<kuvatavNr id="bbf7ea70-5cab-45c3-9cbc-8031f10aa547"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="ec2cb45c-3ea9-4fc0-abad-6b6b0fae8f33">
						<tavatekst id="46d90d73-070d-41a1-98d9-5881e00763c7">For the purposes of this Act, ‘digital service provider’ means an information society service provider provided in the Information Society Services Act who:</tavatekst>
					</sisuTekst>
					<alampunkt id="para4lg1p1">
						<alampunktNr id="7d8607b0-d5bb-4327-8532-1aa36f7fd907">1</alampunktNr>
						<kuvatavNr id="de1e5b16-d4f8-4e3c-9e52-f36ccfa7beaf"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="db708a2f-763c-42ad-bf8e-74a219df298b">
							<tavatekst id="483ab584-2c69-46cd-9aa8-e0c61d12b659">offers an online marketplace;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p2">
						<alampunktNr id="330d535b-798b-406c-81a9-988a1e1a3311">2</alampunktNr>
						<kuvatavNr id="68c8681c-e726-44bf-89ce-6b89e12788be"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="a90a1f03-357c-4cc2-ab14-75accca4eede">
							<tavatekst id="1927d8fe-4c0a-4210-95c9-25c83d9ffd96">offers an online search engine; or</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p3">
						<alampunktNr id="18018b0b-b5a9-4672-bc6d-cc5904de87ec">3</alampunktNr>
						<kuvatavNr id="9801eb23-0e05-4162-8cd4-bf666aa1429b"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="b968f15f-72ad-4174-b623-50acec304757">
							<tavatekst id="d6a45730-6983-41ce-ab9a-4ee44d27375f">provides cloud computing services.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para4lg2">
					<loigeNr id="b2595915-5634-434a-8509-4f2056cceeb6">2</loigeNr>
					<kuvatavNr id="56acb78c-0329-4a7c-8e19-a36551f76435"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="85068439-8655-46aa-a0bb-06b621916ea8">
						<tavatekst id="c354e4df-0178-4ae4-94ea-fa13da71ceb6">A digital service provider who provides services in Estonia but is not established in the European Union must designate a representative in Estonia or in another Member State of the European Union where they provide services and must make the representative’s contact details permanently publicly available.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para5">
				<paragrahvNr id="f435c720-01e9-4aaf-a488-acae8e546b1c">5</paragrahvNr>
				<kuvatavNr id="6594d972-f328-4cf5-a72a-e30b65fbe96c"><![CDATA[§ 5. ]]></kuvatavNr>
				<paragrahvPealkiri id="be937614-841c-4ef5-a65b-ab001918560b">Single point of contact and competent authority</paragrahvPealkiri>
				<loige id="para5lg1">
					<loigeNr id="75262f59-1a5f-4b9c-a702-0e2ea1889922"/>
					<kuvatavNr id="c2e08edc-bc4f-4987-9660-047e0c5fa43d"/>
					<sisuTekst id="a29edba5-f975-4a40-a004-c733d6d407a9">
						<tavatekst id="794a8b36-d2f9-4a4a-ab5e-6484dca4aa53">The Estonian Information System Authority has the roles of the competent authority referred to in Article 8 (1) of Directive (EU) 2016/1148 of the European Parliament and of the Council and the single contact point referred to in Article 8 (3) and the computer incident response team referred to in Article 9 (1).</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para5b1">
				<paragrahvNr id="5a9b7edd-d7ee-44eb-8f76-fdfebbee6aee" ylaIndeks="1">5</paragrahvNr>
				<kuvatavNr id="2a234d20-5ed0-4171-aacf-2dc846b0bc7d"><![CDATA[§ 5<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="0fd49420-8bee-4fc7-8a7e-ea897f425b61">European Cybersecurity Industrial, Technology and Research Competence Centre and National Coordination Centre</paragrahvPealkiri>
				<loige id="para5b1lg1">
					<loigeNr id="65a51f11-a6d0-4c2f-b2b7-5eae209963c2">1</loigeNr>
					<kuvatavNr id="83a8067f-b9e0-4569-bc5d-91a72b0fd5e2"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="da139836-46f3-45a7-b40e-d2c73fa59ca2">
						<tavatekst id="357e017b-6979-4b49-a35f-c69709443ed0">For the purposes of Article 12 of Regulation (EU) 2021/887 of the European Parliament and of the Council establishing the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres (OJ L, 202, 08.06.2021, pp 1–31), the representative and alternate of the Governing Board of the European Cybersecurity Industrial, Technology and Research Competence Centre are appointed by a directive of the minister in charge of the policy sector.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b1lg2">
					<loigeNr id="a23f49ab-70a1-4e75-ad27-d433c394e41b">2</loigeNr>
					<kuvatavNr id="914a09ba-22b0-45ed-9e41-b798116e8c99"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="5514086a-37df-45b6-a404-c36ae4922d08">
						<tavatekst id="e0c2c697-2805-43e5-b8de-76fc68751872">For the purposes of Article 6 of Regulation (EU) 2021/887 of the European Parliament and of the Council, the functions of the national coordination centre are performed by the Estonian Cybersecurity Industrial, Technology and Research Coordination Centre.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b1lg3">
					<loigeNr id="ea68ef26-2c50-4a14-920d-b10d628a9cd2">3</loigeNr>
					<kuvatavNr id="09c5dd48-981b-4fb3-88f6-99da95cc8737"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="feaca986-cda3-4f83-a5e3-7769f8921371">
						<tavatekst id="a8fa0a1e-3c96-46ba-bc2e-463f6791aabd">The coordination centre specified in subsection 2 of this section is appointed and the procedure for the performance of its functions is established by a regulation of the minister in charge of the policy sector.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para6">
				<paragrahvNr id="c852ff8e-ed95-4dec-8645-0c5da86fc566">6</paragrahvNr>
				<kuvatavNr id="c3090202-94e0-4fb6-81f2-f5eba2c1c83f"><![CDATA[§ 6. ]]></kuvatavNr>
				<paragrahvPealkiri id="3f6204c0-671f-4e75-b636-3c18bd8bf7f3">Principles of ensuring cybersecurity</paragrahvPealkiri>
				<loige id="para6lg1">
					<loigeNr id="529646be-6a11-4d02-b68d-e82634c5a8fd"/>
					<kuvatavNr id="91254d49-4525-4c42-b2a7-eb292f5f83f9"/>
					<sisuTekst id="54ab33e2-36df-4d82-b159-5fa7d9c137b7">
						<tavatekst id="b57800ba-00c5-4767-a972-e6c7edac8bea">The following principles are taken into account in ensuring cybersecurity:</tavatekst>
					</sisuTekst>
					<alampunkt id="para6lg1p1">
						<alampunktNr id="bd5f5365-e258-4905-8a1e-58adc3177b9a">1</alampunktNr>
						<kuvatavNr id="0e52ff05-091f-49db-8a40-9be43364457a"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="5635a645-669d-4e84-b1ba-24f486742740">
							<tavatekst id="07e085bc-b3d3-4c87-8b15-f693d7410dfc">the principle of personality – ensuring the security of a system is arranged by the service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p2">
						<alampunktNr id="46caa2f6-a379-4ca8-a1ba-d41ead1d9e6b">2</alampunktNr>
						<kuvatavNr id="da80ab0e-4d54-493f-8617-a60b174f9e57"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="43cf289b-391f-4422-9b86-31188f86d94f">
							<tavatekst id="726894c4-a0b1-4025-a8fe-5713109a3b1a">the principle of integral protection – the service provider ascertains potential risks posed to the system and applies appropriate organisational and technical measures for the protection of the system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p3">
						<alampunktNr id="2fdcc657-ef6e-4283-acf5-28dc4132438e">3</alampunktNr>
						<kuvatavNr id="39ab7df7-a0c5-4e1d-b999-d4fdbd5dc5f1"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="f1feea4c-9e69-4696-b63b-c93b48f04f14">
							<tavatekst id="4380bca5-c731-4e86-89d8-a49134fca0d9">the principle of minimising adverse effect – in the case of a cyber incident the service provider applies due care and measures to avoid the escalation of the effect of the cyber incident and its possible spread to another system and notifies the supervisory authority provided in this Act of the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p4">
						<alampunktNr id="dc565708-57a9-4e86-861d-11d4f38eb08b">4</alampunktNr>
						<kuvatavNr id="fbe90f6b-c1cb-4fc9-bb69-0275fe8387a7"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="3a804cc8-1e0b-4d7a-9a0a-320b234d51d2">
							<tavatekst id="b2c23faa-a89f-48f6-a484-a2bf6af691e1">the principle of cooperation – in ensuring cybersecurity and resolving cyber incidents the parties co-operate and, where necessary, take into account the mutual connection between and dependence of the systems and services.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="675c6213-0214-40e5-8c66-e4aaef458b21">
			<peatykkNr id="64c8fcc0-c30d-40dc-9fee-0077f6e1391d">2</peatykkNr>
			<kuvatavNr id="94a6c3a1-79fa-4339-bf1c-50860afbdad0"><![CDATA[Chapter 2]]></kuvatavNr>
			<peatykkPealkiri id="fa7232b2-0a86-4a19-824f-d2f6a479d007">Obligations for Ensuring Cybersecurity </peatykkPealkiri>
			<paragrahv id="para7">
				<paragrahvNr id="b40bbac4-1bde-4cb1-b2b1-df9d1ca02287">7</paragrahvNr>
				<kuvatavNr id="ccf3b1ef-a6b0-41f3-82dd-5dbcfac36a8e"><![CDATA[§ 7. ]]></kuvatavNr>
				<paragrahvPealkiri id="a56e7965-1715-413a-876c-1515f31b326e">Security measures of service provider’s system</paragrahvPealkiri>
				<loige id="para7lg1">
					<loigeNr id="35a9100a-69ce-49b6-8197-3515fd665dc3">1</loigeNr>
					<kuvatavNr id="fcc03cbb-bd3e-404a-a57b-2508964990c3"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="669baf20-8261-4166-b609-09192ebea8fd">
						<tavatekst id="d5c365ed-070f-4008-a193-7fa3ea62af3f">A service provider is to permanently apply security measures:<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg1p1">
						<alampunktNr id="f07557ae-8dc2-4f48-8bd7-fd62e2adf773">1</alampunktNr>
						<kuvatavNr id="1de60921-649d-4d21-b1ee-eebca0d45e4a"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="8047b67c-9a14-44dc-9a8b-64848e804296">
							<tavatekst id="eb4167e9-4503-4f2c-9b15-a0c72b604bcc">for preventing cyber incidents;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg1p2">
						<alampunktNr id="6fc35564-e526-40d6-8386-06dd6c235105">2</alampunktNr>
						<kuvatavNr id="a2013aed-c354-479b-8cd1-8aaf707510ca"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="4d25ff79-5f1e-45a5-89ae-b4d09e9955e6">
							<tavatekst id="05bdf797-5259-432f-9f61-36ccc881e325">for resolving cyber incidents;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg1p3">
						<alampunktNr id="441876ca-8d7f-496a-82ba-cb3363829317">3</alampunktNr>
						<kuvatavNr id="6decee2b-38b4-4dbb-b477-5f0bba85fb8f"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="0750ea2c-b876-4923-90f0-9d3689b9e51a">
							<tavatekst id="41ec867c-41d6-4462-b50d-6c63c184cc28">for preventing and mitigating an impact on the continuity of the service or the security of the system due to a cyber incident or for preventing and mitigating a possible impact on the continuity of another dependant service or the security of a system.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para7lg2">
					<loigeNr id="0ae79613-d526-42c2-ba5d-3aee5ba7cd6f">2</loigeNr>
					<kuvatavNr id="e3a4631d-2b26-4c26-b0b2-3e1577130038"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="506e6b18-0e44-4d52-ab34-73519c1fbc0d">
						<tavatekst id="8fee4914-cec6-43d5-adae-711fbcfd691d">Upon the application of security measures, the service provider is required to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg2p1">
						<alampunktNr id="0f096c3d-fc7e-4f38-aec4-ebe4b3db5ef2">1</alampunktNr>
						<kuvatavNr id="4b0ca2a8-dfb9-4fd3-b7ce-020f5a868297"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="1d80d075-d702-4129-8905-0f953573b880">
							<tavatekst id="e2e52c43-5b99-4bd1-965e-c011e9adc2f1">prepare a system risk assessment in which they must set out a list of risks affecting the security of the system and the continuity of the service and causing the occurrence of cyber incidents, determine the severity of consequences of a cyber incident occurring upon the realisation of risks, and describe the measures for resolving a cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p2">
						<alampunktNr id="a79c26a1-2867-4512-98cf-750305f4c022">2</alampunktNr>
						<kuvatavNr id="347fa8d7-97bf-4446-899c-6b9626fbd570"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="771c4c6d-a315-4fea-beeb-b922e5cbf377">
							<tavatekst id="e266561d-d0c2-4d42-a533-ce404a478765">ensure the existence and timeliness of a documented system risk assessment, security regulations and description of the application of security measures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p3">
						<alampunktNr id="bbfe7051-f27a-432e-a412-8a18d99bf734">3</alampunktNr>
						<kuvatavNr id="43338daa-747f-440f-9291-d1f318a2612e"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="5e4b0529-cb14-434a-9903-21d76253b291">
							<tavatekst id="986a1630-e698-4d88-b968-6fe82e324a67">ensure the monitoring of the system for detecting actions or software compromising its security and communicate information about the actions or software compromising the security of the system to the Estonian Information System Authority;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p4">
						<alampunktNr id="56d2a0da-8ed4-4209-b38d-1bb26d9a6e58">4</alampunktNr>
						<kuvatavNr id="33b2d45a-40d2-4cc0-a0c4-5965181d317c"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="9779b37a-2877-4bca-843b-f496c1fd8ebd">
							<tavatekst id="62ea40c2-d244-4afc-8c39-153c67390f97">take measures for reducing the impact and spread of a cyber incident, including restriction of the use of or access to the system, where necessary.</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p5">
						<alampunktNr id="96203bd5-d8e5-4ed0-bcd6-9ae7aed6c2b3">5</alampunktNr>
						<kuvatavNr id="908cc495-4179-4c0b-b64d-da2737423096"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="3cc9f26e-3037-431b-988b-3efd70d7e3e7">
							<tavatekst id="c3affc6f-a73d-4301-b6fa-9b51f6745fd6">[repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p6">
						<alampunktNr id="4e7ccb6b-5f80-45de-9965-f1f404c0668c">6</alampunktNr>
						<kuvatavNr id="5a53b443-0aeb-4864-891c-af6e8c5c08f1"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="0cd0064b-48eb-4c19-aabf-4bb49603a6d5">
							<tavatekst id="24c34a70-1e46-472f-8980-e6c5fbbf7b2b">[repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para7lg3">
					<loigeNr id="089e429a-acce-4bef-bb4e-4da73f1cc91a">3</loigeNr>
					<kuvatavNr id="0e080363-317e-425f-9b03-019db582bb63"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="95dbcd9b-e2da-46f4-9ebf-e4d777194079">
						<tavatekst id="54729b01-5d20-412a-a1a7-826d864bb44a">If the service provider authorises another party to administer the system or uses another party to host the system, the service provider is responsible for the application of the security measures of the system by the other party.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg4">
					<loigeNr id="8c3fb87d-b23f-42e6-8c0c-153897834526">4</loigeNr>
					<kuvatavNr id="a6def745-6dcf-4344-9e5d-4904207c9850"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="a3020d58-029c-4382-ac8c-8408965a1f9d">
						<tavatekst id="658de530-5a8b-40e0-a806-61d5c340aae5">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg5">
					<loigeNr id="cd161f61-1881-44b0-8988-b94dccaf8ce6">5</loigeNr>
					<kuvatavNr id="65886a1e-01fe-47fe-b601-71d467477775"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="65022003-a7e1-432d-80bf-86077a10e589">
						<tavatekst id="69848ff2-dd76-43e4-843c-f1b5eaca7a1b">For ensuring the performance of the obligations provided in this section and the cybersecurity of systems, the Government of the Republic or a minister authorised thereby establishes by a regulation:</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg5p1">
						<alampunktNr id="642e12d5-188d-4976-9516-cb4c1cca89b7">1</alampunktNr>
						<kuvatavNr id="150c0a78-2e81-4e52-912c-7f7728f5775a"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="828af301-0767-43a6-8f22-39e25efdc012">
							<tavatekst id="27bf4151-905e-4194-b636-a96bb3cb783b">requirements for information security management under general title ‘Estonian Information Security Standard’;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg5p2">
						<alampunktNr id="a4c13639-76c9-48fb-9516-c61bcdb7bfd4">2</alampunktNr>
						<kuvatavNr id="ef5aa8e5-7d95-441c-b82c-05ec80df2cc9"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="aded5930-3f91-4cf4-b5e2-3cb4b9f3b517">
							<tavatekst id="42204499-c421-43bc-862f-7c79c40e1a0b">general requirements for security measures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg5p3">
						<alampunktNr id="b0195db9-2aeb-4037-ba8c-8ef187e8833f">3</alampunktNr>
						<kuvatavNr id="cf4e394c-ec54-46ef-9a23-947e3a433c1b"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="aff60357-df29-451f-a46c-ba0f150add6e">
							<tavatekst id="889b22e0-eb18-46e0-ae5b-553952b8f95b">special requirements for system security measures and the scope of application of such requirements.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
			<paragrahv id="para8">
				<paragrahvNr id="635445a2-eb32-434a-ab98-36684db3339d">8</paragrahvNr>
				<kuvatavNr id="178d9ab0-330f-417b-84a8-8c9f94b4ebe0"><![CDATA[§ 8. ]]></kuvatavNr>
				<paragrahvPealkiri id="7eb71885-c694-4d0d-a05f-399952fde94e">Obligation of service provider to notify of cyber incident</paragrahvPealkiri>
				<loige id="para8lg1">
					<loigeNr id="ad95e49a-a661-4497-977c-5f3fdea1bded">1</loigeNr>
					<kuvatavNr id="6ddef7f7-3cf5-4989-8143-c1655835f11c"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="3fafeb3b-9633-4df1-827e-d388291a87fb">
						<tavatekst id="71837d52-14aa-4001-81ef-b4927741b3b4">A service provider informs the Estonian Information System Authority immediately but no later than 24 hours after becoming aware of a cyber incident:</tavatekst>
					</sisuTekst>
					<alampunkt id="para8lg1p1">
						<alampunktNr id="8785d811-a3e5-4970-885b-6c9fa49bd2c3">1</alampunktNr>
						<kuvatavNr id="fef03900-dd9c-40a6-bf7a-fda43f0fa939"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="2c59611d-3646-48a2-9a02-ad79109ac47e">
							<tavatekst id="e51d3e36-8ae6-44e4-bbce-f5a3bb1ff6f3">which has a significant impact on the security of the system or the continuity of the service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg1p2">
						<alampunktNr id="a026cb36-1be9-49ca-b06e-209a202da246">2</alampunktNr>
						<kuvatavNr id="d7d064bb-f552-467f-8802-40a1eb1e4246"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="2c517dfb-3ee9-4c70-9bcf-7b206b1d8322">
							<tavatekst id="5c8863ab-54d4-4efe-bf28-6fb489c99728">a significant impact of which on the security of the system or the continuity of the service is not obvious but can be reasonably presumed.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para8lg1b1">
					<loigeNr id="82aa7e35-e619-4855-9eb0-c1adb573f60a" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="a329570c-75fc-4517-a743-982244e61a30"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="efa4f2a8-f83e-4af7-84b9-288c32de10ea">
						<tavatekst id="29d5582d-9c30-47b9-a0a7-4d4befed9ace">If a service provider authorises another party to administer a system or uses another party to host a system, the service provider is responsible for ensuring that the other party informs the service provider no later than 24 hours after becoming aware of a cyber incident specified in subsection 1 of this section.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg2">
					<loigeNr id="58cc4183-a36b-41c4-b3f4-1c11cd91d20c">2</loigeNr>
					<kuvatavNr id="34228a59-2e1f-4eec-be46-cc597b7fc75d"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="bd0f2ea7-cc29-4ea7-8594-d1fc2088ff76">
						<tavatekst id="b61ce888-af11-4886-a69d-759ea39abc65">A cyber incident has a significant impact if at least one of the following conditions is met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para8lg2p1">
						<alampunktNr id="203b5a30-e708-48a5-8223-c47ed69760ab">1</alampunktNr>
						<kuvatavNr id="677dd7ab-8a2b-4e12-bc6d-4790e6b83df9"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="99ebb125-41c8-43db-84a8-fa02091a28ee">
							<tavatekst id="6e1806d5-499c-4eac-a5cd-22fb65bd1262">the impact of the cyber incident is at least severe according to the degree of consequences determined in the system risk assessment prepared on the basis of clause 1 of subsection 2 of § 7 of this Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p2">
						<alampunktNr id="7b22ba03-3cf0-473c-aefc-5ede20baf744">2</alampunktNr>
						<kuvatavNr id="b6002422-4e25-4ae7-b445-281f7e66a10e"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="16f6ee5f-aab0-489e-a49e-e667a49a9bc1">
							<tavatekst id="05dd4a7b-8b80-4ebb-854c-63818d142316">due to the cyber incident the provision of the service cannot be continued after the passing of the maximum permitted time of disruption of the service provided by the relevant service level agreement or the requirements for the continuity of the service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p3">
						<alampunktNr id="9a09565f-8330-4d10-aca9-bf5369a5adf9">3</alampunktNr>
						<kuvatavNr id="7145bc06-8b0c-4eb5-98ca-a10fa6fa6a55"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="6590f9ce-14b4-4caa-bf8c-ef4020541482">
							<tavatekst id="9cae4ebf-3eff-4149-a6fe-7bc581775922">the continuity of the service of the provider of another service is disrupted due to the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p4">
						<alampunktNr id="bc5cbe40-1182-4c62-9a52-524df27b54b3">4</alampunktNr>
						<kuvatavNr id="8040ded1-9b14-4438-a3e3-f9934f6506de"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="eb638989-f9a5-4f19-b524-a3dcef2afc13">
							<tavatekst id="719905dc-4bd2-4188-b5c1-27bb4f7b195f">the extraordinary measures set out in the system risk assessment prepared under clause 1 of subsection 2 of § 7 of this Act or in another document, if any, describing the restoration of the continuity of the service or the security of the system need to be applied for resolving the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p5">
						<alampunktNr id="5417294d-b141-481f-83f3-b09be77ca334">5</alampunktNr>
						<kuvatavNr id="d4820dd0-b0b9-46f2-b485-ac8619fa10ee"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="c0ef682e-36e2-4141-9a7f-b2434c87465c">
							<tavatekst id="422412fe-434d-44b0-834e-eb251d9e04f0">the service provider, the provider of another service or service users suffer or may suffer significant damage due to the cyber incident.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para8lg3">
					<loigeNr id="a2bb4494-549a-4700-959d-057f808dad8c">3</loigeNr>
					<kuvatavNr id="b07b52fc-e7f7-4aee-8bfb-6ff21fcc890b"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="e4d80035-6474-48a0-a508-6bf4d10a9a2a">
						<tavatekst id="d479f8da-254d-4987-89cd-cef3232c7fd8">If as a result of a cyber incident the provision of the service or another service is disrupted in at least one more European Union Member State, the cyber incident is always deemed to be of significant impact.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg4">
					<loigeNr id="a48a9442-840a-4ae9-852a-1e9ebc59f314">4</loigeNr>
					<kuvatavNr id="249789a8-1519-408a-a440-838412c33d92"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="93e92efa-031c-4129-bc8f-4918a642fe57">
						<tavatekst id="3cd4ce91-cd83-4fdf-a15f-dbf66921aca2">The obligation provided in subsection 1 of this section does not restrict the right of the service provider to notify the Estonian Information System Authority of a cyber incident that does not have a significant impact provided in subsection 2 of this section.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg5">
					<loigeNr id="8b4230ad-53b2-45ce-aa01-a892d821a22b">5</loigeNr>
					<kuvatavNr id="87a22821-68a9-406e-af06-4da4cbd6a653"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="2d151769-441e-4341-ad8c-5b564428c6b5">
						<tavatekst id="0d16bf4a-e8fa-4060-acfd-fea27a6abd5c">Within a reasonable period of time, the service provider is required to notify persons possibly affected by a cyber incident with a significant impact or the public if the persons affected cannot be notified individually.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg6">
					<loigeNr id="ff3d7985-3c49-4d0a-8000-3a5e3f861fdc">6</loigeNr>
					<kuvatavNr id="acd4858f-deed-4df7-a386-8b13d003ddde"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="3487622c-7fcc-4915-952e-f1e4871a2e22">
						<tavatekst id="11e44d2d-f52b-4577-8241-7b7fa083ffc7">If the service provider does not perform the notification obligation provided in subsection 5 of this section within a reasonable period of time, the Estonian Information System Authority may notify the person affected or the public itself, also informing the service provider of such notification.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg7">
					<loigeNr id="2eaade52-2e0a-42f1-91e1-2c23ba47828a">7</loigeNr>
					<kuvatavNr id="637a2176-1c98-4738-b9c7-78e55c7325b2"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="88f0f5b9-6de0-4936-87cf-bf568881514d">
						<tavatekst id="3b521eb1-17f2-42c9-8ec9-c3114fbab1e4">In resolving a cyber incident with a significant impact, the service provider is required to send the Estonian Information System Authority a report which includes information about the causes for the cyber incident, the time spent on its resolution, the measures applied and the impact of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg8">
					<loigeNr id="b38b0510-9890-4fef-affb-03207c168b2f">8</loigeNr>
					<kuvatavNr id="f902d8d0-bee8-46bd-a16f-53f18be154ef"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="6ca589fd-1572-47f4-a292-aad31e58ed89">
						<tavatekst id="d4798e3a-b112-432e-b4f3-2e30c886ff26">The procedure for notifying of a cyber incident and the format of the report may be established by a regulation of the minister in charge of the policy sector.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg9">
					<loigeNr id="a4f7bbd8-3513-4d54-869b-69383e35dcaa">9</loigeNr>
					<kuvatavNr id="96d15d37-372f-4815-b4dd-4352bee8e0b3"><![CDATA[(9)]]></kuvatavNr>
					<sisuTekst id="b7954904-b203-4781-aacc-2bf4f992fd3d">
						<tavatekst id="e4953177-eff9-4654-9393-2e822ee5c460">The service provider is required to notify the Estonian Information System Authority of the significant impact of a cyber incident concerning a digital service provider on the continuity of their service if their service depends on the service of the digital service provider defined in § 4 of this Act.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para9">
				<paragrahvNr id="061ed419-1e71-40fa-8072-d6661daa1a50">9</paragrahvNr>
				<kuvatavNr id="9729e234-4b4b-4e2f-ac1e-30a1a866af83"><![CDATA[§ 9. ]]></kuvatavNr>
				<paragrahvPealkiri id="75de1423-a0b6-4a8f-a206-5cc4ac09bc10">Security measures of state and local authority’s system</paragrahvPealkiri>
				<loige id="para9lg1">
					<loigeNr id="72f0d563-a1bc-4f1f-bd44-0bacf309ea74"/>
					<kuvatavNr id="78260b6c-77a4-418d-9081-ce28b287a101"/>
					<sisuTekst id="9aa0b2c1-83fd-4bda-bf8b-6f43bc9c3752">
						<tavatekst id="47384a63-9ddc-428b-866e-022c5db778c2">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para10">
				<paragrahvNr id="70f86514-40af-4406-bb5d-fc8e07df8479">10</paragrahvNr>
				<kuvatavNr id="59bc8dba-207d-47ed-8776-03fe8e185c07"><![CDATA[§ 10. ]]></kuvatavNr>
				<paragrahvPealkiri id="1e8ab182-bd25-457f-8393-c0ae19e52383">Security measures of digital service provider’s system</paragrahvPealkiri>
				<loige id="para10lg1">
					<loigeNr id="f7cedfb0-37b7-4481-8424-5513fc5e20e4">1</loigeNr>
					<kuvatavNr id="8925d102-7954-4976-b8ea-086fe02092f0"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="5d20d8dd-39f5-4a98-a6b5-4e7ee01c48c5">
						<tavatekst id="75d3e015-459a-48ce-834f-8e6ed3f983d1">A digital service provider is required to ascertain the risks posed to the security of their system and analyse them and take organisational and technical measures appropriate for risk management.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para10lg2">
					<loigeNr id="7699a4d2-f22b-4778-b5c2-74c0266bf6ad">2</loigeNr>
					<kuvatavNr id="8f68b183-197d-4f66-a2c0-7fb0f5567fdd"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="43b62f5b-e06f-4c42-9bff-9767cab00697">
						<tavatekst id="7ed61e31-5f71-4396-810e-f13f2caa0cdc">In choosing measures for ensuring the security of a system the following must be taken into account:</tavatekst>
					</sisuTekst>
					<alampunkt id="para10lg2p1">
						<alampunktNr id="7340a6cd-efeb-414b-800f-286fe422e82a">1</alampunktNr>
						<kuvatavNr id="c1814e29-7956-4436-8c36-c7d58e036c54"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="6a857017-e3e4-4ac8-809d-0dfa998c95db">
							<tavatekst id="ec2f4da8-cba0-4683-bae9-0b80bcb77243">the security of the technical infrastructure;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para10lg2p2">
						<alampunktNr id="c6606ac7-ff74-4298-a106-2c9207892c40">2</alampunktNr>
						<kuvatavNr id="df9c4fbb-b91f-4433-83e3-77be70dc6079"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="f08ae25e-a41e-42a7-9608-80057ab3d5b4">
							<tavatekst id="9c93bc09-38b0-48cf-9c4c-16945d4cf287">the prevention, detection and resolution of a cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para10lg2p3">
						<alampunktNr id="0d91541b-5bdb-473d-a3d2-1b71761e9041">3</alampunktNr>
						<kuvatavNr id="af1e2fc2-a7e1-418f-ac6c-fa21ab3190ed"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="822c7952-11dd-4226-9c27-c586405f54dd">
							<tavatekst id="82a24498-3a08-4662-9683-b6f9042c2989">continuity management;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para10lg2p4">
						<alampunktNr id="f279146b-e4a8-4c1c-b407-b1f4b077ad50">4</alampunktNr>
						<kuvatavNr id="382c05cb-4258-41f0-93c3-271ecba94dc9"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="61cedd87-e1e8-4ab7-93c7-a56d377c2637">
							<tavatekst id="429a3f76-dbf6-4081-a0ce-c420f1af6f68">monitoring, auditing and testing;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para10lg2p5">
						<alampunktNr id="47d49587-b944-4dad-af3f-dd4d4cf47870">5</alampunktNr>
						<kuvatavNr id="6f377ee3-3d92-4e67-93ed-f4ee29807765"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="c24c9866-bd16-459c-bbea-9a4917ba60a1">
							<tavatekst id="a11d3fa4-062c-4d04-90cc-1ec4cb3d9b6f">compliance with international standards.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para10lg3">
					<loigeNr id="eeaccf3e-0659-4c8f-b4ae-44ffefb2a4bc">3</loigeNr>
					<kuvatavNr id="598dfbb8-fac5-4733-8831-78d667d623cc"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="ed91163c-2e18-45f8-8f41-2a1b75a9763b">
						<tavatekst id="a81a3eb8-a679-4373-9444-262e5f1527f6">In applying subsection 2 of this section, the digital service provider is required to abide by the implementing regulation of the European Commission issued under Article 16 (8) of Directive (EU) 2016/1148 of the European Parliament and of the Council.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para10lg4">
					<loigeNr id="3d12f5b2-24af-4b7d-ba3e-d37860674c08">4</loigeNr>
					<kuvatavNr id="994cfb9f-b7e3-4286-b758-40d07eb296d6"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="da9c5a44-a8b1-4378-89b1-04d837dc9141">
						<tavatekst id="bb2224c2-bc41-4680-9844-f5f5a3b95b11">The digital service provider takes appropriate measures to minimise the impact of a cyber incident on the continuity of the service provided.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para11">
				<paragrahvNr id="0663c49a-08e5-4db8-957a-353c20818cfe">11</paragrahvNr>
				<kuvatavNr id="d03c52ed-1c73-4e5f-a617-9c66e851fede"><![CDATA[§ 11. ]]></kuvatavNr>
				<paragrahvPealkiri id="f5c104d3-bf2c-4046-b0d6-20e9ddd8fd9a">Obligation of digital service provider to notify of cyber incident</paragrahvPealkiri>
				<loige id="para11lg1">
					<loigeNr id="471295ad-e3b4-43bf-b584-973b442d222b">1</loigeNr>
					<kuvatavNr id="02a3da87-3e3b-4d68-9f77-01fc35c83294"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="e4bca3ad-b12a-4a4c-9d98-380094901635">
						<tavatekst id="4e7867d8-7098-4c80-afcc-ba8f95e824a9">A digital service provider notifies the competent authority or the computer security incident response team of a cyber incident which has a significant impact on the digital service provided, immediately after becoming aware of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para11lg2">
					<loigeNr id="9dcc7476-73eb-4c2d-b3d8-bba3675abdf1">2</loigeNr>
					<kuvatavNr id="c4762b3e-95b5-4ea2-9f34-4f9d4d2638cc"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="0655b954-d9bb-430f-9b08-6c19a6bda993">
						<tavatekst id="c2577feb-9ee1-4399-ba3f-a83bfbe7243d">A notification must be submitted to the competent authority or the computer security incident response team of the Member State where:</tavatekst>
					</sisuTekst>
					<alampunkt id="para11lg2p1">
						<alampunktNr id="af3e3306-7e1a-4b38-8c70-565270db620e">1</alampunktNr>
						<kuvatavNr id="82d7e89d-5a45-4a95-8a78-0d17c5ac113c"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="438aad04-6b52-438c-9190-411ee89681b4">
							<tavatekst id="f47fcb38-6c61-4af7-834d-9d474908c6ea">the digital service provider is founded;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para11lg2p2">
						<alampunktNr id="877ae0a6-0acf-4326-b2d6-a06e302d3ac6">2</alampunktNr>
						<kuvatavNr id="8eadc094-c2a5-4952-b1b4-99d6f233db3e"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="741a1ca1-d856-41dc-9e04-69282a8d6d4a">
							<tavatekst id="4edb7155-71e9-4f74-83c9-1fb3cf9c5f64">the parent company of the group is founded in the case of a group; or</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para11lg2p3">
						<alampunktNr id="9c573bbb-1569-4d94-bdf3-e1b36ea54c4c">3</alampunktNr>
						<kuvatavNr id="965e10d7-bfeb-4037-8567-796ade89c834"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="f2e31a9b-0acd-47cc-9333-bc0fbfbe276f">
							<tavatekst id="dab3a3b5-f2db-401f-acf6-734bff7c1236">the representative appointed by an economic operator from a third country is located.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para11lg3">
					<loigeNr id="59a51512-b950-4440-8c5d-3d2ce8512cfe">3</loigeNr>
					<kuvatavNr id="31b2d0b1-5a04-4083-926f-3b5d16447efd"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="80eb7b4c-4172-4dd6-8f9b-d914073260e7">
						<tavatekst id="7c46e81b-8262-4ece-93c4-405eda8385c8">Notifying of a cyber incident is based on the criteria provided in the implementing regulation of the European Commission issued under Article 16 (8) of Directive (EU) 2016/1148 of the European Parliament and of the Council.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para11lg4">
					<loigeNr id="32bae177-9e01-4fe8-be47-2b51d213a0e9">4</loigeNr>
					<kuvatavNr id="d3fc8a07-61f8-4185-ba15-95b56be998ae"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="3a55d6d4-2119-4973-a39a-e0797b3255ff">
						<tavatekst id="80c272f1-35f0-4f52-b0e3-e1321d09bbdf">The notification must include information enabling the competent authority or the computer security incident response team to determine any cross-border impact of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para11lg5">
					<loigeNr id="741b804e-30b1-4b63-b7af-494ff1e01263">5</loigeNr>
					<kuvatavNr id="7207d090-08c9-4ebf-a94d-abfb0a2c3424"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="48522684-a467-4b77-adef-e1501fda0543">
						<tavatekst id="14684e43-8118-4a65-b77e-816f4eccb469">If a cyber incident has a significant impact on the continuity of a digital service in another Member State, the Estonian Information System Authority notifies the affected Member State on the basis of the information presented by the digital service provider.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para11lg6">
					<loigeNr id="5af84371-fb8c-45a3-810a-4e28330fe42d">6</loigeNr>
					<kuvatavNr id="d28a7ffc-cb34-4fe4-93d7-cb28fd04a95f"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="6f614974-c410-4958-9d71-891255e0a610">
						<tavatekst id="a0d75563-793b-4a72-a79e-831c5da4c790">If for the purpose of preventing a cyber incident or resolving an on-going cyber incident and in the public interest it is necessary to notify the public, the Estonian Information System Authority may, after informing the digital service provider, notify the public of the cyber incident or require the digital service provider to do so.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para11lg7">
					<loigeNr id="79188735-02f0-4e11-a333-a864bb705790">7</loigeNr>
					<kuvatavNr id="c53000cd-8796-4476-a794-35a33cdf09b4"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="7cfaf61a-4722-4a5a-8511-0f676d4c3123">
						<tavatekst id="d43dd508-f77b-4296-be33-4298633b8360">Subsection 1 of this section is not applied if the digital service provider lacks information for identifying the significance of the impact of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="bf73ed11-2a28-4ed2-bb6a-71f3ea102b95">
			<peatykkNr id="3e9be8bc-fe30-41e2-937b-d3d8c366eb47">3</peatykkNr>
			<kuvatavNr id="6be5acf2-1f07-42eb-bb19-199770fed48b"><![CDATA[Chapter 3]]></kuvatavNr>
			<peatykkPealkiri id="b0cce574-9664-4cd1-bc7d-a2fdaea962b2">Ensuring Cybersecurity </peatykkPealkiri>
			<paragrahv id="para12">
				<paragrahvNr id="70714e6d-d9d9-42b1-a848-14323a21a364">12</paragrahvNr>
				<kuvatavNr id="e7f04d8e-b3a8-4ab9-a85c-3098fd2f8170"><![CDATA[§ 12. ]]></kuvatavNr>
				<paragrahvPealkiri id="dec48aaa-34dd-4997-9f82-e4b2d4feb446">Prevention and resolution of cyber incident</paragrahvPealkiri>
				<loige id="para12lg1">
					<loigeNr id="6becbe9a-0725-476f-86b1-172454023c43">1</loigeNr>
					<kuvatavNr id="29238a51-1d19-4748-a326-75d87eb6713e"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="0b8098f9-8b69-494f-bf89-dc3fad6bff31">
						<tavatekst id="77429c22-fe25-4a4c-b1f4-631fb789f0ee">Ensuring cybersecurity and preventing and resolving a cyber incident to the extent provided by this Act is co-ordinated by the Estonian Information System Authority.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg2">
					<loigeNr id="66bec098-341a-4747-8b79-d38e09d109fd">2</loigeNr>
					<kuvatavNr id="4ba788a5-e8a7-44c0-8e38-db18e1bcd3cf"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="8e6f3004-6b46-4188-82df-165232ad4cfa">
						<tavatekst id="2fca0e7c-e435-4d0e-aa91-e66815545134">For the purpose of ensuring cybersecurity, the Estonian Information System Authority observes domains in the Estonian Internet protocol address space and related to the Estonian country code, analyses risks posed to the security of systems and the impact thereof on the state, society and the security of systems.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg3">
					<loigeNr id="25db90f3-7c8a-45ea-b097-6f069dd4d221">3</loigeNr>
					<kuvatavNr id="97ff5f4a-161d-4898-98a3-a310dfdeaeab"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="fa58d9f5-0946-4ee0-95c9-9828192af9fc">
						<tavatekst id="68a24c28-7ac9-46ea-8014-519456000c87">For the purpose of preventing and resolving a cyber incident, the Estonian Information System Authority sends people alerts enabling them to take measures avoiding or reducing the impact of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg4">
					<loigeNr id="f8555953-4691-41d6-b8d3-22d29e75e183">4</loigeNr>
					<kuvatavNr id="396b5d03-da49-4de3-972d-99d5d1765346"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="7277ab9d-53f8-4193-a7fa-e755261a7362">
						<tavatekst id="1ff7c439-85e1-4c3d-ba38-0849f9ecc22c">The Estonian Information System Authority has the right to forward to a foreign state or the European Union Agency for Network and Information Security or another organisation information related to preventing and resolving a cyber incident for the performance of the functions provided in § 5 of this Act or an obligation arising from European Union law or in cases and pursuant to the procedure set forth in an international agreement provided the information forwarded does not harm national security or criminal proceedings.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg5">
					<loigeNr id="29b8d677-c2fc-4cb8-a7a8-51d2a134e3ef">5</loigeNr>
					<kuvatavNr id="2ac6586a-1d82-4f34-8cb4-ae9912622797"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="e599080b-b28c-4bcf-b890-ec07a6c2b879">
						<tavatekst id="6805e7bb-fac4-41b6-bb68-55800222a489">When forwarding information, the Estonian Information System Authority takes into account the business interests of the service provider or digital service provider and abides by the obligation to keep business secrets.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para13">
				<paragrahvNr id="9db09acd-55a5-48e0-b57c-64036e73448d">13</paragrahvNr>
				<kuvatavNr id="bd8fbdb1-1f07-4d3c-9648-8695cb1bbfa4"><![CDATA[§ 13. ]]></kuvatavNr>
				<paragrahvPealkiri id="8e7f8e21-2eb7-4ff5-88f4-10991ec9d2a2">Cyber incident registry</paragrahvPealkiri>
				<loige id="para13lg1">
					<loigeNr id="3ca6d7ea-4b08-42a5-bec8-0dac9146c997">1</loigeNr>
					<kuvatavNr id="38cda566-b1dc-410c-8ad6-041041f2d652"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="166f78d3-d9b5-4968-887d-02698e90ad00">
						<tavatekst id="6d75b1b6-a036-4dbd-8178-909a18cfa24f">The cyber incident registry (hereinafter the <i>registry</i>) is a database maintained by the Estonian Information System Authority where data describing the occurrence of a cyber incident is entered for the purpose of keeping record of cyber incidents and analysing cyber incidents for resolving them, forwarding alerts and performing supervisory operations.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg2">
					<loigeNr id="18c12f1d-9d5e-45a6-b60c-37c78315e270">2</loigeNr>
					<kuvatavNr id="14a30840-a3a1-4f24-87e0-374fdcbdd579"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="6b3dc14b-4d67-41e6-a977-95539ab2ada5">
						<tavatekst id="bfdeaaea-f955-4db6-9529-b684bc537737">Access to the registry is restricted and the registry data is intended for internal use, unless otherwise provided by legislation.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg3">
					<loigeNr id="d3b40abc-1fcb-4e3a-a92b-4aa61a40edf3">3</loigeNr>
					<kuvatavNr id="2d7878ef-79b5-42d5-921d-908957d9bad3"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="533dfbac-1500-4bc5-ae8a-75433fd3d43b">
						<tavatekst id="4c59c445-a689-4733-891b-7bdb49175b09">The registry and the statutes thereof are established by a regulation of the minister in charge of the policy sector.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="ff3b1bc2-0966-4199-80ff-22a32c1b7672">
			<peatykkNr id="fb25341d-2197-4c62-8162-55498e8f3c82" ylaIndeks="1">3</peatykkNr>
			<kuvatavNr id="05516c46-e906-492f-a44a-0fe732bbc678"><![CDATA[Chapter 3<sup>1</sup>]]></kuvatavNr>
			<peatykkPealkiri id="cebaf3e6-536a-49af-a894-226f8056b296">Cybersecurity Certification </peatykkPealkiri>
			<muutmismarge id="bfab6b6b-0266-4b50-aab8-6450cbd19098">
				<avaldamismarge id="46e2064b-e81d-4045-b35c-bab3428b16e0">
					<RTosa id="21a2497f-1e4a-4185-9daa-4b592b02f954">RT I</RTosa>
					<avaldamineKuupaev id="948c2e19-4a3a-4c31-a567-3e653d7bc091">2022-08-06</avaldamineKuupaev>
					<RTartikkel id="d2dcc255-d665-419d-b6bc-96ba5747c0f1">2</RTartikkel>
					<aktViide id="3a14d976-ca08-48ef-b9da-2b29381c7a2c">106082022002</aktViide>
				</avaldamismarge>
				<joustumine id="fe8900db-bcbf-40d3-b507-7be404549630">2022-08-16</joustumine>
			</muutmismarge>
			<paragrahv id="para13b1">
				<paragrahvNr id="903866ef-8434-4025-8abb-62245132b1fe" ylaIndeks="1">13</paragrahvNr>
				<kuvatavNr id="ade90ad6-319e-4291-8d80-c28f615d4abd"><![CDATA[§ 13<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="9016c5b8-2ccc-411b-b38b-12a2aa0184d3">National cybersecurity certification authority</paragrahvPealkiri>
				<loige id="para13b1lg1">
					<loigeNr id="f54df5b2-ce8c-444e-a437-21b2a1602cf9"/>
					<kuvatavNr id="d365f884-72d7-4dda-a7cc-4f53d6990c36"/>
					<sisuTekst id="525dc5f0-aef6-43fe-a18c-57188b9a5050">
						<tavatekst id="a829ec50-df39-40be-a8b8-8c287e3869d0">For the purposes of Article 58(1) of Regulation (EU) 2019/881 of the European Parliament and of the Council on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 07.06.2019, pp 15–69), the national cybersecurity certification authority is the Consumer Protection and Technical Regulatory Authority.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para13b2">
				<paragrahvNr id="1fabb3f0-72ea-4bf4-9741-46b1d1fa8b1b" ylaIndeks="2">13</paragrahvNr>
				<kuvatavNr id="2509015e-3ed7-450e-9a0a-34f2348677a0"><![CDATA[§ 13<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="79eaf04c-57ad-403f-83c2-e6fed03e97da">Cybersecurity conformity assessment body</paragrahvPealkiri>
				<loige id="para13b2lg1">
					<loigeNr id="8ceba226-57a9-475f-86b1-f0a50453e05d"/>
					<kuvatavNr id="68ad88a3-a61e-4777-b36b-45cafff90cd5"/>
					<sisuTekst id="5f15a89d-ffd3-4fa7-99ff-7efa9446a967">
						<tavatekst id="c6eb6297-31fa-4c4c-8558-9b4fea1cd052">Operating as a conformity assessment body and issuing an activity licence to a conformity assessment body are subject to §§ 22–31 and 33 and subsection 1 of § 35 of the Product Conformity Act, taking into account the specifications set out in Articles 60 and 61 and in an implementing act of the European Commission adopted under Article 61 of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="82cf84cc-d4ed-4ba6-a9a4-d9e20a241a20">
			<peatykkNr id="3f5ece97-23ec-4dd6-af36-91a58a3f3f1e">4</peatykkNr>
			<kuvatavNr id="ead34e92-aae4-495e-b7a5-18f522c460f7"><![CDATA[Chapter 4]]></kuvatavNr>
			<peatykkPealkiri id="31390356-4fc0-4945-924b-5ff9febdb825">State and Administrative Supervision </peatykkPealkiri>
			<paragrahv id="para14">
				<paragrahvNr id="488c8b7e-a601-4110-9ad3-0254eaaf8636">14</paragrahvNr>
				<kuvatavNr id="82559081-c97d-4090-be5e-d065adca427e"><![CDATA[§ 14. ]]></kuvatavNr>
				<paragrahvPealkiri id="a0625a0c-92b8-4729-a629-43d620bb9422">Exercise of state and administrative supervision</paragrahvPealkiri>
				<loige id="para14lg1">
					<loigeNr id="a7d42b2f-f740-4dfb-a08f-027f3c007ffc">1</loigeNr>
					<kuvatavNr id="1af608ac-a523-4cb2-9466-d946548758d6"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="053678b1-3978-4be5-843c-8733bbdc5532">
						<tavatekst id="318cc1cf-670d-4726-b508-7a32976f1de3">State and administrative supervision over compliance with the requirements provided in this Act and in legislation established on the basis of this Act is exercised by the Estonian Information System Authority.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg2">
					<loigeNr id="b28bc70a-e98a-4814-8a7b-76e74ab7f436">2</loigeNr>
					<kuvatavNr id="86673fad-de9b-4ea8-a201-170c3183da00"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="6bd9b22d-bd75-467e-9271-54f8d7683305">
						<tavatekst id="8fd3a599-16df-4244-9a72-8ddfe8f67493">State supervision over the compliance with the requirements set for digital service providers by §§ 10 and 11 of this Act is exercised if the Estonian Information System Authority is notified of said requirements not being complied with by:</tavatekst>
					</sisuTekst>
					<alampunkt id="para14lg2p1">
						<alampunktNr id="1ed7f61d-f068-4782-8ffa-bc658a32df06">1</alampunktNr>
						<kuvatavNr id="8ee56523-1788-4904-9eba-49e93ab46e66"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="ce8209e9-bee2-40dc-860e-2cfe44cc86d9">
							<tavatekst id="4536a091-e1e1-4d13-8dc7-12b9cc773338">a digital service provider established in Estonia;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg2p2">
						<alampunktNr id="0b1e5714-4ab9-4b16-8e88-cb7f268fbbf5">2</alampunktNr>
						<kuvatavNr id="c22aaff1-d828-4269-bb3f-045acaeb735a"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="9d851b04-5f5d-484a-bde1-9e4e4eeb1ce4">
							<tavatekst id="2b121a04-73c3-44f7-a929-02784e1f461f">a digital service provider belonging to a group whose parent company is established in Estonia;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg2p3">
						<alampunktNr id="ebe2660c-0357-46a6-a55e-f2fbf32b86d4">3</alampunktNr>
						<kuvatavNr id="c1e37139-35c0-4b1c-8269-9d45415f1a17"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="e4113ed7-3ec0-4ff5-9d72-2e8f701394fb">
							<tavatekst id="57d352ce-3eeb-4e11-aeb6-b4b083160a1f">a digital service provider of a third country who has a representative in Estonia.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para14lg3">
					<loigeNr id="62e4e875-0a18-41c7-920e-bdb5569c404d">3</loigeNr>
					<kuvatavNr id="14a73009-46e0-4baa-b322-ff535c8b9f29"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="9e53109c-7443-4928-ba5f-cd90703136e9">
						<tavatekst id="396ab768-8cfe-4f27-bd0c-74b92052827d">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg4">
					<loigeNr id="0f66b3be-3d5e-46cf-ad9d-510863a7ce2a">4</loigeNr>
					<kuvatavNr id="36d9204e-4111-4e82-b120-e6a2d5f09a78"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="9055dd49-5b44-4dd5-8d61-7ffbf346172c">
						<tavatekst id="e6d5dc83-e098-453d-ad18-f4d8d080948f">The Consumer Protection and Technical Regulatory Authority exercises state and administrative supervision to the extent provided in Article 58(7) of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg5">
					<loigeNr id="0d3a496d-40cf-4b26-8168-40a9dc3866be">5</loigeNr>
					<kuvatavNr id="6583e3da-1826-4144-b661-3f6077f64c3d"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="ec4bdb9a-47e1-485f-b4ac-83d3dd8d69e3">
						<tavatekst id="381a48bb-e28e-4446-8d72-fbd144554a82">Administrative supervision over compliance with requirements for systems of a security authority as provided by this Act and legislation established on the basis of this Act is exercised by the relevant security authority.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para15">
				<paragrahvNr id="37e2867f-3ad4-4ee1-958d-9638bf0df235">15</paragrahvNr>
				<kuvatavNr id="51bdb7b2-fadb-4474-ae3a-6517a1449a20"><![CDATA[§ 15. ]]></kuvatavNr>
				<paragrahvPealkiri id="2e777c2d-ca0d-4396-bf8a-26914fc5203a">Special state supervision measures</paragrahvPealkiri>
				<loige id="para15lg1">
					<loigeNr id="5e78d4a9-9bbd-4dd8-a00e-f51ea568d7da">1</loigeNr>
					<kuvatavNr id="a957cea5-ca1f-4786-a30e-f7db4b612be1"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="94f3aa17-91f5-463b-ab67-f84762a1f2f5">
						<tavatekst id="ea7f2eab-1ab1-4780-a035-bf739a284e5b">In order to exercise the state supervision provided by this Act, law enforcement agencies may apply the special state supervision measures provided in §§ 30, 31, 32, 49, 50 and 51 of the Law Enforcement Act on the grounds and in accordance with the rules provided in the Law Enforcement Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para15lg2">
					<loigeNr id="9b4c726d-9bc0-42d0-9a5f-7903605bdc33">2</loigeNr>
					<kuvatavNr id="ce2184e4-7383-46a8-abb3-d1eaac37424e"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="397b737c-42cc-44cf-8bb1-3ec11a25a977">
						<tavatekst id="63152b9d-0068-4109-acb4-68632d0ff15d">Upon exercising state supervision over compliance with the requirements of §§ 7 and 8 of this Act and legislation established on the basis of said sections, law enforcement agencies may also apply, in addition to the special measures referred to in subsection 1 of this section, the special state supervision measure provided in § 52 of the Law Enforcement Act on the grounds and in accordance with the rules provided in the Law Enforcement Act.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para16">
				<paragrahvNr id="3345c9d4-2534-4f1d-8b41-895521eccfe0">16</paragrahvNr>
				<kuvatavNr id="082b0130-7902-4377-a111-05ffa12cc3d6"><![CDATA[§ 16. ]]></kuvatavNr>
				<paragrahvPealkiri id="a8a950e9-bc8f-4455-9205-5a2027a9922a">Specifications of state supervision</paragrahvPealkiri>
				<loige id="para16lg1">
					<loigeNr id="34831c5a-8058-4cc9-b965-302d07e187a6">1</loigeNr>
					<kuvatavNr id="0b84b1aa-ff63-48aa-bd3d-bf58a785a7ed"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="bdbdf908-2f35-42da-ab9e-5bd04058ec60">
						<tavatekst id="453b4429-e3fa-46b2-baf3-c385086c2ae7">For countering an immediate serious threat or eliminating a disturbance in case of a cyber incident the Estonian Information System Authority may restrict the use of or access to a system provided all the following conditions are met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para16lg1p1">
						<alampunktNr id="a7c86ac5-1ce8-473b-85f6-ed6effcadbad">1</alampunktNr>
						<kuvatavNr id="04ee4d19-2877-4bc3-8742-1f65d439e03e"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="03e7fb97-303a-4f3f-bf2f-0337a8f59c6c">
							<tavatekst id="3d4ec0e0-d6fc-4b6a-9865-264f42163493">the cyber incident compromises or harms the security of another system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p2">
						<alampunktNr id="86664006-d55e-4935-a5c0-c7dd9f1dc5c9">2</alampunktNr>
						<kuvatavNr id="0eb411db-3a2e-4a88-8262-5c25dad65355"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="4f2dc087-114d-48d4-b828-66a746950e6f">
							<tavatekst id="ab23e4da-8087-4494-acc6-42b4d3b25337">the system administrator is unable or is unable in a timely manner to counter the serious threat or eliminate the disturbance originating from the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p3">
						<alampunktNr id="f6e72266-031e-4fe7-aa18-96128d874ffb">3</alampunktNr>
						<kuvatavNr id="d94b7413-f65c-4806-b8d1-f724fb985289"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="c4dbd26e-2874-439f-b12c-6114987220c0">
							<tavatekst id="c714b22a-379d-4375-ac1c-8916261fc075">it is not possible to counter the serious threat or eliminate the disturbance originating from the cyber incident by using a less infringing measure;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p4">
						<alampunktNr id="84af50b2-6f8e-42aa-9925-0af3321b1c5d">4</alampunktNr>
						<kuvatavNr id="7e5ff142-fbfa-4d94-8858-f0a25f431df3"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="b869b5dc-a48c-437e-b6f2-83126b297558">
							<tavatekst id="c2a0de8b-ce3d-44df-a207-e245406c6ed7">a person is not caused disproportional damage by countering the serious threat or eliminating the disturbance originating from the cyber incident.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para16lg1b1">
					<loigeNr id="5dc5e085-56c3-4862-b770-adeb8688063f" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="2196b275-bc46-4319-9b93-f2e192ee3232"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="6d2ff72f-bf41-41f4-94a1-200b829b0f4f">
						<tavatekst id="61c44a68-e48d-443c-b942-3fabf1999e1c">For the exercise of state supervision, the Consumer Protection and Technical Regulatory Authority may take measures provided in Article 58(8) of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg2">
					<loigeNr id="2949c444-1cb3-47e1-8fca-a48356fa593b">2</loigeNr>
					<kuvatavNr id="c570ac8b-b015-49f7-ab9a-591fc0cecf7a"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="554072d3-1dee-4580-add1-21ce00d1ce82">
						<tavatekst id="5c8f994a-2091-4894-b8cb-b0d657a7810b">The addressee and in the case of a service provider set out in clause 1 of subsection 1 of § 3 of this Act the authority organising the continuity of the vital service must be notified of the application of a measure provided in this section at the first opportunity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg3">
					<loigeNr id="52df7883-b8da-4c68-90ce-de71031f8493">3</loigeNr>
					<kuvatavNr id="74230e79-b732-4c9e-977f-6da367debe9b"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="ac605833-eaa4-46c8-a264-6d434ef95061">
						<tavatekst id="763d832e-0a24-4e4a-b94f-2b4c808670a1">It is required to record the measure provided for in this section.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17">
				<paragrahvNr id="3b1cf2d6-fe1c-4fc1-b82a-bb31c0f0cb7b">17</paragrahvNr>
				<kuvatavNr id="1182d1e9-b68b-4d66-baa7-24aa8f87e3ef"><![CDATA[§ 17. ]]></kuvatavNr>
				<paragrahvPealkiri id="61d367ac-6b38-4dd4-a644-8e26f1e01d9d">Administrative supervision measures</paragrahvPealkiri>
				<loige id="para17lg1">
					<loigeNr id="813e8d77-5859-4387-998e-d7d5d2951f03">1</loigeNr>
					<kuvatavNr id="fe90d509-795e-46b5-bad2-0d7d5c6efaec"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="bb2c01cc-7ca4-4e1d-9190-6b9c223d206b">
						<tavatekst id="370bad19-5f61-4234-8d4d-54af40686f8c">Upon exercising administrative supervision, the Estonian Information System Authority is authorised to access a system and restrict the use of or access to the system provided all the following conditions are met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17lg1p1">
						<alampunktNr id="18dc7a3b-b241-4a7b-ab1e-06a590422dfd">1</alampunktNr>
						<kuvatavNr id="abefef81-dd10-4886-ad83-e7e01eb3bdc5"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="3cd77614-14ad-46b9-8c04-85c991e01302">
							<tavatekst id="ac77425b-7fed-49da-a5d8-b171b6dbaab2">a cyber incident compromises or harms the security of another system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p2">
						<alampunktNr id="22593ab4-efd9-47f2-8e1a-fb1efff1e08d">2</alampunktNr>
						<kuvatavNr id="097988d0-0895-43ee-b190-f81e5996ae1f"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="dce3f04d-4de8-48a1-b5cd-b740a7ccc4bc">
							<tavatekst id="69397167-08bc-4bdb-b0b4-8f0512b12b81">the system administrator is unable or is unable in a timely manner to counter a threat originating from the cyber incident or eliminate the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p3">
						<alampunktNr id="c0534730-fdb5-464d-a161-cbb458b5bc39">3</alampunktNr>
						<kuvatavNr id="8525d7f8-176b-46cd-b32a-74750b43078e"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="16467adb-5ecc-4988-a8af-8dfe739c6229">
							<tavatekst id="85fd558d-49ee-4197-baba-50e6cbcf726e">it is not possible to counter the threat originating from the cyber incident or eliminate the cyber incident by using a less infringing measure in respect of a person;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p4">
						<alampunktNr id="6b761c0d-87ee-4f4e-aff3-e51dac1a95cb">4</alampunktNr>
						<kuvatavNr id="c86327af-fd4c-430a-baf0-d284912eb298"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="bf216eb0-acc4-449c-baeb-99ab91df7199">
							<tavatekst id="5291b293-ae3b-45ad-b309-5fbfa98ed9ea">a person is not caused disproportional damage by countering the threat originating from the cyber incident or by eliminating the cyber incident.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17lg2">
					<loigeNr id="85751b44-3551-4ccb-8633-2fe66a51592c">2</loigeNr>
					<kuvatavNr id="6859337e-a534-4df4-851d-21a165ef93d7"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="06b8a706-ffa2-4f5f-a9d6-2b8c55fe7760">
						<tavatekst id="f5b672b2-eeb0-41f6-8052-243eb82dae16">The addressee must be notified of the application of the measure provided in this section at the first opportunity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17lg3">
					<loigeNr id="af0034e0-a172-4da0-a69f-743780b4510c">3</loigeNr>
					<kuvatavNr id="78ceffaf-f11e-4401-b007-c6c330764256"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="579d1c59-0daa-4bb0-aef2-3cdc1bcc9bc9">
						<tavatekst id="23d50e31-3241-4426-ac11-aa48a7ccc371">It is required to record the measure provided for in this section.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b1">
				<paragrahvNr id="d33dfe0f-1853-418d-9f5c-f1050602ab54" ylaIndeks="1">17</paragrahvNr>
				<kuvatavNr id="370f44fc-91ca-496e-9be5-335c5b4f5218"><![CDATA[§ 17<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="241a404e-f338-4ef9-a0ec-d27b6462bb15">Rate of non-compliance levy</paragrahvPealkiri>
				<loige id="para17b1lg1">
					<loigeNr id="2e1ba0e2-4f3e-4226-bd4a-73bd80c6a2e9"/>
					<kuvatavNr id="b82bfcde-60cf-41ef-8c5e-b3f5689b5f2b"/>
					<sisuTekst id="9484dc5b-b86b-4e6e-90f5-6bc95b0b466f">
						<tavatekst id="8aa931a0-44dd-4850-862e-a86dc3160b93">Upon failure to comply with a compliance notice in the course of state supervision proceedings, the upper limit of non-compliance levy for each imposition thereof in accordance with the rules provided in the Substitutional Performance and Non-Compliance Levies Act is 20,000 euros.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b2">
				<paragrahvNr id="412c35b4-6b90-4b10-84d5-64f5786ccc95" ylaIndeks="2">17</paragrahvNr>
				<kuvatavNr id="6389edc4-084d-4ca4-87d0-2c4128a97089"><![CDATA[§ 17<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="adc5060d-703a-4e6c-be84-a5686adac626">Term for review of complaint</paragrahvPealkiri>
				<loige id="para17b2lg1">
					<loigeNr id="0094262b-9f85-4dbb-8071-e8c17c846c2a">1</loigeNr>
					<kuvatavNr id="b97c29d2-1510-449e-817c-da111027d63c"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="447c1278-1745-4742-94d0-0e914cbf595d">
						<tavatekst id="b4745e9f-8f83-4f7c-9d33-e5103eaa6a9c">The Consumer Protection and Technical Regulatory Authority settles a complaint provided in Article 63 of Regulation (EU) 2019/881 of the European Parliament and of the Council no later than on the 90<sup>th</sup> day as of the receipt of the complaint.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b2lg2">
					<loigeNr id="c08fe1a0-403b-4086-b590-cb384642a3a2">2</loigeNr>
					<kuvatavNr id="12e7d0c7-4184-4117-a82d-299441928307"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="5b9e3363-cd8f-4daf-b52f-7e6779f2c34e">
						<tavatekst id="97ff12c5-a246-439a-b4cc-5094fe30268c">Should the settlement of a complaint specified in subsection 1 of this section require co-operation with the national cybersecurity certification authority of another state, the Consumer Protection and Technical Regulatory Authority has the right to extend the term for review of the complaint by a period of time necessary for hearing the opinion of said authority. The person who lodged the complaint is informed of the extension of the term for review of the complaint in writing.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="d0e66b46-c5c8-438a-9845-abe8ad616733">
			<peatykkNr id="3d38fafe-9594-43a2-9614-9912793f8866">5</peatykkNr>
			<kuvatavNr id="8d35f106-175f-497a-a956-4c293089aa30"><![CDATA[Chapter 5]]></kuvatavNr>
			<peatykkPealkiri id="1a1583f0-e3d0-4f56-84c4-e5621d93ff8f">Liability </peatykkPealkiri>
			<paragrahv id="para18">
				<paragrahvNr id="9443d07d-d673-4910-bb82-804f63672997">18</paragrahvNr>
				<kuvatavNr id="fde501ac-0df7-4914-95aa-fa060e6b7fe1"><![CDATA[§ 18. ]]></kuvatavNr>
				<paragrahvPealkiri id="529fcdb8-7dd3-4e01-854c-c3dd24f0921c">Violation of requirements of Act</paragrahvPealkiri>
				<loige id="para18lg1">
					<loigeNr id="e9804674-2cec-44e4-982f-8c2feaaf5ba0">1</loigeNr>
					<kuvatavNr id="c87731bd-209d-45f1-b48c-5c712084cd7c"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="badd4058-8966-4a7e-9d57-018341ca4cef">
						<tavatekst id="f8b3fbf2-6add-4058-8bd9-aa43c60f2bd0">Violation of the requirements provided in subsections 1–3 of § 7 of this Act<reavahetus/>is punishable by a fine of up to 200 fine units.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18lg2">
					<loigeNr id="7711cbbb-8ded-4422-88fc-7f34d74de8e5">2</loigeNr>
					<kuvatavNr id="a34e30f1-8560-4e59-9e6f-e00e252bd967"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="abee590e-f275-4315-8cf8-15c1fbd51f28">
						<tavatekst id="77d14565-db4a-44b2-bc8a-293440ae2ee8">The same act, if committed by a legal person,<reavahetus/>is punishable by a fine of up to 20,000 euros.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b1">
				<paragrahvNr id="081ed26a-47a1-4992-9e49-73f02492de05" ylaIndeks="1">18</paragrahvNr>
				<kuvatavNr id="af80d4fc-6180-4575-b484-a4e1570a0e38"><![CDATA[§ 18<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="7a4dea16-77df-45e2-b59d-5f5be229e5fb">Violation of requirements of Regulation (EU) 2019/881 of the European Parliament and of the Council</paragrahvPealkiri>
				<loige id="para18b1lg1">
					<loigeNr id="740ac6c6-f18d-4c0d-9244-7ce10fa008fa">1</loigeNr>
					<kuvatavNr id="c70152ac-ef53-4388-90c1-987d1d7bbdc2"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="bfd9c54b-a081-408e-950b-3d5db3dea07e">
						<tavatekst id="ef5e2c90-d13f-4596-8fad-6f6a38c6c81d">Issue of a statement of conformity that does not comply with the conditions provided in Article 53(2) of Regulation (EU) 2019/881 of the European Parliament and of the Council or, in the event of information specified in Article 55(1), violation of the requirements provided in paragraph 2 of the same Article<reavahetus/>is punishable by a fine of up to 200 fine units.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b1lg2">
					<loigeNr id="8f322516-e729-4c04-8af0-c2fb4a13f378">2</loigeNr>
					<kuvatavNr id="26c0ab15-265b-4d40-9d3f-5091a7c276c6"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="55d6eee4-3666-4ac4-9b8f-0ac5227ea996">
						<tavatekst id="becaac4f-3072-4c88-a795-9963a0743726">The same act, if committed by a legal person,<reavahetus/>is punishable by a fine of up to 20,000 euros.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para19">
				<paragrahvNr id="efdd1bc3-7bad-40f2-a518-094bd1f73a22">19</paragrahvNr>
				<kuvatavNr id="81778b5d-6f60-45aa-853a-d1447e945c6b"><![CDATA[§ 19. ]]></kuvatavNr>
				<paragrahvPealkiri id="d170d2be-36d7-4522-b6e6-e5dbc7c22841">Proceedings</paragrahvPealkiri>
				<loige id="para19lg1">
					<loigeNr id="66e5586d-9ff2-4bc0-904c-adda7ffe07a6">1</loigeNr>
					<kuvatavNr id="06d10e38-db20-4e85-8ddb-3941ddb1a032"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="3f77ce11-bdb2-4345-a602-9294a64e2f7d">
						<tavatekst id="a1faee1e-fd59-4a66-93cb-1075fc5c7927">The body conducting extra-judicial proceedings pertaining to the misdemeanour provided in § 18 of this Act is the Estonian Information System Authority.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para19lg2">
					<loigeNr id="6812ad45-6226-4fea-8fca-478916f1284b">2</loigeNr>
					<kuvatavNr id="a7a7671d-ef8e-47a1-967b-908372656383"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="121f6fb8-b331-4552-b8b7-69385d04ce10">
						<tavatekst id="171c41ef-4afb-4151-8766-be3146e36b3c">If the misdemeanour provided in § 18 of this Act is related to a violation of the requirements for the processing of personal data, the Personal Data Protection Act is applied to the misdemeanour proceedings.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para19lg3">
					<loigeNr id="11c079e3-eab5-456d-ad9d-6deb904c35e2">3</loigeNr>
					<kuvatavNr id="db2e71bd-d18f-4ed7-a27d-d3266e599021"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="c26a073a-fa37-44ea-a7e9-ebb98c248730">
						<tavatekst id="9a6d0cb9-6695-4e8c-9267-e10ceb5aa387">The body conducting extra-judicial proceedings pertaining to the misdemeanour provided in § 18<sup>1</sup> of this Act is the Consumer Protection and Technical Regulatory Authority.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="d5269c62-de85-45ed-a618-4186d7dd299c">
			<peatykkNr id="230ad5bb-3f15-4f74-b6b7-8cadfc0da63a">6</peatykkNr>
			<kuvatavNr id="9a3302db-eab2-45ba-b064-778e3f0b8bcc"><![CDATA[Chapter 6]]></kuvatavNr>
			<peatykkPealkiri id="1a471cd2-0e5e-4538-bc4e-d8183d5c0dbf">Implementing Provisions </peatykkPealkiri>
			<paragrahv id="para20">
				<paragrahvNr id="60c1f214-155c-41b2-996e-c019e51ac35c">20</paragrahvNr>
				<kuvatavNr id="257a1be0-6b46-4146-af9a-597329994fb7"><![CDATA[§ 20. ]]></kuvatavNr>
				<paragrahvPealkiri id="af35667b-d9c5-4645-b588-8d8a8b201b56">Identification of service providers</paragrahvPealkiri>
				<loige id="para20lg1">
					<loigeNr id="4373365b-8f87-4e5d-a189-c43d7bfe8b37"/>
					<kuvatavNr id="c80b2863-5de4-4bc6-87b7-84b922f8ccab"/>
					<sisuTekst id="d899b4b3-dd5a-4298-8bde-e5e90f1af9ac">
						<tavatekst id="bd07f9aa-5ebe-4bd8-a0af-5f04fbad619b">The service providers referred to in subsection 3 of § 3 of this Act are identified by the Estonian Information System Authority by 9 November 2018.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para21">
				<paragrahvNr id="e4726c00-11d9-47d0-8594-74a7aaf6bf30" kehtiv="0">21</paragrahvNr>
				<kuvatavNr id="b685b802-04b0-4a3e-b8cb-2f1cd1d85370"><![CDATA[§ 21. ]]></kuvatavNr>
				<sisuTekst id="d8948db0-8df8-48da-8eb2-5bc70d98c1eb">
					<tavatekst id="96f9ddde-ee96-4ef9-85c8-2b83ca9e7256"> – </tavatekst>
				</sisuTekst>
			</paragrahv>
			<paragrahv id="para28">
				<paragrahvNr id="1d1085f6-3e61-4235-9e22-800ac15d5767" kehtiv="0">28</paragrahvNr>
				<kuvatavNr id="7f247bd7-d4d5-494b-b07f-34e0f7917efe"><![CDATA[§ 28. ]]></kuvatavNr>
				<sisuTekst id="82210d9d-88dc-458a-b4c2-0511a6fc40d8">
					<tavatekst id="69b92ea0-9e7d-44ad-9149-c159d4345fbd">[Provisions governing the amendment of other Acts are omitted from this translation.]</tavatekst>
				</sisuTekst>
			</paragrahv>
			<paragrahv id="para29">
				<paragrahvNr id="161e0033-6c58-4fae-94d7-0e9b0118a25e">29</paragrahvNr>
				<kuvatavNr id="65b2ad7d-885e-4786-9090-395de6812c4f"><![CDATA[§ 29. ]]></kuvatavNr>
				<paragrahvPealkiri id="37fd8ac8-b4ed-41ac-b391-1707f2e09afc">Entry into force of Act</paragrahvPealkiri>
				<loige id="para29lg1">
					<loigeNr id="572e2a67-e68b-4b84-9714-bf06fcbf1409">1</loigeNr>
					<kuvatavNr id="c704d3f1-2834-4c7f-981b-975e9bd59ae5"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="85c37587-a5dd-4809-a789-4d3839132371">
						<tavatekst id="15bf828b-02a6-4157-bf76-a5ba939c75ca">This Act enters into force on the day following its publication in <i>Riigi Teataja</i>.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para29lg2">
					<loigeNr id="e89d2e17-dfb2-4667-b0c4-9deffaf183ec">2</loigeNr>
					<kuvatavNr id="711829ba-765d-4449-ac38-1d628a5fe464"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="b54863e3-0e46-465b-9169-eda30160d34b">
						<tavatekst id="3e840627-b07f-476d-b487-390cc74baa87">Clause 8 of subsection 1 of § 3, subsection 3 of § 3, § 9 and clause 3 of § 23 of this Act enter into force on 1 January 2020.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para29lg3">
					<loigeNr id="01d05a1c-2c33-4952-b503-5c83af92fd75">3</loigeNr>
					<kuvatavNr id="f9da8148-c8a6-4b69-b885-58db7a4f1dc8"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="3f73112a-40b4-4b42-9d7c-fba3de9792a0">
						<tavatekst id="98f98783-b5d2-45c6-a3c4-01e3ac95caf5">Clauses 7 and 10 of subsection 1 of § 3, § 21 and clauses 1 and 5 of § 28 of this Act enter into force on 1 January 2022.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
	</sisu>
	<normtehnmarkus id="6e3cf8b1-d1fd-4bb6-85f9-f43def7c1fac" kuuluvus="0aa5df45-e59c-4546-98a4-b91f9faf1fbe">
		<normtehnmarkusNr id="c0c5acb4-90be-4dac-964c-34ac6539d71d">1</normtehnmarkusNr>
		<normtehnmarkusTekst id="4d977881-60ca-4fdb-b89d-7d7be81c5673"><![CDATA[ Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.07.2016, pp 1–30).]]></normtehnmarkusTekst>
	</normtehnmarkus>
</oigusakt>