<?xml version="1.0" encoding="UTF-8"?>
<oigusakt id="26c19686-cab1-4cf0-b08f-5e849423869f" xsi:schemaLocation="tyviseadus_1_10.02.2010 http://xmlr.eesti.ee/xml/schemas/oigusakt/tyviseadus_1_10.02.2010.xsd" xmlns="tyviseadus_1_10.02.2010" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
	<metaandmed>
		<valjaandja>Riigikogu</valjaandja>
		<dokumentLiik>seadus</dokumentLiik>
		<tekstiliik>terviktekst</tekstiliik>
		<dokumentEtapp>avaldamine</dokumentEtapp>
		<dokumentStaatus>avaldatud</dokumentStaatus>
		<vastuvoetud>
			<aktikuupaev>2018-05-09</aktikuupaev>
			<avaldamismarge>
				<RTosa>RT I</RTosa>
				<avaldamineKuupaev>2018-05-22</avaldamineKuupaev>
				<RTartikkel>1</RTartikkel>
				<aktViide>122052018001</aktViide>
			</avaldamismarge>
			<joustumine>2018-05-23</joustumine>
			<tavatekst>, in part 01.01.2020 and 01.01.2022</tavatekst>
		</vastuvoetud>
		<avaldamismarge><RTosa>RT V</RTosa><avaldamineKuupaev>2026-01-28</avaldamineKuupaev><RTaasta>2026</RTaasta><RTartikkel>3</RTartikkel><aktViide>528012026003</aktViide></avaldamismarge><kehtivus>
			<kehtivuseAlgus>2026-01-01+02:00</kehtivuseAlgus>
		</kehtivus>
		<versioon>
			<dokumentVersioon>1</dokumentVersioon>
			<dokumentVersioonKuupaev>2026-01-28</dokumentVersioonKuupaev>
		</versioon>
		<skeemiNimi>tyviseadus_1_10.02.2010.xsd</skeemiNimi>
		<globaalID>528012026003</globaalID>
		<metaandmedVersioon>5</metaandmedVersioon>
		<metaandmedVersioonKuupaev>2026-01-28</metaandmedVersioonKuupaev>
		<metaandmedVersioonPohjustaja>Mari Peetris</metaandmedVersioonPohjustaja>
		<terviktekstiGrupiID>100704</terviktekstiGrupiID><eesmark>Tüviseaduse raamskeem XML struktuuri koostamiseks</eesmark>
	</metaandmed>
	<aktinimi id="e2758876-f27b-44ad-9c07-93eeefaa4654">
		<nimi id="598d5c60-4638-491e-b80d-26c67db34f0e">
			<pealkiri id="5095f8fc-e43a-4659-8ec4-dcaff6a62faa">Cybersecurity Act</pealkiri>
			<normtehnmarkus id="04724735-693d-4919-a796-cf162ff6e76b" kuuluvus="8872b516-4cfa-41c2-a67f-55f851dc5504">
				<normtehnmarkusNr id="83c940a2-9181-423e-87b8-7be5d32de0fe">1</normtehnmarkusNr>
			</normtehnmarkus>
		</nimi>
	</aktinimi>
	<muutmismarge>
		<aktikuupaev>2022-07-19</aktikuupaev>
		<avaldamismarge>
			<RTosa>RT I</RTosa>
			<avaldamineKuupaev>2022-08-06</avaldamineKuupaev>
			<RTartikkel>2</RTartikkel>
			<aktViide>106082022002</aktViide>
		</avaldamismarge>
		<joustumine>2022-08-16</joustumine>
		<tavatekst>, in part 01.01.2027;</tavatekst>
		<tavatekst> amended in part [RT I, 30.12.2025, 4]</tavatekst>
	</muutmismarge>
	<muutmismarge>
		<aktikuupaev>2024-06-04</aktikuupaev>
		<avaldamismarge>
			<RTosa>RT I</RTosa>
			<avaldamineKuupaev>2024-06-21</avaldamineKuupaev>
			<RTartikkel>2</RTartikkel>
			<aktViide>121062024002</aktViide>
		</avaldamismarge>
		<joustumine>2024-07-01</joustumine>
	</muutmismarge>
	<muutmismarge>
		<aktikuupaev>2025-12-10</aktikuupaev>
		<avaldamismarge>
			<RTosa>RT I</RTosa>
			<avaldamineKuupaev>2025-12-30</avaldamineKuupaev>
			<RTartikkel>4</RTartikkel>
			<aktViide>130122025004</aktViide>
		</avaldamismarge>
		<joustumine>2026-01-01</joustumine>
	</muutmismarge>
	<sisu id="3fcf8cbd-be93-4278-87ca-996d1f8bbccb">
		<peatykk id="13432592-6c65-421a-97e3-2027934d7c10">
			<peatykkNr id="fe6a4e48-7878-44e5-8fa5-10f5d0b58701">1</peatykkNr>
			<kuvatavNr id="28e54797-2dc7-4332-a203-b06deb82478a"><![CDATA[Chapter 1]]></kuvatavNr>
			<peatykkPealkiri id="0daed7ac-ea77-4799-ae53-5fb9ded36651">General Provisions</peatykkPealkiri>
			<paragrahv id="para1">
				<paragrahvNr id="9bac5437-bb7d-45a4-ac97-a48a68bfa22e">1</paragrahvNr>
				<kuvatavNr id="4ce165dd-a955-4f32-a2cd-2ac5e2e8e351"><![CDATA[§ 1. ]]></kuvatavNr>
				<paragrahvPealkiri id="8832b793-08fb-483c-a268-fc5590ae690b">Scope of regulation and scope of application of Act</paragrahvPealkiri>
				<loige id="para1lg1">
					<loigeNr id="6d277c7a-9446-4857-878a-0e1370ec36f7">1</loigeNr>
					<kuvatavNr id="b086eac2-b6a9-46e3-b855-93005e5984dc"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="8a18fad8-4860-45bd-bc8e-1c4b7dfe00ea">
						<tavatekst id="ed39e675-d5eb-4f24-9e81-4a0f30ce4eb2">This Act provides for:</tavatekst>
					</sisuTekst>
					<alampunkt id="para1lg1p1">
						<alampunktNr id="1b38cdea-c28b-4958-94c6-55f57df728c5">1</alampunktNr>
						<kuvatavNr id="ad98f8ef-876c-47c8-a55f-04e7da15bbf2"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="f626502e-27c6-43da-8fbc-65f4c46f0299">
							<tavatekst id="19e5aaa6-694b-4147-b618-c499d49feff7">requirements for the maintenance of the network and information systems used by essential entities and important entities and domain name registration service providers, as well as liability and supervision;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg1p2">
						<alampunktNr id="115ab009-89eb-4571-86fa-a8ac3a551fba">2</alampunktNr>
						<kuvatavNr id="4371440a-868f-4de3-925a-5b93e481a0c6"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="cba5c45a-1b9a-4925-95b9-e07e7c18c631">
							<tavatekst id="b4abf831-80b1-49d9-bbc2-1c357875d8b7">grounds for handling cyber incidents and requirements for addressing security vulnerabilities and cyber threats;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg1p3">
						<alampunktNr id="637d70ab-0dfa-4dd4-a7bb-34b33a1bc734">3</alampunktNr>
						<kuvatavNr id="55427d9d-4596-4eb6-8ade-d8aa06aee44e"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="4323629a-a7e8-4293-9b11-41a6578e9050">
							<tavatekst id="62069cfe-a11e-4b63-add3-9e1e578c4934">requirements for preventing and responding to large-scale cyber incidents and crises;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg1p4">
						<alampunktNr id="db4baa1d-76e4-4a79-8170-a86151c24f41">4</alampunktNr>
						<kuvatavNr id="826ca5ba-052a-4e8f-acbb-40b18a545d32"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="a39cfe4a-7f9c-4e0a-9b27-be37cef86d67">
							<tavatekst id="29f7a4fe-7add-41ba-b844-0f3f6efccdc8">requirements for co-operation, information sharing and peer review in the field of cybersecurity;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg1p5">
						<alampunktNr id="3d4005ff-1004-4e3c-86d8-a1be6f6385d3">5</alampunktNr>
						<kuvatavNr id="1218c602-e6af-48b6-8802-3bb39cf6c1f7"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="df188299-4a04-4e89-b225-325b29988557">
							<tavatekst id="d52aff5e-a688-4a69-a3fc-9cdfa3d40529">the competent authorities in the field of cybersecurity and the requirements for designating the competent authority carrying out cybersecurity supervision in the field of cross-border electricity flows.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para1lg2">
					<loigeNr id="84bac8d9-c222-406e-83b9-7a12300387e5">2</loigeNr>
					<kuvatavNr id="d3466db5-1557-4257-b619-1426d5af73ae"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="bbd6123d-77e8-46a0-afc4-25904ce78a0c">
						<tavatekst id="595532f5-37ae-4cde-a502-737109a8f2d6">This Act is not applied to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para1lg2p1">
						<alampunktNr id="df119aaa-b01e-4578-863c-0a3c21ce0b94">1</alampunktNr>
						<kuvatavNr id="72b5390b-1e23-45ee-b4ca-74aa6f1f800c"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="c5884c98-2e75-486d-876c-297fe5d1a2f6">
							<tavatekst id="d6fd3fd8-0761-4b2f-b25b-5056d8bd8ea2">the processing of state secrets and classified information of foreign states or to the maintenance of processing systems for such information;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg2p2">
						<alampunktNr id="21d020fa-eef2-4cd2-8409-c130b5112d9d">2</alampunktNr>
						<kuvatavNr id="8d95938c-c90e-4dae-a06d-fbad69435430"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="5e3517ab-df36-424f-abcb-9d38cf28b05f">
							<tavatekst id="4f554fce-7267-43fe-bbc2-7d1ff6872b70">the maintenance of systems necessary for international military co-operation and for preparations for national military defence within the area of government of the Ministry of Defence;<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para1lg2p3">
						<alampunktNr id="af22bd00-a1fd-4e6a-85de-a66a0debb66f">3</alampunktNr>
						<kuvatavNr id="6978042f-d05d-43b9-b23e-b77865813579"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="5f33339b-8cb6-420b-856c-9c2373d5c0cd">
							<tavatekst id="6e0d29b1-a771-4671-96e4-e2588c1e7932">the diplomatic and consular missions of the Republic of Estonia in third countries and their network and information systems, where such systems are located on the premises of the mission or are operated for users in a third country.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para1lg2b1">
					<loigeNr id="fb5cea6d-997d-49ef-98cd-e3ce2314cbc5" ylaIndeks="1">2</loigeNr>
					<kuvatavNr id="b593dfff-b341-4955-af66-31c7d86da331"><![CDATA[(2<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="7e83a966-5e79-4678-aad8-241683eb590c">
						<tavatekst id="0ba8120f-4a7f-4b31-b2ae-eda47d4f4616">The exemption provided in subsection 2 of this section does not apply to a trust service provider.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg3">
					<loigeNr id="63977317-ec0e-4345-987e-b86d92245b96">3</loigeNr>
					<kuvatavNr id="54a61d5c-90c5-41b6-a65a-f42f7f96347f"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="0a825fe3-140b-40a5-8ace-4eaa0b1afcf3">
						<tavatekst id="89d0414e-c765-47b1-8cdf-2afba60c0558">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg4">
					<loigeNr id="6a6e8d2b-5eb5-47ff-80c6-24a6a5db550e">4</loigeNr>
					<kuvatavNr id="e2f567fe-0457-4bdb-bf5b-99f47c3f901e"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="697c6022-c3f9-46bf-b520-81ada3581015">
						<tavatekst id="e6ddd5b6-07ea-4e8e-9780-e75dc1cb2d07">Where the requirements for the maintenance of a service provider’s network and information system and for the notification of a cyber incident are governed by an international agreement, a European Union legal act or another Act in a manner equivalent to that provided in this Act, this Act is applied with the specifications arising from the international agreement, European Union legal act or other Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para1lg5">
					<loigeNr id="b66f5a6b-8aa3-4cda-8458-ac04192e5ebc">5</loigeNr>
					<kuvatavNr id="1801e4aa-4331-4e49-934e-b67c59758f30"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="32879742-04ab-4844-be47-b17c1f0a8bdf">
						<tavatekst id="688e6d3c-cd85-4e73-bffd-828c7445b364">The provisions of the Administrative Procedure Act apply to administrative proceedings prescribed in this Act, taking into account the specifications provided in this Act.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para2">
				<paragrahvNr id="d8c5ea3f-4e73-4581-884d-7e9e905a2d1e">2</paragrahvNr>
				<kuvatavNr id="ffdf1527-998e-4f80-94f5-10f5d19610cc"><![CDATA[§ 2. ]]></kuvatavNr>
				<paragrahvPealkiri id="8ef3f7aa-55ce-4626-a343-2790037c7011">Definitions</paragrahvPealkiri>
				<loige id="para2lg1">
					<loigeNr id="1ac4b236-7b26-41bb-b703-f4719c0b09fc"/>
					<kuvatavNr id="d0f32989-9f07-4615-b5b2-1c8792e45ce3"/>
					<sisuTekst id="95cfc67e-aa7d-4d3b-876a-1e00b3154a34">
						<tavatekst id="226983a2-e415-4afe-880e-299d522b3d48">For the purposes of this Act, definitions have the following meanings:</tavatekst>
					</sisuTekst>
					<alampunkt id="para2lg1p1">
						<alampunktNr id="74c3e9ac-2ba8-4f3d-8916-6c9f3979379f">1</alampunktNr>
						<kuvatavNr id="5edc78ff-7250-43e2-9a95-2027ed0c1d15"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="84415fab-c744-4958-b9c6-9ac2028bedd4">
							<tavatekst id="0c872e15-64e7-4469-9e6c-fba5089b8f1e">‘data centre service’ means a service that encompasses structures, or groups of structures, dedicated to the centralised accommodation, interconnection and operation of information technology and network equipment providing data storage, processing and transport services, including all the facilities and infrastructures for power supply and accommodation environment control;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p2">
						<alampunktNr id="bf4b4e3a-49e2-4999-901a-9e781132d331">2</alampunktNr>
						<kuvatavNr id="750cd267-98af-414e-af65-c8ee2d15b45b"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="a14d140e-992f-4c93-aec3-4db7b745fd11">
							<tavatekst id="5c5bac8b-a78e-42f0-bfea-12d28e560b40">‘digital service provider’ means a generic term referring to a domain name system service provider, a top-level domain name registry, a domain name registration service provider, a cloud computing service provider, a data centre service provider, a content delivery network service provider, a managed service provider, an information security service provider, an online marketplace provider and a provider of an online search engine or a social media platform;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p3">
						<alampunktNr id="a12f8d14-f8c4-446b-95df-5c2296f0f477">3</alampunktNr>
						<kuvatavNr id="f8d94028-f6a5-4607-95b9-8856890fd4d1"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="03cc0bef-2473-4d64-92df-6eff7b5bf96e">
							<tavatekst id="66615d63-3d22-48df-bc68-db26fef67072">‘representative of a digital service provider’ (hereinafter <i>representative</i>) means a natural or legal person established in the European Union designated to act on behalf of a digital service provider not established in the European Union, which may be addressed by the Estonian Information System Authority with regard to the obligations of the digital service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p4">
						<alampunktNr id="18e4cc10-e92e-4c35-91a5-8ad9cc169c5c">4</alampunktNr>
						<kuvatavNr id="de11b434-16d9-4442-9d15-d4b967d64ff6"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="6997804b-9639-4eea-92e6-ad60c0049156">
							<tavatekst id="56b5f8d0-cfba-4fcd-a52a-5dd13d1f60c0">‘domain name registration service provider’ means a top-level domain name registry or a person acting on behalf of that top-level domain name registry, such as a privacy or proxy registration service provider or a reseller;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p5">
						<alampunktNr id="61eaa504-9a1a-4225-acea-ce89f36c45a9">5</alampunktNr>
						<kuvatavNr id="f555f922-fdfd-4ce5-8f6b-0bc485f3224c"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="fdee82c3-4e8e-4520-a2b5-5716afd2a83c">
							<tavatekst id="0757f7f3-dd55-40fe-95ff-aa3c630ce15d">‘domain name system’ means a hierarchical and distributed naming system which enables the identification of internet services and resources by making it possible for end-user devices to use internet routing and connectivity services to reach those services and resources;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p6">
						<alampunktNr id="14f63912-4727-49cd-916e-a530f85c5f2b">6</alampunktNr>
						<kuvatavNr id="702b5af0-3aa1-47f2-9896-64d51e27264c"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="b726c158-b4d4-4f73-b479-31d221322365">
							<tavatekst id="707cf2da-ec9b-47b6-97ff-423989341daf">‘domain name system service provider’ means an entity that provides publicly available recursive domain name resolution services for internet end-users, or that provides authoritative domain name resolution services for third-party use, with the exception of root name servers;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p7">
						<alampunktNr id="7e67dc98-3e49-457a-bfb9-877cdbfddd5a">7</alampunktNr>
						<kuvatavNr id="fb97f096-96e8-48c1-b56f-0e7ec4e009ea"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="db541bac-b4b5-4358-bcc6-dcbdf9a1f5ce">
							<tavatekst id="d808ef50-2b3b-45ab-9fbe-6bb39a08838d">‘managed service provider’ means an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers’ premises or remotely;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p8">
						<alampunktNr id="c52591ba-62af-4196-9b3e-318bfbf1c236">8</alampunktNr>
						<kuvatavNr id="79bb3a8a-a179-4773-b229-e09331fbdd76"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="61adc7d4-d46e-4d08-b2b1-2cbeef63ac0d">
							<tavatekst id="ce176a49-0d04-45c0-8efd-d55946204c18">‘ICT process’ means an ICT process as defined in point 14 of Article 2 of Regulation (EU) 2019/881 of the European Parliament and of the Council on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 07.06.2019, pp 15–69);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p9">
						<alampunktNr id="fbfb5809-e608-4468-9513-d56581334b60">9</alampunktNr>
						<kuvatavNr id="2b36ff64-0afc-4782-96bf-71ba175712fb"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="12a47d9d-9516-4284-8775-d85c3464f8bf">
							<tavatekst id="6165e0ba-ee84-4781-8770-e58135504651">‘ICT service’ means an ICT service as defined in point 13 of Article 2 of Regulation (EU) 2019/881 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p10">
						<alampunktNr id="f7649e73-5c06-483b-a7d2-90916d796924">10</alampunktNr>
						<kuvatavNr id="11dd95fa-b3d7-45dc-8116-adcf775abca4"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="e03f6623-76c2-4449-b0c9-6a7cac30e4f5">
							<tavatekst id="5f127355-0612-4b02-b456-20136e4087ed">‘ICT product’ means an ICT product as defined in point 12 of Article 2 of Regulation (EU) 2019/881 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p11">
						<alampunktNr id="725cd761-67b0-40f7-9391-57b29e1e000b">11</alampunktNr>
						<kuvatavNr id="c5da825a-2f98-452f-972a-beadf351c260"><![CDATA[11) ]]></kuvatavNr>
						<sisuTekst id="e2b0cefb-cb84-428f-a91c-cffcc5b61fcb">
							<tavatekst id="bdcafa9d-028f-407b-a1bc-109140d9d823">‘information security service provider’ means a managed service provider that carries out or provides assistance for risk management;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p12">
						<alampunktNr id="e8def6ea-14ee-40f6-a4c4-1d082dafec5c">12</alampunktNr>
						<kuvatavNr id="4753e88d-6729-4c52-be17-b2a2bf9aca98"><![CDATA[12) ]]></kuvatavNr>
						<sisuTekst id="3110da36-f2b4-423f-8a75-07c417c9c849">
							<tavatekst id="4563d359-e883-478b-95e3-c2ed53a5f641">‘internet exchange point’ means a network facility which enables the interconnection of more than two independent networks and the exchange of internet traffic between them, and which provides interconnection only for autonomous systems and which neither requires the internet traffic passing between any pair of participating autonomous systems to pass through any third autonomous system nor alters or otherwise interferes with such traffic;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p13">
						<alampunktNr id="71c0a89d-06fb-4472-a85e-9cab0fedd9ee">13</alampunktNr>
						<kuvatavNr id="94bb511e-0e21-4786-a8d8-bbb7a428ea6a"><![CDATA[13) ]]></kuvatavNr>
						<sisuTekst id="52c42560-9f90-4089-97b1-004c825bccef">
							<tavatekst id="0156b701-3eb3-4559-a14e-67c4df68cd60">‘online marketplace’ means an online marketplace for the purposes of the Consumer Protection Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p14">
						<alampunktNr id="ae97776a-161a-4de1-a592-6ac938f7c759">14</alampunktNr>
						<kuvatavNr id="59b56a11-474b-4b23-af5b-096b25b58ba0"><![CDATA[14) ]]></kuvatavNr>
						<sisuTekst id="f0c08b08-36c9-42d1-858d-ae13a07a75fb">
							<tavatekst id="86d0faa9-b515-412f-8b4a-b3d21b5ee46d">‘ex post inspection’ means supervision related to an ex post response to a cyber incident or to additional verification of an imminent threat of a cyber incident, based on evidence, indications or information which has drawn the attention of the supervisory authority to a cyber incident or an imminent threat thereof, publicly available information, or information received or created by the supervisory authority in the performance of another task;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p15">
						<alampunktNr id="97f7db48-b0e3-4fb4-ba56-adf5ba53c739">15</alampunktNr>
						<kuvatavNr id="cdcd2aa9-10b4-4f75-a7d3-4804f45143d9"><![CDATA[15) ]]></kuvatavNr>
						<sisuTekst id="6420d28f-7047-4816-801f-2eb08d2d180a">
							<tavatekst id="cf356035-f142-4845-9cba-3294e3b037ae">‘central government public administration entity’ means Eesti Pank, a judicial body, the State Electoral Office, the Chancellery of the Riigikogu, the State Audit Office, the Office of the President of the Republic, a governmental authority, a state agency governed by a governmental authority, and the Office of the Chancellor of Justice;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p16">
						<alampunktNr id="64630ee8-040d-4718-bd02-1b70f967bf1e">16</alampunktNr>
						<kuvatavNr id="a1ab9a5d-e955-4c63-8651-ce7252b6925a"><![CDATA[16) ]]></kuvatavNr>
						<sisuTekst id="a925fee0-a471-4051-8f82-7e6e982d7360">
							<tavatekst id="b8ef5055-cc67-49df-94f8-99f28df5e458">‘local government public administration entity’ means a local authority, a rural municipality or city administrative agency, an agency under the administration of a rural municipality or city administrative agency, a rural municipality district, a city district, an administrative agency of a rural municipality district or city district, an agency under the administration of an administrative agency of a rural municipality district or city district, and a joint administrative agency and joint agency of local authorities;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p17">
						<alampunktNr id="7f04e60f-878b-4ab1-884d-b66ba3375a14">17</alampunktNr>
						<kuvatavNr id="6c71adbb-0ecb-4d2b-9c5a-692528b6067f"><![CDATA[17) ]]></kuvatavNr>
						<sisuTekst id="099e1c6e-a0fb-4a49-a6ad-4ff29bb61e8c">
							<tavatekst id="79ac7a54-bd35-43f5-a67c-7438d3ad8290">‘qualified trust service provider’ means a qualified trust service provider as defined in point 20 of Article 3 of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (OJ L 257, 28.08.2014, pp 73–114);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p18">
						<alampunktNr id="e44faaae-f5ea-4d03-8e7f-40fe037c8413">18</alampunktNr>
						<kuvatavNr id="73e8f81d-a6a5-4622-af48-954724fa22d4"><![CDATA[18) ]]></kuvatavNr>
						<sisuTekst id="61e3acd8-653b-4274-802f-0225198ade11">
							<tavatekst id="939f67d5-79e0-4390-804b-7c3639bd0b47">‘cyber incident handling’ means any actions and procedures aiming to prevent, detect, analyse, and contain or to respond to and recover from a cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p19">
						<alampunktNr id="4648971a-726d-46fa-8a8c-cd9062e0c7f1">19</alampunktNr>
						<kuvatavNr id="599764b8-9410-40a2-9ac9-78834819ee16"><![CDATA[19) ]]></kuvatavNr>
						<sisuTekst id="b63c496a-31c9-40c3-afbe-37df20ca3479">
							<tavatekst id="d7992a6c-aa7d-4a81-94e6-5765ddd94360">‘cyber incident’ means an event in a network and information system that poses a risk to or compromises the security of the network and information system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p20">
						<alampunktNr id="dbdd072a-5701-4e4b-9a14-8f3c2ce80918">20</alampunktNr>
						<kuvatavNr id="f86e6b88-652b-4a2a-abb0-b44f4600fda6"><![CDATA[20) ]]></kuvatavNr>
						<sisuTekst id="10fcb8f7-d80f-4949-a1ad-b37d6ab298a3">
							<tavatekst id="ae4cd6c2-0fed-4079-bf9a-18ee9fc8aada">‘cyber incident handling unit’ means a group of experts whose task is to carry out operations supporting cyber incident handling;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p21">
						<alampunktNr id="20eb456c-61f7-4e84-bd34-377c3c82067f">21</alampunktNr>
						<kuvatavNr id="61e27d05-283e-44d4-ab1e-1a613a6dfbf2"><![CDATA[21) ]]></kuvatavNr>
						<sisuTekst id="8458ea8c-05b4-4ccc-b76d-be61075b20af">
							<tavatekst id="4a7b4d82-e22e-45c9-bef4-af100380d348">‘cyber threat’ means a cyber threat as defined in point 8 of Article 2 of Regulation (EU) 2019/881 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p22">
						<alampunktNr id="37b849d0-02c7-450c-8703-1f11a4046775">22</alampunktNr>
						<kuvatavNr id="8576787c-2dbb-4ef4-b641-83aabb889d1e"><![CDATA[22) ]]></kuvatavNr>
						<sisuTekst id="de0f020c-68f0-44de-b775-f0d9cd019a1e">
							<tavatekst id="2fe111ce-0fe6-4c50-a2d9-3479130e56ef">‘cybersecurity’ means cybersecurity as defined in point 1 of Article 2 of Regulation (EU) 2019/881 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p23">
						<alampunktNr id="4a3cae1f-97f8-4c0d-8b00-e10be410bddc">23</alampunktNr>
						<kuvatavNr id="48c2d063-aa7c-47c3-aac2-0614dec50cdc"><![CDATA[23) ]]></kuvatavNr>
						<sisuTekst id="f1eddc0e-a7dd-406c-8bd4-1d81064bd5db">
							<tavatekst id="78eab6d1-9a75-4d21-95d0-1c07501050e5">‘significant cyber threat’ means a cyber threat which, based on its technical characteristics, can be assumed to have the potential to have a severe impact on the network and information system of an entity or the users of the entity’s network and information system by causing considerable material or non-material damage;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p24">
						<alampunktNr id="51f605a2-012e-40a3-80b9-508c2af07893">24</alampunktNr>
						<kuvatavNr id="733c00d6-b104-4b1b-a8ce-b274007bdcee"><![CDATA[24) ]]></kuvatavNr>
						<sisuTekst id="a4a8f7f9-d8eb-40cc-a2be-7d50e1d5ca56">
							<tavatekst id="a08ea49d-6ae3-4729-a164-9ff3505302b2">‘cloud computing service’ means an information society service that enables on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including where such resources are distributed across several locations;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p25">
						<alampunktNr id="2918b90c-7274-48c5-836b-c5b89b2f141e">25</alampunktNr>
						<kuvatavNr id="7d3d09f8-f535-4ac3-a515-cf1d162fbc24"><![CDATA[25) ]]></kuvatavNr>
						<sisuTekst id="56410f9f-ea7e-4149-a678-2b164e68fa49">
							<tavatekst id="0c6a5fcd-5562-4bc0-93dc-3fa7d6bff0e3">‘risk’ means the potential for loss or disruption caused by a cyber incident, expressed as a combination of the magnitude of the loss or disruption and the likelihood of occurrence of the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p26">
						<alampunktNr id="ae56aa92-254d-47db-8368-0bd52f1272c0">26</alampunktNr>
						<kuvatavNr id="1d28614e-4875-4d4a-b4ca-db8745380945"><![CDATA[26) ]]></kuvatavNr>
						<sisuTekst id="615fe6a0-cc17-4c8c-bea4-d0fc7d0dc681">
							<tavatekst id="fcde6411-8021-4c3a-aec9-233f2512b12b">‘targeted security audit’ means an independent review and examination of network and information system datasets and operations to verify the adequacy of the security measures of the network and information system and compliance with applicable information security policies and operating procedures, to detect security breaches, and to recommend possible consequential changes to measures, policies and procedures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p27">
						<alampunktNr id="a26281db-401e-4187-95e7-8fab31fa2d72">27</alampunktNr>
						<kuvatavNr id="d1ed3cfe-b622-4e1c-aad0-b1a31625d36c"><![CDATA[27) ]]></kuvatavNr>
						<sisuTekst id="abd008f4-23ce-4a1d-b763-c658782e9a9a">
							<tavatekst id="c322a9de-ca80-48e0-bf58-bf67f7650a49">‘content delivery network’ means a network of geographically distributed servers for the purpose of ensuring high availability, accessibility or fast delivery of digital content and information society services to internet users on behalf of content and service providers;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p28">
						<alampunktNr id="9f1bf997-62f2-49c3-bc22-1324173fe27a">28</alampunktNr>
						<kuvatavNr id="8af6eabd-104b-49cb-aea7-09fb834a1316"><![CDATA[28) ]]></kuvatavNr>
						<sisuTekst id="85caab46-33f1-4790-9d36-2e8e12956dae">
							<tavatekst id="87155d00-e193-4760-868f-6a5bfcc4e937">‘social media platform’ means a platform that enables end-users to connect, share, discover and communicate with each other across multiple devices, in particular via chats, posts, videos and recommendations;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p29">
						<alampunktNr id="9516b595-f29b-40a2-a198-43c2d4f8af6d">29</alampunktNr>
						<kuvatavNr id="534b2bbf-8acd-4dba-a4d8-89d757a8b1d8"><![CDATA[29) ]]></kuvatavNr>
						<sisuTekst id="fc4e127a-16de-47e5-8afa-441b96066947">
							<tavatekst id="3a294f98-ef41-46c3-a80f-4044678687dc">‘research organisation’ means an entity whose principal activity is to carry out applied research or product development with a view to exploiting the results of such research or development for commercial purposes, but which is not an educational institution;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p30">
						<alampunktNr id="85366433-0ad0-4113-8347-7bf73d6b2e21">30</alampunktNr>
						<kuvatavNr id="dbd02d92-5392-4595-a65d-c53798012580"><![CDATA[30) ]]></kuvatavNr>
						<sisuTekst id="97d20e68-4f67-4d2a-9b0e-9a4a31b74429">
							<tavatekst id="ceac07b3-1c7a-4ffd-b4e1-427d0397c27b">‘top-level domain name registry’ means an entity which has been delegated the top-level domain associated with the Estonian country code and is responsible for administering that top-level domain, including the registration of domain names under that top-level domain and the technical operation of the top-level domain, including the operation of its name servers, the maintenance of its databases and the distribution of top-level domain zone files across name servers, irrespective of whether any of those operations are carried out by the entity itself or are outsourced, but excluding situations where the registry uses top-level domain names only for its own use;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p31">
						<alampunktNr id="7097b5b5-aa2b-4673-a451-f3e79c0ab5ac">31</alampunktNr>
						<kuvatavNr id="822477bb-0959-441c-ab92-3fdd0f025fc9"><![CDATA[31) ]]></kuvatavNr>
						<sisuTekst id="8908e608-bf40-42e9-95a2-2b3c144c2f51">
							<tavatekst id="a53ba248-f909-4055-ac62-65364a77eccc">‘vulnerability’ means a weakness, susceptibility or flaw of an ICT product or ICT service that can be exploited by a cyber threat;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p32">
						<alampunktNr id="c4382108-4ccb-408d-b728-74fdeeec0fa5">32</alampunktNr>
						<kuvatavNr id="22b59892-4e3e-4301-a1b0-9fdab83ca43e"><![CDATA[32) ]]></kuvatavNr>
						<sisuTekst id="7bfff294-13c7-464f-9bc1-2f811b773b76">
							<tavatekst id="029bfd23-abd0-4500-a673-300261ff105c">‘security assessment’ means a technical and organisational investigation of a network and information system to identify a vulnerability of the network and information system or non‑compliance of the security measures of the network and information system with applicable requirements;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p33">
						<alampunktNr id="03287c5b-66da-4746-bc93-95f6c65cd1cb">33</alampunktNr>
						<kuvatavNr id="e73d0e84-b5fe-4ffc-bd21-d8ace87f8897"><![CDATA[33) ]]></kuvatavNr>
						<sisuTekst id="5d04053c-6f48-421a-ade9-9b4e5dc2bafa">
							<tavatekst id="ccfd67e1-3aa0-41e1-8232-aa4e28fd294f">‘security measures’ means organisational, physical and information technology actions or means applied to achieve and maintain the security of data and network and information systems;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p34">
						<alampunktNr id="7c77f0d0-382a-45ff-b9a0-8253508ce31b">34</alampunktNr>
						<kuvatavNr id="ee6b7589-f311-456a-ba77-5731dc811ee3"><![CDATA[34) ]]></kuvatavNr>
						<sisuTekst id="3dd3cdbf-51ef-4074-adba-65186070dd2a">
							<tavatekst id="5c0c4838-dc4d-466f-8350-067ece73ad39">‘large-scale cyber incident’ means a cyber incident which causes a level of disruption that exceeds a European Union Member State’s capacity to respond to it or which has a significant impact on at least two European Union Member States;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p35">
						<alampunktNr id="828f3295-33d4-4251-a246-f3711456ac38">35</alampunktNr>
						<kuvatavNr id="d9c0171b-52b4-46fa-8ac1-c2e0316dc570"><![CDATA[35) ]]></kuvatavNr>
						<sisuTekst id="3b542f52-6eaf-446a-8251-26436d9fa928">
							<tavatekst id="db707f7d-c961-48dc-babc-72e83ab91d1a">‘trust service provider’ means a trust service provider as defined in point 19 of Article 3 of Regulation (EU) No 910/2014 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p36">
						<alampunktNr id="723ac278-836a-4fe1-8064-0c7fdb461cca">36</alampunktNr>
						<kuvatavNr id="6709498c-9ca5-41ce-b190-015817ab33b5"><![CDATA[36) ]]></kuvatavNr>
						<sisuTekst id="2d23060a-2431-4d86-8b53-d422fb3d128b">
							<tavatekst id="155aa97f-4ddd-4d3c-b9b2-39c2072c1070">‘online search engine’ means an online search engine as defined in point 5 of Article 2 of Regulation (EU) 2019/1150 of the European Parliament and of the Council on promoting fairness and transparency for business users of online intermediation services (OJ L 186, 11.07.2019, pp 57–79);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p37">
						<alampunktNr id="7943ae17-f3ae-4613-a8e9-d207354f7859">37</alampunktNr>
						<kuvatavNr id="39eaed19-4c94-4f6a-98f2-d7352aff3e4d"><![CDATA[37) ]]></kuvatavNr>
						<sisuTekst id="fc1b58fc-37b9-4b71-99ca-9982832915d7">
							<tavatekst id="77edc4d0-9dd5-4fe7-a214-177216962bab">‘network and information system’ (hereinafter <i>system</i>) means an electronic communications network for the purposes of clause 8 of § 2 of the Electronic Communications Act, a device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data, or digital data stored, processed, retrieved or transmitted by the aforesaid elements for the purposes of their operation, use, protection or maintenance;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p38">
						<alampunktNr id="ec4556a7-c892-44db-996c-81d56d6879e2">38</alampunktNr>
						<kuvatavNr id="5ef0220b-88cc-421e-9d8a-2d8db0efe1d3"><![CDATA[38) ]]></kuvatavNr>
						<sisuTekst id="655a6310-783b-4066-a68e-f8548f0eac89">
							<tavatekst id="b55fc89f-edb6-499d-8e2b-3404d2a7315a">‘security of a network and information system’ (hereinafter <i>security of system</i>) means the ability of the system to resist any event that threatens the availability, authenticity, integrity and confidentiality of data processed in the system or of the services offered by, or accessible via, the system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p39">
						<alampunktNr id="48af43be-6900-45ba-8dc4-cf0eb271a754">39</alampunktNr>
						<kuvatavNr id="29ff2f43-2bb1-4831-a82b-183363d7f53c"><![CDATA[39) ]]></kuvatavNr>
						<sisuTekst id="def168fd-3dea-447c-9044-77fb2f88c9fc">
							<tavatekst id="ff40e3ef-3eed-457c-882a-a9c852d5fe91">‘entity’ means a legal person created and recognised under the law of the country of its place of establishment, which may have rights and obligations, or a natural person;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p40">
						<alampunktNr id="79c68bbb-78a3-4966-8788-b0a98995a9e5">40</alampunktNr>
						<kuvatavNr id="947506b5-22b8-4767-b375-c99da2bbf110"><![CDATA[40) ]]></kuvatavNr>
						<sisuTekst id="d17a8e83-f125-4cd7-89fb-fd3fa0e39e4a">
							<tavatekst id="47899015-df87-42da-b5cb-4ca2a4b95013">‘publicly available electronic communications service’ means a publicly available electronic communications service for the purposes of the Electronic Communications Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para2lg1p41">
						<alampunktNr id="a940dc1c-ff23-4b99-a432-4b11fa3023da">41</alampunktNr>
						<kuvatavNr id="c8b5a05a-90cd-4952-b657-ea302153471e"><![CDATA[41) ]]></kuvatavNr>
						<sisuTekst id="9aae2346-26d9-400e-aec3-eb1288e4ae2c">
							<tavatekst id="72525b02-8bbf-4a80-9ec1-86735f5bb7a3">‘public electronic communications network’ means a public electronic communications network for the purposes of the Electronic Communications Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
			<paragrahv id="para3">
				<paragrahvNr id="87bdcc1b-a01f-45d8-b809-e2f62fcf70f7">3</paragrahvNr>
				<kuvatavNr id="38389e1f-00b8-4841-97ee-bce4e141dc8d"><![CDATA[§ 3. ]]></kuvatavNr>
				<paragrahvPealkiri id="0a0f7c6e-9edd-4638-b9fe-e59737a29745">Service provider</paragrahvPealkiri>
				<loige id="para3lg1">
					<loigeNr id="83ca29de-4555-4926-a424-be72faf90790">1</loigeNr>
					<kuvatavNr id="d5badf70-405a-4261-97f5-08c24bf31129"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="f806da5d-0502-4eed-91ca-b482a073812c">
						<tavatekst id="58d1e4d4-1b0c-4f17-bd77-efe565cfd39b">For the purposes of this Act, ‘service provider’ means an entity essential for the functioning of society (hereinafter <i>essential entity</i>) and an entity important for the functioning of society (hereinafter <i>important entity</i>).</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3lg2">
					<loigeNr id="f5e94162-9237-4f90-90ac-050c0f044bd2">2</loigeNr>
					<kuvatavNr id="b720622f-5ac0-4c57-a27e-b7a1ee03b641"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="df924f18-63d1-4228-a90c-ab10c0cc811a">
						<tavatekst id="c7118021-26fa-4f8c-b62a-9c03d80c573a">An essential entity is:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg2p1">
						<alampunktNr id="8665eab2-2e09-43b5-b3f6-b54938492c26">1</alampunktNr>
						<kuvatavNr id="6d1e63a0-c19e-4774-bfae-f14ad01e0607"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="b33b7db0-7d71-4d4c-b16b-975cd961f076">
							<tavatekst id="aef78b7c-681d-4c30-952d-94a72ba63b33">a domain name system service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p2">
						<alampunktNr id="f874e20d-29ef-4175-86a1-756a51a0b207">2</alampunktNr>
						<kuvatavNr id="ab626721-de62-4b13-8c8e-9d8f45a59dc0"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="664fa9a1-d5a4-4c10-b646-0bee9d00f9f9">
							<tavatekst id="287dc528-2832-40c5-8d97-4466a335be0e">a provider of a vital service for the purposes of the Emergency Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p3">
						<alampunktNr id="1865b9f0-2bc1-491e-b18b-9ef1ba9d18a2">3</alampunktNr>
						<kuvatavNr id="987787c2-c7b9-47b7-b71b-9f7a056a53df"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="e6b0e2e6-6943-46be-903a-2d2f3c6057f3">
							<tavatekst id="d621b83e-18fe-4350-be98-b94009c870cb">a central government public administration entity;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p4">
						<alampunktNr id="3dfaf42d-ac73-4924-8abf-00692c4405b5">4</alampunktNr>
						<kuvatavNr id="e6ef0f26-8e79-4317-83d3-70663644b1e4"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="6d77d182-ec54-4d84-b94e-f866543608c9">
							<tavatekst id="b23c2b69-dfd8-4c0e-ab4c-0db4286c83f2">a local government public administration entity;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p5">
						<alampunktNr id="e85c6d96-00d1-4697-aa44-fd33b3924919">5</alampunktNr>
						<kuvatavNr id="096d7a76-4892-4dc3-8617-91b98620fee4"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="2e81a42e-7092-4170-9083-7bcac5084753">
							<tavatekst id="2daf29aa-4d18-4fbe-aff9-5c4836fe5145">a provider of critical communications services, marine radio communications services and operational communications network services;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p6">
						<alampunktNr id="83e503da-1b75-46df-8203-8a4a052d8610">6</alampunktNr>
						<kuvatavNr id="80fc48da-0cc6-4aca-9139-f228f7449014"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="774ad2a0-647d-4f95-af03-4f11ee52ce6e">
							<tavatekst id="c44a2ab9-dac0-4db3-9024-2cdccbef05d1">a qualified trust service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p7">
						<alampunktNr id="8d893802-a7bb-4347-bde2-b7c0ec63c148">7</alampunktNr>
						<kuvatavNr id="f6b19874-5b7c-48ad-8769-3060689b5d65"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="4fe2e480-b308-465e-9356-e4ead289169f">
							<tavatekst id="bedb326e-6ef2-4375-ba75-a9ee79fdfaf6">a top-level domain name registry;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg2p8">
						<alampunktNr id="d2a43070-92b8-4146-8a64-491dd410681c">8</alampunktNr>
						<kuvatavNr id="f8bb8ffa-2c67-46e9-b9de-7105ff63b427"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="a479b1cc-b751-4e76-8ecb-dade266729ba">
							<tavatekst id="002868a4-6963-4e61-85f9-5332264a73aa">a provider of a public electronic communications network service or a provider of a publicly available electronic communications service who, according to the definition of a medium-sized enterprise set out in Commission Recommendation 2003/361/EC on the definition of micro, small and medium-sized enterprises (OJ L 124, 20.05.2003, pp 36–41), employs 50 or more persons during a financial year and whose annual balance sheet total or annual turnover exceeds 10 million euros.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3lg3">
					<loigeNr id="fb0099bc-f386-4ea5-a8d8-1f98216d4e9d">3</loigeNr>
					<kuvatavNr id="f3036f91-a614-48b4-82c8-5f8227617e9b"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="a4cb34a0-85c1-483a-9ab0-8d92cf2f81cc">
						<tavatekst id="9319b24e-079b-4bdd-ba1c-010b1ed1c3d8">In addition to that provided in subsection 2 of this section, an essential entity also includes an entity which, according to the definition of a medium-sized enterprise set out in Commission Recommendation 2003/361/EC, employs 250 or more persons during a financial year and whose annual balance sheet total exceeds 43 million euros or whose annual turnover exceeds 50 million euros, and which is:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg3p1">
						<alampunktNr id="2b145c36-cb22-4ce1-87c0-ebfbfef0f08b">1</alampunktNr>
						<kuvatavNr id="5b492432-aeb0-483f-a9d9-2959083af5ea"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="ca368d08-03db-422d-aafd-edbcca0b97fc">
							<tavatekst id="c00c35fe-3b7d-48f5-afbe-1fc4bc23e6b1">a data centre service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p2">
						<alampunktNr id="229295b5-9b2e-4b88-b151-eed652acdfbd">2</alampunktNr>
						<kuvatavNr id="da3a80c6-3131-4144-ab87-408eb87ecc50"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="b2954296-94cb-46d4-a03c-de7b2294c1dc">
							<tavatekst id="f3c54e82-5ec0-41dd-b8a4-4891b2be0338">an electricity undertaking for the purposes of the Electricity Market Act which engages in the sale of electricity, including the resale thereof to an electricity wholesaler or an end customer;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p3">
						<alampunktNr id="a2c756da-3d8c-4e59-8559-e3d3dbd5b635">3</alampunktNr>
						<kuvatavNr id="a573c3c7-9ff8-4567-a445-a7b1ff6997e2"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="9e6e56e4-03f5-48f6-825a-4275f7143cc5">
							<tavatekst id="8f0bad24-fe9c-44d1-98ef-74cb81828d96">an electricity undertaking for the purposes of the Electricity Market Act which engages in the generation of electricity;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p4">
						<alampunktNr id="fbba8564-166e-49e9-869f-5ef2683bf84b">4</alampunktNr>
						<kuvatavNr id="6535b936-24b3-424a-bbea-89e544a9581f"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="b88258a5-e6eb-46b2-896e-f4d8f76d9e8b">
							<tavatekst id="462483c5-14c5-4cba-888b-4c51d06b4251">an undertaking engaged in the collection, discharge or treatment of urban waste water, domestic waste water or industrial waste water as defined in points 1, 2 and 3 of Article 2 of Council Directive 91/271/EEC concerning urban waste-water treatment (OJ L 135, 30.05.1991, pp 40–52), except for an undertaking for which the collection, discharge or treatment of urban waste water, domestic waste water or industrial waste water constitutes an insignificant part of its overall activities;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p5">
						<alampunktNr id="07d96bb5-635e-4be9-8433-c65df545acdc">5</alampunktNr>
						<kuvatavNr id="cc7b7470-cc61-41e7-b396-7301b8707656"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="7a2ccd01-e7f1-441a-a376-fcbbbb5b5ad1">
							<tavatekst id="85793bc3-cf01-4aab-b297-16c5786f857c">an undertaking indicated, as regards maritime transport, in Annex I to Regulation (EC) No 725/2004 of the European Parliament and of the Council on enhancing ship and port facility security (OJ L 129, 29.04.2004, pp 6–91), which engages in the carriage of passengers and freight on inland waterways, at sea and in coastal waters, except for individual vessels operated by that undertaking;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p6">
						<alampunktNr id="20719082-e872-41f2-971f-54e17957346e">6</alampunktNr>
						<kuvatavNr id="ccd2c1ac-e8ca-48a6-9f86-34d16cdd9aab"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="90a7e80e-271a-4fad-b1ec-efd1924d0696">
							<tavatekst id="ded2bd93-6e86-42c2-90e8-a368c3be7484">a manufacturer of a critical medical device in a public health emergency specified in Article 22 of Regulation (EU) 2022/123 of the European Parliament and of the Council on a reinforced role for the European Medicines Agency in crisis preparedness and management for medicinal products and medical devices (OJ L 20, 31.01.2022, pp 1–37);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p7">
						<alampunktNr id="930c27c7-a9b4-480e-a56a-c40a7a95c843">7</alampunktNr>
						<kuvatavNr id="5d4252c8-7d19-4d23-93af-b6e473c2f4fb"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="eab671b8-f779-434b-bdf7-2d6b12e222fe">
							<tavatekst id="82f2b16c-943f-4bde-89e9-5f7e0f9e0dbe">a manufacturer of basic pharmaceutical products and pharmaceutical preparations referred to in Division 21 of Section C of NACE Revision 2, the statistical classification of economic activities in the European Community;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p8">
						<alampunktNr id="1865bf78-c050-4c55-aa75-615ff61cf6d3">8</alampunktNr>
						<kuvatavNr id="9e33a772-0809-4363-a916-5c95e5f76f9a"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="138e2357-f030-431c-82f0-ea0c377e85cc">
							<tavatekst id="feb47b6d-38fb-49b1-87f3-4b0eea7d6ef8">a gas undertaking for the purposes of the Natural Gas Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p9">
						<alampunktNr id="593e22a0-9ee6-4868-a179-c35bad686e37">9</alampunktNr>
						<kuvatavNr id="4c7e5b11-1a38-42ec-a8d7-50d467493aaf"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="9d089b6c-dd5f-49ce-8e3f-8475dfac153c">
							<tavatekst id="9e6ce9ac-362a-486b-80b1-8aa444f48b6c">a managed service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p10">
						<alampunktNr id="676fe044-6415-4a5e-993e-1a9edd0a7ac0">10</alampunktNr>
						<kuvatavNr id="d909dff8-f9c0-44b1-97a0-35692cf445a2"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="87131a63-65b4-4f7a-b4ef-b7beb1d84593">
							<tavatekst id="ac48c647-096e-4439-b6e0-e6e6377d6fe1">a storage network operator for the purposes of the Natural Gas Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p11">
						<alampunktNr id="1fcd3e7f-b787-45aa-92f6-bf0ccc0714fc">11</alampunktNr>
						<kuvatavNr id="918fe1e1-c307-4e1a-94be-a71bac2ac02d"><![CDATA[11) ]]></kuvatavNr>
						<sisuTekst id="6969582f-16b9-4ead-b052-3203899130bc">
							<tavatekst id="96ca882c-1a4a-4e57-9598-c10c775c3a59">an information security service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p12">
						<alampunktNr id="0365cdd9-d2b2-4e1e-9467-cb11dca61f6d">12</alampunktNr>
						<kuvatavNr id="c721e74c-036a-4a4f-9c42-d87c77f3a259"><![CDATA[12) ]]></kuvatavNr>
						<sisuTekst id="6ae11155-e30a-45f3-b2b0-5fb009ef4a2e">
							<tavatekst id="27aa70c4-75f6-4d2d-8db8-99873c68c02f">an internet exchange point service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p13">
						<alampunktNr id="abeaca7f-04eb-4f38-b693-44f1c7dc069f">13</alampunktNr>
						<kuvatavNr id="2d2d567a-72cd-4746-a867-a93cd2b06c65"><![CDATA[13) ]]></kuvatavNr>
						<sisuTekst id="3a359e61-38dd-41e8-80f1-0ba0a720bccd">
							<tavatekst id="16f627ab-28c5-47e4-9f56-3d6cf9ea3e2d">a distribution network operator for the purposes of the Electricity Market Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p14">
						<alampunktNr id="a8d8995e-a600-4531-b4c6-b98e442131d2">14</alampunktNr>
						<kuvatavNr id="bdc92737-8274-4673-83f9-c8efd841eeb9"><![CDATA[14) ]]></kuvatavNr>
						<sisuTekst id="055c7923-f996-4718-86f8-5c9b78665699">
							<tavatekst id="48877767-96d1-41b9-b768-7c2617a82d9a">an operator of a district heating and district cooling system for the purposes of the District Heating Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p15">
						<alampunktNr id="71bdf2c6-e238-4d0e-95a9-d845219ffe0e">15</alampunktNr>
						<kuvatavNr id="66f7609f-69f1-462c-b651-2745e5215e13"><![CDATA[15) ]]></kuvatavNr>
						<sisuTekst id="d89075c0-3d54-4e17-b453-2ff86f511bc5">
							<tavatekst id="d66cdde8-5e55-4661-9f9a-2ef6b35c92f0">a trading venue operator for the purposes of the Securities Market Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p16">
						<alampunktNr id="5ca5807c-0ac3-4e57-995d-48478169cfc3">16</alampunktNr>
						<kuvatavNr id="bd845278-8f37-454d-b83a-634b44991ae4"><![CDATA[16) ]]></kuvatavNr>
						<sisuTekst id="99215b65-1ff4-4d06-837b-6416bac44475">
							<tavatekst id="7c417dd9-fbbd-4bb8-aa63-8d7d7511c00c">a central counterparty for the purposes of point 1 of Article 2 of Regulation (EU) No 648/2012 of the European Parliament and of the Council on OTC derivatives, central counterparties and trade repositories (OJ L 201, 27.07.2012, pp 1–59);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p17">
						<alampunktNr id="495744d3-f86e-4539-b1be-4a53cc6e092e">17</alampunktNr>
						<kuvatavNr id="8a081bce-5040-426e-8b8f-9a3c7412f931"><![CDATA[17) ]]></kuvatavNr>
						<sisuTekst id="ded78940-188e-4a3d-be15-20e3ee05c11c">
							<tavatekst id="584e1b5b-7405-4e5e-bc66-e5adf72a3e37">an operator of ground-based infrastructure, owned, managed or operated by the Republic of Estonia or by a person governed by private law, which supports the provision of space-based services and which is not a provider of a public electronic communications network service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p18">
						<alampunktNr id="cf134d22-bdea-4cf5-836e-1495873df8bc">18</alampunktNr>
						<kuvatavNr id="f50b64ef-8225-4017-83bf-4ff5f56f7e38"><![CDATA[18) ]]></kuvatavNr>
						<sisuTekst id="2eee7219-a9e1-4137-8082-0d87ba37299d">
							<tavatekst id="9518324a-e8c9-4dc9-bec8-b61557cb7b37">a credit institution for the purposes of point 1 of Article 4 of Regulation (EU) No 575/2013 of the European Parliament and of the Council on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.06.2013, pp 1–337);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p19">
						<alampunktNr id="da2e6089-491f-40e4-9cf5-cee47c6ede38">19</alampunktNr>
						<kuvatavNr id="b7b8c4a6-484c-45b1-987c-a6b8c2b9e292"><![CDATA[19) ]]></kuvatavNr>
						<sisuTekst id="83ced020-afc3-429e-9dfd-93e6f4e0c78c">
							<tavatekst id="57e039af-066a-4065-8e49-bdceb4e71d98">an operator of a recharging point for the purposes of the Electricity Market Act, who is responsible for managing and operating the recharging point by providing a recharging service to end users, including on behalf of, and for, a mobility service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p20">
						<alampunktNr id="4f8d24b4-56cf-4cc3-8cec-5df2985a5f53">20</alampunktNr>
						<kuvatavNr id="52364ace-c386-4554-8042-7d1036846019"><![CDATA[20) ]]></kuvatavNr>
						<sisuTekst id="a6c48c99-a5d2-4458-80d9-3b7b4bc2bda3">
							<tavatekst id="25fe6bca-ff0e-4e27-aa79-a69384a2911b">an air carrier for the purposes of point 4 of Article 3 of Regulation (EC) No 300/2008 of the European Parliament and of the Council on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 09.04.2008, pp 72–84), which engages in commercial air transport;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p21">
						<alampunktNr id="941ce7cc-674e-49f8-9036-bcbf39fdc6ee">21</alampunktNr>
						<kuvatavNr id="67ddbbd9-0b32-4e70-88d1-109638abd849"><![CDATA[21) ]]></kuvatavNr>
						<sisuTekst id="7de381d3-534d-4c4a-84b3-ec70b064f8df">
							<tavatekst id="5ce82c33-7013-4921-a8f1-18314394ea1f">a managing body of an airport as defined in point 1 of Article 2 of Directive 2009/12/EC of the European Parliament and of the Council on airport charges (OJ L 70, 14.03.2009, pp 11–16), and an operator of airport ancillary installations;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p22">
						<alampunktNr id="0e61b10f-63d0-4ffc-81c5-3c5ede92348e">22</alampunktNr>
						<kuvatavNr id="639d5a57-d3fe-4b0b-831b-da20b2ad2e84"><![CDATA[22) ]]></kuvatavNr>
						<sisuTekst id="f04095ee-9d80-4032-a048-47d6b1944add">
							<tavatekst id="93a35891-2544-4f82-8500-e504a9644042">an airport operator for the purposes of the Aviation Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p23">
						<alampunktNr id="12d03eb9-89d8-42b9-b95f-331253706907">23</alampunktNr>
						<kuvatavNr id="b3dff14b-a2d2-4ae4-b847-d95745220173"><![CDATA[23) ]]></kuvatavNr>
						<sisuTekst id="62cc41c4-d030-44d4-84c7-78cbe5cf481f">
							<tavatekst id="0ee4c6c9-265f-45c6-acac-8deb34ef458d">an air traffic management undertaking providing air traffic control services for the purposes of point 6 of Article 2 of Regulation (EU) 2024/2803 of the European Parliament and of the Council on the implementation of the Single European Sky (recast) (OJ L, 2024/2803, 11.11.2024);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p24">
						<alampunktNr id="925edeae-74b6-4c25-9905-ce52f3afa8b4">24</alampunktNr>
						<kuvatavNr id="9b4f2201-f232-46a2-83bc-87262e3b9bda"><![CDATA[24) ]]></kuvatavNr>
						<sisuTekst id="71e4e983-2a81-480b-8fc4-ad715b03877e">
							<tavatekst id="453ab9a7-a175-46e1-852f-daf3006bdfab">an operator of an intelligent transport system for the purposes of the Traffic Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p25">
						<alampunktNr id="198f712e-ea9b-41a8-99e4-c4bdaf1ed364">25</alampunktNr>
						<kuvatavNr id="a7fabe87-9457-4114-9396-4c89f51470b5"><![CDATA[25) ]]></kuvatavNr>
						<sisuTekst id="0e9e99c4-bfbb-43f7-989d-4ee82bd23039">
							<tavatekst id="dbcda2ec-3f9f-450e-a8b6-7fad1b0eb3f8">an operator of a natural gas refining and processing facility;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p26">
						<alampunktNr id="f5e8705c-b06b-40d2-847a-24b92f95bebb">26</alampunktNr>
						<kuvatavNr id="7dce81c9-a6df-4625-af68-b5b8417f76a2"><![CDATA[26) ]]></kuvatavNr>
						<sisuTekst id="dc32beeb-b237-463a-8ddb-c9f87c27e2bb">
							<tavatekst id="3182c1b0-b5e6-42f7-b8bf-1807fbeedc5d">a gas undertaking for the purposes of the Natural Gas Act which engages in the sale of natural gas, including liquefied natural gas, and in the resale of natural gas to a wholesaler, an end customer and a gas undertaking purchasing natural gas;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p27">
						<alampunktNr id="fd298d08-ad82-41f7-9e6d-af0261ca4c94">27</alampunktNr>
						<kuvatavNr id="cbffbc94-8dd3-40a2-b09c-c7524f48cb6b"><![CDATA[27) ]]></kuvatavNr>
						<sisuTekst id="e1aa60a9-c9ec-4928-9509-4e5789b2c541">
							<tavatekst id="b3985333-8ae2-4545-8937-7ff81635c7be">a nominated electricity market operator for the purposes of point 8 of Article 2 of Regulation (EU) 2019/943 of the European Parliament and of the Council on the internal market for electricity (recast) (OJ L 158, 14.06.2019, pp 54–124);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p28">
						<alampunktNr id="e7af9fdc-be97-471b-bfe2-0e5bb17e071c">28</alampunktNr>
						<kuvatavNr id="76799799-ad0b-4dc7-8712-08b29711bf72"><![CDATA[28) ]]></kuvatavNr>
						<sisuTekst id="1a7e8d9a-ff78-413a-b671-b9ac2ed5e095">
							<tavatekst id="643a3270-50a7-4255-934f-cdbb7435efc6">an undertaking engaged in operating oil production, refining and processing facilities and in oil storage and transfer;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p29">
						<alampunktNr id="e02aade9-f31f-4cac-a280-cac43a1211db">29</alampunktNr>
						<kuvatavNr id="55fee114-b704-4fb7-876c-75199f8644b6"><![CDATA[29) ]]></kuvatavNr>
						<sisuTekst id="b4ac38d1-5505-4a4e-9d4b-eef80a9ea378">
							<tavatekst id="9fc50ae0-8f29-454f-8e1b-b504cab5e334">a cloud computing service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p30">
						<alampunktNr id="e973e88e-3bf3-410b-93b3-71f9dedd7dbd">30</alampunktNr>
						<kuvatavNr id="55356fc7-dffa-4a89-b7a1-2987a4d3c955"><![CDATA[30) ]]></kuvatavNr>
						<sisuTekst id="f20c56d1-20ca-4b30-b064-35195b6be49d">
							<tavatekst id="fa0856cf-e8ac-4050-a905-d145d780a7a0">a transmission network operator for the purposes of the Electricity Market Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p31">
						<alampunktNr id="23c3bd28-86f0-459e-86c0-dda1ed6a713d">31</alampunktNr>
						<kuvatavNr id="80844659-a6e0-4327-b5bf-45d255c36bfa"><![CDATA[31) ]]></kuvatavNr>
						<sisuTekst id="76226762-3e9f-4e8f-9851-219163c7f3dd">
							<tavatekst id="0ac334e7-79eb-4aee-a5fb-bcb7ca56e0d6">a railway infrastructure undertaking and a railway undertaking, including an operator of a service facility, for the purposes of the Railways Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p32">
						<alampunktNr id="b260899e-ff0b-4427-8b08-84f024cbbf0d">32</alampunktNr>
						<kuvatavNr id="ff3d046d-59df-4081-ac15-b96dfbbe746b"><![CDATA[32) ]]></kuvatavNr>
						<sisuTekst id="5efd823f-0a93-4222-bcb2-6566df50fe83">
							<tavatekst id="c9f619d0-33c0-4161-a31b-5f32484c3dde">a port operator or a holder of a port facility for the purposes of the Ports Act, including a holder of a port facility as defined in point 11 of Article 2 of Regulation (EC) No 725/2004 of the European Parliament and of the Council, and an entity engaged in managing operations and equipment in ports;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p33">
						<alampunktNr id="6c0d54e8-b134-4eb0-beb0-8a496d1331e5">33</alampunktNr>
						<kuvatavNr id="eef6437b-8847-4adc-ac38-793256c1c5bc"><![CDATA[33) ]]></kuvatavNr>
						<sisuTekst id="44a50dd8-9206-45c2-95ca-ba0c195c7040">
							<tavatekst id="a3dc8a40-b3b4-404e-99ac-dc4194493b90">a content delivery network service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p34">
						<alampunktNr id="47879785-9caa-4b7f-8129-1f740f9898ab">34</alampunktNr>
						<kuvatavNr id="0e0e3c22-c21a-488c-b5f3-c811253cabde"><![CDATA[34) ]]></kuvatavNr>
						<sisuTekst id="7282eec6-d5a4-403b-87b3-4e794c1c236f">
							<tavatekst id="d57a17e3-7938-4d32-adce-961db55caf41">a market participant for the purposes of point 25 of Article 2 of Regulation (EU) 2019/943 of the European Union and of the Council who provides an aggregation service, a demand response service or an electricity storage service for the purposes of the Electricity Market Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p35">
						<alampunktNr id="62dc37ec-da18-4177-8262-1ed4ea90a953">35</alampunktNr>
						<kuvatavNr id="09933f9e-cd33-4cd1-bff4-a6eae6d1ec7f"><![CDATA[35) ]]></kuvatavNr>
						<sisuTekst id="224b8ca8-770b-4d47-9fb9-d75b1de49fa6">
							<tavatekst id="ca6edb3e-e784-4248-8338-929a8725fb2e">an LNG terminal operator for the purposes of the Natural Gas Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p36">
						<alampunktNr id="316e0c40-c86c-40b3-a875-460f2fece9d2">36</alampunktNr>
						<kuvatavNr id="44ac0b05-7461-4050-a808-5233bb5f2f70"><![CDATA[36) ]]></kuvatavNr>
						<sisuTekst id="dcf3b6f6-ddc7-447b-baa7-962b8c992c21">
							<tavatekst id="2a2ad6c4-27ca-4f73-a0c4-d84839d53f41">a vessel traffic management centre;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p37">
						<alampunktNr id="54aca0be-6a8b-4b50-88b7-ab5baeaedf9f">37</alampunktNr>
						<kuvatavNr id="dadd60a5-ee72-4dde-8ada-40e3d001ed9a"><![CDATA[37) ]]></kuvatavNr>
						<sisuTekst id="7cb0c56a-dca4-4a5b-b56f-a509821c335e">
							<tavatekst id="f395a93d-cd14-4b82-8a30-b549331db409">a drinking water supplier and its distributor according to subsection 1 of § 17 of the Water Act, except for a distributor for which the distribution of drinking water constitutes an insignificant part of its overall activity of supplying other consumer goods and goods;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p38">
						<alampunktNr id="39996df6-d399-49ce-9ba6-485bc90b4e42">38</alampunktNr>
						<kuvatavNr id="dcca8bdc-6fb1-4bed-bbb6-39bd13d7e5ff"><![CDATA[38) ]]></kuvatavNr>
						<sisuTekst id="4d374671-2baf-424e-9139-1cce016af8d2">
							<tavatekst id="e8bc6200-b0db-4376-9065-abe57d6ef1b0">an undertaking engaged in hydrogen production, storage and transmission;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p39">
						<alampunktNr id="b53addfe-6add-4f0d-90a8-b26d035bab08">39</alampunktNr>
						<kuvatavNr id="62520dc7-98c2-4126-a215-ff26d9746550"><![CDATA[39) ]]></kuvatavNr>
						<sisuTekst id="5eeab8e6-3565-400f-92c8-50dcee240dd9">
							<tavatekst id="88291c35-eede-4c08-aa89-531f8986be63">an entity engaged in the research and development of a medicinal product for the purposes of the Medicinal Products Act, except for a veterinary medicinal product as defined in point 1 of Article 4 of Regulation (EU) 2019/6 of the European Parliament and of the Council on veterinary medicinal products and repealing Directive 2001/82/EC (OJ L 4, 07.01.2019, pp 43–167);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p40">
						<alampunktNr id="12db7ced-60af-4a8d-89fd-17bb198e2509">40</alampunktNr>
						<kuvatavNr id="97f555e6-e467-486b-aa0f-b264d3e1f34e"><![CDATA[40) ]]></kuvatavNr>
						<sisuTekst id="2f8586ca-8f9a-4959-909f-40649b69cbfa">
							<tavatekst id="551bbe68-6c90-4d5a-9487-0f82f7188b68">an entity which engages in the formation and management of a liquid fuel reserve for the purposes of the Liquid Fuel Reserve Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p41">
						<alampunktNr id="905253e7-52e6-4231-b9c8-4a7352cbe6d5">41</alampunktNr>
						<kuvatavNr id="cc0be528-54cd-40a8-9f83-8a38df17cbf3"><![CDATA[41) ]]></kuvatavNr>
						<sisuTekst id="d9bd2c9a-93dc-4c14-bad7-6e6649be1ce9">
							<tavatekst id="e318ee20-af92-443c-84dd-974bafe98950">an entity which performs the task of distributing natural gas and is responsible for the operation of the distribution system by ensuring the maintenance of that distribution system and, where necessary, the development thereof in a given area, and which, where necessary, ensures the interconnection of the natural gas network with other natural gas networks and the long-term ability of the natural gas network to meet reasonable demand for the distribution of natural gas;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg3p42">
						<alampunktNr id="ab78ecc2-ad81-49d6-bc1d-99b511033200">42</alampunktNr>
						<kuvatavNr id="5958fd1f-e659-42d5-b99d-713937bf5273"><![CDATA[42) ]]></kuvatavNr>
						<sisuTekst id="c9e7cc5d-cc5a-4b29-ab41-a062fdc5678f">
							<tavatekst id="731ab406-e239-451b-8d5f-ed6086e3818b">an entity which performs the task of transmitting natural gas and is responsible for the operation of the transmission system by ensuring the maintenance of that transmission system and, where necessary, the development thereof in a given area, and which, where necessary, ensures the interconnection of the natural gas network with other natural gas networks and the long-term ability of the natural gas network to meet reasonable demand for the transmission of natural gas.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3lg4">
					<loigeNr id="ea026ae8-3a0d-4003-b1f9-8b6f6a9d9bdb">4</loigeNr>
					<kuvatavNr id="d8d19bdf-7d54-4053-9ac6-9af3836d36a5"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="a415295d-d5fb-4af5-94ee-549141937646">
						<tavatekst id="224e15d3-09dc-474d-8d8f-5c5f236b5b3a">An important entity is:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg4p1">
						<alampunktNr id="bf7ab557-894c-42c7-81c6-3a4933526ebc">1</alampunktNr>
						<kuvatavNr id="cba110b2-0175-4bb2-8b80-f6970db0f84f"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="6e3210b4-baaf-4dff-ab0e-27c6cc122cf3">
							<tavatekst id="f3335542-aeec-4aae-a4f4-199edda39da9">the controller and the processor of a database for the purposes of the Public Information Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p2">
						<alampunktNr id="7314eb9b-caa3-45f3-b677-7afb2dee87ae">2</alampunktNr>
						<kuvatavNr id="05cc308f-1f30-4dca-97fc-2fe5181c98fc"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="180da2c5-a02f-44ee-ab17-752290d7afbc">
							<tavatekst id="2b2d8bce-5c04-48d3-a5cb-9d12b2f5ce88">the Foresight Centre;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p3">
						<alampunktNr id="f8e436ee-c087-43ee-aae1-01a36f7b225c">3</alampunktNr>
						<kuvatavNr id="1e2db5a1-0c24-4e3e-a131-8a9a66b43fca"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="d056769d-bb6a-4c7c-8bcd-57d4e691187a">
							<tavatekst id="4adf2e0d-62ed-42e8-b964-8329ba95acfb">a legal person governed by public law;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p4">
						<alampunktNr id="65998c3b-9aa7-4ec1-9c5e-c4bf814b3f28">4</alampunktNr>
						<kuvatavNr id="2ce61bd9-af1b-4bd6-8ccb-6c690d42d679"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="33c8051b-2a36-4178-91a6-379024e831f3">
							<tavatekst id="6da60e37-e64c-4d36-952f-5f2d8c8e9ec2">an association of local authorities;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p5">
						<alampunktNr id="8f1e3eba-ffc4-4dfa-b714-da6573b7331a">5</alampunktNr>
						<kuvatavNr id="676c3f59-e7ba-4ced-878e-07a224529d5e"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="556393a9-7f96-466c-b038-1a4ca09a2de0">
							<tavatekst id="89902515-aa21-417f-ad10-10204fdb3c2a">a provider of family physician care for the purposes of the Health Services Organisation Act who is not a provider of a vital service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p6">
						<alampunktNr id="70551e7a-a60b-4c73-b2ed-44a8a9d87bcb">6</alampunktNr>
						<kuvatavNr id="d8a37d7f-5cdd-4981-a8ca-4b0c24880997"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="2c4ae7ee-7d3a-4536-bb43-34c8858b0362">
							<tavatekst id="850cf26e-17f3-47c3-9125-6948267bc2bd">the State Forest Management Centre;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p7">
						<alampunktNr id="e382a00d-8ea7-4f51-bfe1-b546a713f168">7</alampunktNr>
						<kuvatavNr id="047461ce-58dd-4a72-b087-08ea54191a60"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="d73afa04-2465-4ebf-99fb-34d388876b74">
							<tavatekst id="8da00a10-d65c-45ed-9753-7ef569767eec">a trust service provider, except for a qualified trust service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p8">
						<alampunktNr id="630d2d4d-1c90-43e1-9344-a50c8fd29511">8</alampunktNr>
						<kuvatavNr id="0fb5c711-e22d-4f72-95c3-355fad0e7028"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="2ea52067-ad5b-45f1-9627-c330f5736b1f">
							<tavatekst id="3d32cddf-8b74-40e8-969f-97fbca390ced">an entity which is not an essential entity, but which, according to the definition of a medium-sized enterprise set out in Commission Recommendation 2003/361/EC, employs 50 or more persons during a financial year and whose annual balance sheet total or annual turnover exceeds 10 million euros and whose sector is listed in subsection 3 of this section;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg4p9">
						<alampunktNr id="121d260a-062e-47ac-8044-d77e3a332c11">9</alampunktNr>
						<kuvatavNr id="c98928cf-9444-4f04-b14b-87c9a8c0c5d0"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="b2ff554e-c5aa-4092-9adc-bf2316ca0415">
							<tavatekst id="bd3f1fed-4dfd-4297-ae88-cf2c73c2dfb6">a provider of a publicly available electronic communications service and a provider of a public electronic communications network service who does not meet the conditions specified in clause 8 of subsection 2 of § 3 of this Act.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3lg5">
					<loigeNr id="13880339-4181-46d7-8a3d-a03655b4518c">5</loigeNr>
					<kuvatavNr id="9dec5894-5ee3-439e-bbfc-fb74270129ff"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="4b495884-bb3e-4bdf-877e-ff000f6e4045">
						<tavatekst id="d28dbd94-e031-4e14-b3af-aba3534f718a">In addition to that specified in subsection 4 of this section, an important entity also includes an entity which, according to the definition of a medium-sized enterprise set out in Commission Recommendation 2003/361/EC, employs 50 or more persons during a financial year and whose annual balance sheet total or annual turnover exceeds 10 million euros, and which is:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3lg5p1">
						<alampunktNr id="aeca7f01-615a-42c8-a35e-92839d24b35f">1</alampunktNr>
						<kuvatavNr id="2fa3054d-ff7d-41d9-9e71-61fad4df1f15"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="bba8b8bd-873f-4f82-ad1b-936d917e53f3">
							<tavatekst id="e2801aad-3bba-4f81-b27d-1ac188d006f0">an undertaking whose principal activity is waste management for the purposes of the Waste Act, including supervision over waste handling and aftercare of a waste management facility intended for the disposal of waste;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p2">
						<alampunktNr id="319b3467-4628-453c-9ebf-c224d03877c6">2</alampunktNr>
						<kuvatavNr id="66748eaf-d577-459c-b533-692c71abba36"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="903a0548-c2be-4a38-87c6-00947e38bd21">
							<tavatekst id="729f00ae-ba9e-4022-afc7-3eb1aba4d8ac">an undertaking which manufactures substances for the purposes of point 9 of Article 3 of Regulation (EC) No 1907/2006 of the European Parliament and of the Council concerning the Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH) and establishing a European Chemicals Agency, amending Directive 1999/45/EC and repealing Council Regulation (EEC) No 793/93, Commission Regulation (EC) No 1488/94, Council Directive 76/769/EEC and Commission Directives 91/155/EEC, 93/67/EEC, 93/105/EC and 2000/21/EC (OJ L 396, 30.12.2006, pp 1–850), and places substances or mixtures on the market for the purposes of Article 3(14) of that Regulation, and an undertaking which manufactures articles as defined in point 3 of Article 3 of that Regulation from substances or mixtures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p3">
						<alampunktNr id="0e93bcb3-b068-4836-8547-39912bee4744">3</alampunktNr>
						<kuvatavNr id="df26d6a2-ef82-44e0-ba98-3e8208771273"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="9ea21ab4-f4f6-42ca-987c-68db3adfe802">
							<tavatekst id="e5c86fee-7bd4-4ba1-b8ec-799282fdce7b">an undertaking engaged in the wholesale, industrial manufacture or industrial processing of food, or in more than one of those activities, except for the wholesale, industrial manufacture and industrial processing of alcohol, in an undertaking as defined in point 2 of Article 3 of Regulation (EC) No 178/2002 of the European Parliament and of the Council laying down the general principles and requirements of food law, establishing the European Food Safety Authority and laying down procedures in matters of food safety (OJ L 31, 01.02.2002, pp 1–24), and the annual turnover derived from one or more of those activities constitutes at least 50 per cent of its annual turnover;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p4">
						<alampunktNr id="06d3fdd3-4217-4c7c-8a1c-00995d4c239a">4</alampunktNr>
						<kuvatavNr id="d8347e03-ed9e-450a-88d4-7ff20d69666c"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="a7c9406d-8dd3-40b4-b4a6-3288e271c10b">
							<tavatekst id="f11cc31f-52ff-4b77-b653-957657f66f45">a manufacturer of a medical device as defined in point 1 of Article 2 of Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 05.05.2017, pp 1–175), and a manufacturer of an in vitro diagnostic medical device as defined in point 2 of Article 2 of Regulation (EU) 2017/746 of the European Parliament and of the Council on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 05.05.2017, pp 176–332), except for a manufacturer of a medical device referred to in clause 6 of subsection 3 of this section;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p5">
						<alampunktNr id="cc640878-4baa-4cb4-b79c-eb80a816b281">5</alampunktNr>
						<kuvatavNr id="45b0e7d8-a45a-4cfe-a154-049f3d40465f"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="f92494bf-cb51-4c92-af6f-ea0abd3c8856">
							<tavatekst id="1d699b23-0e80-4bcf-802d-3aed91383922">an undertaking engaged in economic activities referred to in Divisions 26–30 of Section C of NACE Revision 2, the statistical classification of economic activities in the European Community;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p6">
						<alampunktNr id="3315aec4-b219-42e7-86c5-39213ae9abfa">6</alampunktNr>
						<kuvatavNr id="eb523d47-1e5a-48eb-8a23-83a37e7331be"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="3cf6fb48-2cf5-4227-9396-a38cd885b700">
							<tavatekst id="c7492b00-bc39-4392-beaa-9010ff5577d3">a provider of an online marketplace;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p7">
						<alampunktNr id="b981fc45-c7b1-400e-95a3-53fbba2b0b35">7</alampunktNr>
						<kuvatavNr id="4d2c5aca-49be-4c4d-99e4-805ea4ad814e"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="02f29efa-7159-4193-8160-e8f5edced5c1">
							<tavatekst id="bd399c6c-e049-4cfc-b91a-b50bfcae3a66">a postal service provider for the purposes of the Postal Act, including a courier service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p8">
						<alampunktNr id="1f73bba1-43eb-4d29-b851-997006769758">8</alampunktNr>
						<kuvatavNr id="1d4f3de0-ceb8-413b-b6b1-da38a53fe1d3"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="6cc7771c-a961-4f1b-8123-0b67c2d23462">
							<tavatekst id="37b79c1a-38a8-41c4-a749-cba55a4167a2">a provider of a social media platform;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p9">
						<alampunktNr id="b0e6b300-500f-4210-b753-f471c6a6a1e4">9</alampunktNr>
						<kuvatavNr id="639962c8-9759-415a-a166-bc10d57febc8"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="b295b9ba-a675-42a2-9972-5c580ebc6668">
							<tavatekst id="64b3b2ad-14c1-4609-9b07-1191e70c8898">a research organisation;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3lg5p10">
						<alampunktNr id="cb639374-ae52-406f-acee-c6924229d19d">10</alampunktNr>
						<kuvatavNr id="684bd246-1f45-4f49-ab4a-4a8aa3445fa6"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="3ad5143f-d95d-47cb-b36e-e5aeedf5c3c6">
							<tavatekst id="5deaf93e-a65e-4312-8e9b-2726019db1c2">a provider of an online search engine.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3lg6">
					<loigeNr id="7194169c-5a0b-4165-89d2-732511e0a9dd">6</loigeNr>
					<kuvatavNr id="33cc0c2f-77d6-4c61-8551-f93510968051"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="8b7e37a4-a407-48fa-9c2b-304ce6ec34f2">
						<tavatekst id="9e28f333-8f2d-4649-b327-256222b46f94">For the purposes of this Act, Article 3(4) of the Annex to Commission Recommendation 2003/361/EC does not apply when determining the number of employees of an entity, its annual balance sheet total and its annual turnover.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3lg7">
					<loigeNr id="60297682-28cd-49f9-aa51-619f3c6750d9">7</loigeNr>
					<kuvatavNr id="61cdee7c-6c11-4530-9abd-e5e103ed4eb7"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="0ba2494e-b283-4119-b95d-2e166c39bb7e">
						<tavatekst id="3affa021-ec49-4356-9e23-32e636b8e262">For the purposes of this Act, the data of partner enterprises or linked enterprises for the purposes of Commission Recommendation 2003/361/EC is not taken into account when determining the number of employees of an entity, its annual balance sheet total and its annual turnover, if, in respect of the systems used to provide services, the entity is independent of its partner enterprise or linked enterprise.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3lg8">
					<loigeNr id="01bad6ed-e9ec-4790-ad6f-be222cebc02a">8</loigeNr>
					<kuvatavNr id="03fddf14-64f1-4f04-9a04-911226f6d4ef"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="3e052160-10a2-463b-a66a-621a216f6a1e">
						<tavatekst id="6c0c2a93-89eb-4c5b-9d80-47baf0c38cb3">A detailed list of the processing domains and food groups specified in clause 3 of subsection 5 of this section is established by a regulation of the minister in charge of the policy sector of food supply security.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para3b1">
				<paragrahvNr id="547757ea-625a-44f4-a4cc-842e74883b51" ylaIndeks="1">3</paragrahvNr>
				<kuvatavNr id="987a88fa-1ef9-4e06-ab31-e774a093f481"><![CDATA[§ 3<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="83f36517-4bc9-4358-9782-539a8c3a4cde">Notification obligation and list</paragrahvPealkiri>
				<loige id="para3b1lg1">
					<loigeNr id="46d02abe-c2df-4cec-844f-45af69f1efde">1</loigeNr>
					<kuvatavNr id="c89c54d5-7cba-4dee-8edf-59a63e7eda76"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="e761fa11-9955-4312-a6ca-e24746608dfc">
						<tavatekst id="302cb762-9e4a-4dac-a6c4-84b14d01afaa">A service provider and a domain name registration service provider submit to the Estonian Information System Authority, for the compilation of the list specified in subsection 2 of this section, at least the following information:</tavatekst>
					</sisuTekst>
					<alampunkt id="para3b1lg1p1">
						<alampunktNr id="696b1b2b-53cf-47c6-a087-86eecff34613">1</alampunktNr>
						<kuvatavNr id="1b700756-af8b-4f43-b10d-bf0c18157f6d"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="58c9df18-aa69-4fa1-a9bf-6743b48c1457">
							<tavatekst id="cce155e9-ebb0-4285-85e0-b41bc8adc352">name and registry code;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3b1lg1p2">
						<alampunktNr id="a5053313-8cae-47db-a85b-89eb3ed4e174">2</alampunktNr>
						<kuvatavNr id="4bdb5b90-c9aa-46a5-87f4-d37b29e41b3c"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="b0cbaa21-6142-4c1d-8659-c82e5ffcee70">
							<tavatekst id="92eed9e2-8d5b-49ca-8010-b39412cc8f34">the address of the place of business and up-to-date contact details, including e-mail addresses, Internet Protocol address ranges and telephone numbers;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3b1lg1p3">
						<alampunktNr id="2b6788d0-35f7-4c5e-b4be-bbd982c0eac0">3</alampunktNr>
						<kuvatavNr id="2121134c-cc5b-47db-83c9-a7ba5917170a"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="9e270c1e-21ff-4cf7-85c4-db7aa3bbec49">
							<tavatekst id="ab9c1ff7-a6a5-4c78-96c1-8a1641bbb350">where appropriate, the relevant sector and subsector referred to in Annex I or II to Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, pp 80–152);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para3b1lg1p4">
						<alampunktNr id="f4ca013b-6542-46af-98a1-15f2d7bfe0fc">4</alampunktNr>
						<kuvatavNr id="654bac7f-9c42-4783-b0ba-4a2fe7a86fed"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="1c126df8-fd75-412d-9aec-3535000605b8">
							<tavatekst id="cde9107a-b65c-4274-87ae-b3f07280256d">where appropriate, a list of the countries in which it provides services falling within the scope of Directive (EU) 2022/2555 of the European Parliament and of the Council.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para3b1lg2">
					<loigeNr id="7d301047-d83b-4469-b34e-9c09e43f0ecb">2</loigeNr>
					<kuvatavNr id="65148954-7c7f-4d02-abaf-3dc3b620b868"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="565097cf-1c09-4411-9fba-c75dcf599f65">
						<tavatekst id="ce7e3bfb-1ae5-40b9-bfc8-7c14db43f4e2">Every two years, the Estonian Information System Authority compiles a list of service providers and domain name registration service providers.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg3">
					<loigeNr id="52446981-1d0d-448b-8b90-4ceabb1664b8">3</loigeNr>
					<kuvatavNr id="8c7fbbf6-5963-4853-9713-3545e2ff1c29"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="6c47006c-b75d-40d7-ad4f-9dd640a2191e">
						<tavatekst id="14659eca-6eba-4fcd-ab92-d71efbff20b5">The information specified in subsection 2 of this section is information intended for internal use for the purposes of the Public Information Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg4">
					<loigeNr id="f962172c-0672-41e4-9e27-3532ba48f9aa">4</loigeNr>
					<kuvatavNr id="2388735a-9da8-480f-a821-ec40040a380e"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="e70bebf0-e642-4462-9abb-e753a2293c1d">
						<tavatekst id="f3081c76-a249-420c-b4e9-c7620b8ded82">The service provider and the domain name registration service provider notify the Estonian Information System Authority of any changes to the information submitted pursuant to subsection 1 of this section without delay, but no later than two weeks after the date on which the change was made.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg5">
					<loigeNr id="57e54648-5b7b-4a7b-ba4b-e01febacd49e">5</loigeNr>
					<kuvatavNr id="f4442339-67b6-4a75-9ced-12d8f7836918"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="a254e803-e60e-4529-bcd0-648bf4e6d5e6">
						<tavatekst id="b2148c46-9ed1-4234-90d1-efc1ca8036ef">Every two years, the Estonian Information System Authority informs the European Commission and the Cooperation Group specified in Article 14 of Directive (EU) 2022/2555 of the European Parliament and of the Council (hereinafter <i>Cooperation Group</i>) of the number of service providers entered in the list specified in subsection 2 of this section, for each sector and subsector referred to in Annex I or II to that Directive.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg6">
					<loigeNr id="97ef31a5-bfc6-47b5-8220-c449116f4b06">6</loigeNr>
					<kuvatavNr id="f00025f0-b3bf-480d-913c-562a4b384ea8"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="b65d61b4-cbcc-40be-8081-7d49a0298935">
						<tavatekst id="6e9a6068-53cf-4fe2-b9b3-18a032ab1e17">Every two years, the Estonian Information System Authority submits to the European Commission information on entities which are essential entities and important entities on the basis of points b–e of Article 2(2) of Directive (EU) 2022/2555 of the European Parliament and of the Council.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg7">
					<loigeNr id="b34b2a2c-9f11-4c39-bd62-37cf6049e3b8">7</loigeNr>
					<kuvatavNr id="b76678cb-9d30-4c5b-be80-fd97c258dcb1"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="47ff183e-d477-461b-8e6b-8c8b9f0e7c25">
						<tavatekst id="bfe35a59-82c6-4c35-8684-5c1cae5b68f8">The information to be submitted on the basis of subsection 6 of this section is the number of entities, information on the sector and subsector referred to in Annexes I and II to Directive (EU) 2022/2555 of the European Parliament and of the Council and the type of services provided by the relevant service providers, together with information on which of points b–e of Article 2(2) of Directive (EU) 2022/2555 of the European Parliament and of the Council is the basis for considering an entity to be an essential entity or an important entity for the purposes of this Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg8">
					<loigeNr id="c87c847b-0db0-4e1e-8852-1b2d95b32029">8</loigeNr>
					<kuvatavNr id="01361450-2514-4195-a1cb-30ef6394f4e1"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="0f4d2612-dc8b-49c5-bf26-b8b4a6878f84">
						<tavatekst id="0d64494d-f65a-49c6-8c11-34aa0494ac91">Upon request by the European Commission, the Estonian Information System Authority may forward to the Commission the names of the service providers referred to in subsection 6 of this section.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para3b1lg9">
					<loigeNr id="b07188a2-f3c6-4df6-b699-a502dc2a5093">9</loigeNr>
					<kuvatavNr id="ff41dce2-f5f2-4b5f-a5c4-8e3df42a6871"><![CDATA[(9)]]></kuvatavNr>
					<sisuTekst id="eaa51bc5-5be5-4a64-88ef-17504edf278d">
						<tavatekst id="49a176ee-cee0-4c6d-aba6-d0b9b8cec8dd">In fulfilling the obligation provided in subsection 1 of this section, the service provider and the domain name registration service provider may follow the relevant European Commission guidelines and templates.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para4">
				<paragrahvNr id="7aab0bb4-50af-436c-80ff-a86833f735a7">4</paragrahvNr>
				<kuvatavNr id="0cf5b192-f6c2-444c-ba85-ed9023250ba3"><![CDATA[§ 4. ]]></kuvatavNr>
				<paragrahvPealkiri id="24c7f40b-a4f0-4b9a-b000-a28b0b3360e5">Requirements related to digital service provider</paragrahvPealkiri>
				<loige id="para4lg1">
					<loigeNr id="b4be8fad-8806-4aa8-9f51-af168ac42e6f">1</loigeNr>
					<kuvatavNr id="846b6e6b-e8e7-426e-bc23-b5bd7ab71905"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="d180d02a-7bf8-4c1b-9552-614839713109">
						<tavatekst id="8d5710d8-b356-40f0-9190-2510b3ecba6a">A digital service provider submits to the Estonian Information System Authority at least the following information:</tavatekst>
					</sisuTekst>
					<alampunkt id="para4lg1p1">
						<alampunktNr id="f355ac81-4b7f-42f4-987d-31c64f5bf453">1</alampunktNr>
						<kuvatavNr id="4f2cd189-c039-4b8f-bc82-1be11ec94b93"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="fddfb5b2-0f5b-42ac-9bca-a1e2645521f3">
							<tavatekst id="585fcdd6-9df1-4ab9-beba-b0062fbb02cc">name and registry code;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p2">
						<alampunktNr id="a262dc20-9ea8-46d6-82bc-d829bd5e1ec9">2</alampunktNr>
						<kuvatavNr id="ab9db242-e835-41a5-9c64-da53ea867276"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="5e5d6f9b-9ad8-442d-932f-b6b9b05dc0b7">
							<tavatekst id="89f47cfa-fff5-4534-8986-ea366b6dd335">where relevant, information on the relevant sector, subsector and type of entity referred to in Annex I or II to Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p3">
						<alampunktNr id="b5e68900-76ef-42e6-bd19-f563729fd906">3</alampunktNr>
						<kuvatavNr id="fda3d7f9-3a7b-4384-896b-b1f6f305ea38"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="a4567f40-175c-4e00-a5c1-ea1ed1ea3ac5">
							<tavatekst id="3e091ce0-f48e-47ec-ad2c-c5673a83cba2">the address of its main place of business and the addresses of its other official places of business in the European Union or, if it has no place of business in the European Union or is not established there, the address of the place of business of its representative;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p4">
						<alampunktNr id="f4f5be35-55f9-4575-a63e-66df07eb4d5b">4</alampunktNr>
						<kuvatavNr id="e638cbcf-87e4-4e93-b534-1e07515d436e"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="61c48d04-6b1b-4b15-9b83-30d51f02699a">
							<tavatekst id="2061fbae-5a07-47b2-8d15-336b1b5386ea">its up-to-date contact details and, where relevant, the up-to-date contact details of its representative, including the e-mail address and telephone number;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p5">
						<alampunktNr id="e78a26fc-cf9d-447c-8c6e-ba2d77b6130c">5</alampunktNr>
						<kuvatavNr id="cef95e31-50d8-49fd-8671-b27bbfe19cf0"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="56655bad-5d3a-4483-8822-f020a834ad60">
							<tavatekst id="e4c993ba-0021-4dfe-a9e2-e956c65fe91d">the Member State or Member States where the service is provided;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para4lg1p6">
						<alampunktNr id="16963fd7-db3e-41a6-8079-7cf0c2d80c6d">6</alampunktNr>
						<kuvatavNr id="c8f4e87e-acca-4047-9874-b218610dd41b"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="6bfcaee5-5efd-4f21-8f87-171871cfd868">
							<tavatekst id="8cb2bc67-e43e-4534-be74-89c3e800a197">Internet Protocol address ranges.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para4lg2">
					<loigeNr id="bba76843-9386-4906-b1ce-629ffedfec0a">2</loigeNr>
					<kuvatavNr id="24abaa30-cccf-4902-b820-05c10c3181cd"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="a1fecfde-f26a-4bc7-8b0a-0eac78a2dd1a">
						<tavatekst id="25a68cf9-2a24-439f-af56-7e808ebb5174">Estonia is deemed to be the main place of business of a digital service provider if decisions concerning the security measures of that digital service provider are predominantly taken in Estonia.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg3">
					<loigeNr id="76b4994e-cf2e-476d-9444-6b1fcab4e520">3</loigeNr>
					<kuvatavNr id="1ecb2e57-3edc-49c2-b6bc-f12b9fedc4ed"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="fe4c6d2a-4149-4d29-9518-7b5bcab84f3b">
						<tavatekst id="30e8654a-d9f5-43b3-ab7f-55d38d4f40da">If it is not possible to determine the main place of business of a digital service provider pursuant to subsection 2 of this section or if such decisions are not taken in the European Union, Estonia is deemed to be the main place of business of the digital service provider concerned if the activities related to ensuring the cybersecurity of that digital service provider take place in Estonia.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg4">
					<loigeNr id="af90af10-8654-4e11-a5b5-12dd49bafab6">4</loigeNr>
					<kuvatavNr id="22e4449d-b189-48e1-917a-2865ad92f8a7"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="df2bed0e-682b-461f-92c9-e7aebdc3b869">
						<tavatekst id="4afce363-2edd-47d9-8b27-1d80e7163db7">If it is not possible to determine the main place of business of a digital service provider pursuant to subsections 2 and 3 of this section, Estonia is deemed to be the main place of business of the digital service provider if the digital service provider has its place of business with the largest number of employees in the European Union within the territory of Estonia.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg5">
					<loigeNr id="a421dfbd-f26a-4e96-9f0d-9c63f798aa98">5</loigeNr>
					<kuvatavNr id="6b8b982e-a610-441f-9a3a-c27854cb69c7"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="f82eeede-eadb-45a8-906d-1d7642595ad6">
						<tavatekst id="168851e6-57ec-4fb4-91ab-608c98c1264b">Regardless of subsections 2–4 of this section, this Act applies to a digital service provider if the place of business of its representative is in Estonia or if its representative is established in Estonia.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg6">
					<loigeNr id="1f7a744b-4bf6-40f4-a29f-d15ca8b390b1">6</loigeNr>
					<kuvatavNr id="d1f4bbdb-effc-4df1-b1b1-086900fc89e2"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="0f9af9df-dc30-4eae-87f1-128c777f119c">
						<tavatekst id="34232a75-08d4-46f5-89d7-f0b79992e10e">A digital service provider notifies of all changes to the information submitted pursuant to subsection 1 of this section without delay, but no later than three months after the date on which the change was made.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg7">
					<loigeNr id="bdba6bc1-6864-4551-a67a-e9c2ed04a9cc">7</loigeNr>
					<kuvatavNr id="71da404b-2ad2-4779-af72-ef14f2509a36"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="d22b5dce-10eb-4541-ac50-e52f50c8b396">
						<tavatekst id="a8094288-9faf-423d-8eab-5cf40b4f01b5">The Estonian Information System Authority submits the information referred to in clauses 1–5 of subsection 1 of this section to the European Union Agency for Cybersecurity without undue delay.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg8">
					<loigeNr id="6e13610a-6600-4930-bec2-827dfbb096b7">8</loigeNr>
					<kuvatavNr id="cf227f05-eb74-42d9-9747-9955c458087c"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="b5ef8c41-52e3-449b-8bbc-0a2657699cfa">
						<tavatekst id="704e7b99-5275-4c2f-a89d-0b65129334d3">The Estonian Information System Authority may submit to the European Union Agency for Cybersecurity a request for access to the register specified in Article 27(1) of Directive (EU) 2022/2555 of the European Parliament and of the Council.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg9">
					<loigeNr id="5118af8d-525f-4c69-b15c-0e13f1171b5d">9</loigeNr>
					<kuvatavNr id="400fcd1f-ddd7-4057-aaea-6b465fb79d77"><![CDATA[(9)]]></kuvatavNr>
					<sisuTekst id="c8580597-42ce-4a2a-8fee-6562dba96a7c">
						<tavatekst id="6694dbc5-2b18-4457-b80e-15ae18c77e8a">In fulfilling the obligation provided in subsection 1 of this section, a digital service provider may follow the relevant European Commission guidelines and templates.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg10">
					<loigeNr id="3d9d9f2b-f2f5-4adf-9746-1c5d790ed56b">10</loigeNr>
					<kuvatavNr id="57bc5608-84fc-460b-84df-2d1c41a1d0c0"><![CDATA[(10)]]></kuvatavNr>
					<sisuTekst id="8bcd0353-c48f-43ac-83c2-832e85e91b3e">
						<tavatekst id="54e15048-a7d7-470b-9053-d917be3c391a">A digital service provider providing services in Estonia but established outside the European Union must designate a representative in Estonia or in another Member State of the European Union where it provides the service or where it is established, and must make the contact details of the representative permanently publicly available.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg11">
					<loigeNr id="159c39a6-0655-44bc-81f8-348c1abdf62f">11</loigeNr>
					<kuvatavNr id="f4965c61-e9df-4ad8-be09-df1deae72615"><![CDATA[(11)]]></kuvatavNr>
					<sisuTekst id="4d8a0ca9-4df2-4445-a27d-ba17e8e4ee91">
						<tavatekst id="27d82499-cf0a-4d24-bd62-f686f2cbfd08">The designation of a representative of a digital service provider does not restrict the taking of legal measures in respect of the digital service provider.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4lg12">
					<loigeNr id="d88918cf-4082-44e6-81d2-adcb38bf0e87">12</loigeNr>
					<kuvatavNr id="7203102c-a090-41c8-8582-f31829b47361"><![CDATA[(12)]]></kuvatavNr>
					<sisuTekst id="ad800665-a29f-42f7-b947-3bb0eda2d632">
						<tavatekst id="44879c99-0fef-4f87-a68c-17b13df3ea46">This Act also applies to a digital service provider that breaches the obligation to designate a representative in a Member State of the European Union.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para4b1">
				<paragrahvNr id="403a51c3-1112-4330-b118-dfdb21b9ac8b" ylaIndeks="1">4</paragrahvNr>
				<kuvatavNr id="fd816257-2fc2-4403-a3c9-e6df3f64b2bb"><![CDATA[§ 4<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="f0f2fc0d-0603-41b2-8078-80251e207aa9">Initial compliance with requirements and obligations</paragrahvPealkiri>
				<loige id="para4b1lg1">
					<loigeNr id="31584621-f67f-42bd-b305-4924d89c4cd7">1</loigeNr>
					<kuvatavNr id="3f363e8f-447b-4ec0-9a13-1dd6f99aedfe"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="c1479830-6201-4a20-95ea-141ca66cd928">
						<tavatekst id="47fa467f-ca8e-430f-9128-1b4caaa8c69d">A service provider and a domain name registration service provider are to fulfil the obligation provided in subsection 1 of § 3<sup>1</sup> of this Act within three months as of the date on which they become compliant with the characteristics of a service provider or a domain name registration service provider.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4b1lg2">
					<loigeNr id="e252a936-a032-43c1-9162-3a8e8daa27af">2</loigeNr>
					<kuvatavNr id="e945b7e4-4c45-42bb-9a8e-c5cf12edd4a1"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="38a59293-5e43-4ecf-865c-9ed00bb38b7f">
						<tavatekst id="640e0b02-9d61-4f0c-a0f8-67f4bc16e3ad">A digital service provider is to fulfil the obligations provided in subsections 1 and 10 of § 4 of this Act within three months as of the date on which it becomes compliant with the characteristics of a digital service provider.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4b1lg3">
					<loigeNr id="f041de01-9a2e-4523-924f-2d1615a84793">3</loigeNr>
					<kuvatavNr id="4f2a8e62-05e8-49df-b339-fbc50b4fc56d"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="473779f6-2209-4bbf-80d0-80871c1570b4">
						<tavatekst id="f6e77aa5-368a-4a12-bd7c-850842829038">A service provider, including a digital service provider, is to bring its activities into conformity with the requirements of this Act and the requirements established on the basis thereof and is to fulfil the obligations arising from this Act and legislation established on the basis thereof within three years as of the date on which it becomes compliant with the characteristics of a service provider, including a digital service provider. The service provider is to fulfil the obligation provided in subsections 1 and 2 of this section within the time limits specified in those subsections.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4b1lg4">
					<loigeNr id="3ba63343-1f3d-4da0-9c4b-c102fc943e5a">4</loigeNr>
					<kuvatavNr id="61837b7a-2ea4-44aa-b6fd-69d593b72c20"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="1ee0cedb-4b2c-44f1-b6d7-b1aa82d91189">
						<tavatekst id="9d777195-efba-403d-850a-173dac42947c">Regardless of subsection 3 of this section, a provider of a vital service must bring its activities into conformity with the requirements of this Act and the requirements established on the basis thereof within the time limit determined in accordance with the rules provided in clause 3 of subsection 1<sup>3</sup> of § 38 of the Emergency Act. A provider of a vital service is to fulfil the obligation provided in subsections 1 and 2 of this section within the time limits specified in those subsections.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para4b1lg5">
					<loigeNr id="aeb2aaaf-14e2-48be-9ae7-f1b998d1a5df">5</loigeNr>
					<kuvatavNr id="a0d99831-0b9e-456e-8340-47c3230bec09"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="85e259b4-601e-458e-92a7-1c70f355d355">
						<tavatekst id="e06348a0-ebeb-441c-8e36-a5f7c86eef90">This section does not apply to service providers to whom § 28<sup>1</sup> of this Act applies.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para5">
				<paragrahvNr id="d2159bb7-8849-409b-9be4-8b526ca35db8">5</paragrahvNr>
				<kuvatavNr id="78264031-4c6e-4fb1-8604-57ab6a960259"><![CDATA[§ 5. ]]></kuvatavNr>
				<paragrahvPealkiri id="659e6009-3b56-4028-8620-772fc08233ef">Competent authorities and tasks</paragrahvPealkiri>
				<loige id="para5lg1">
					<loigeNr id="8b00c0bc-93f9-469c-9e52-4c1e2299dc7d">1</loigeNr>
					<kuvatavNr id="33a92d55-0102-4733-bf56-6c632bf8fefa"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="b68c06a8-133b-4425-97d0-f96496bccf3c">
						<tavatekst id="2ee94afb-c0bf-4f6f-89d1-fee9b8f3e589">The Government of the Republic adopts the national cybersecurity strategy specified in Article 7 of Directive (EU) 2022/2555 of the European Parliament and of the Council, which may be prepared as part of a document provided by another legal instrument. The preparation of the national cybersecurity strategy is co-ordinated by the minister in charge of the policy sector of national cybersecurity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5lg2">
					<loigeNr id="e051586c-d611-4454-8175-446f16e78016">2</loigeNr>
					<kuvatavNr id="2fa08162-158d-48a2-bd3e-18e6557fa90c"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="f2be1598-c220-456f-b86d-6ae676e40d25">
						<tavatekst id="87a0fbdd-e4c7-4484-a50d-f42c5e3fff4c">The scope of the national cybersecurity strategy, the conditions and the procedure for implementation thereof, together with a list of the relevant policy measures, are established by a regulation of the minister in charge of the policy sector of national cybersecurity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5lg3">
					<loigeNr id="8c46054d-3f80-4edb-9fc1-e8bc5d8fad96">3</loigeNr>
					<kuvatavNr id="39ce947f-fea3-4c68-ae85-61d62ba8f977"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="46521118-aba4-4e7a-a7cf-22672aa3a906">
						<tavatekst id="d2744373-78a1-40f8-9a21-56d5faeb1026">The Estonian Information System Authority performs the following tasks specified in Directive (EU) 2022/2555 of the European Parliament and of the Council:</tavatekst>
					</sisuTekst>
					<alampunkt id="para5lg3p1">
						<alampunktNr id="a2ed2288-461d-4496-a6a5-9bca29a543be">1</alampunktNr>
						<kuvatavNr id="375d0440-5fa0-4608-bc07-0c7a79f44b0b"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="199a573f-b391-49df-a491-6cbf466dffc2">
							<tavatekst id="affdc4d5-11e1-4d45-8eca-da5213ba3ee3">the tasks of the competent authority specified in Article 8(1) and of the single point of contact specified in Article 8(3);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para5lg3p2">
						<alampunktNr id="84ef81c0-ed57-449d-83f6-dded24ebde3f">2</alampunktNr>
						<kuvatavNr id="3164767a-f4a1-481b-9b13-13abe2952c00"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="b7248c33-9745-4961-8253-a3bc1901d0f6">
							<tavatekst id="486aca3f-3d14-47dd-b535-73aaf01b4fae">the tasks of the competent authority responsible for the management of large-scale cyber incidents and crises specified in Article 9(1);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para5lg3p3">
						<alampunktNr id="e6c6412a-58e3-41d8-976d-0c492beee616">3</alampunktNr>
						<kuvatavNr id="50444f3c-c0fa-46b3-9353-603011b05f57"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="d6931c7b-e8f4-4072-8f62-a58b856f8c64">
							<tavatekst id="fcd2736b-6bd2-4884-ac9b-46188c3b3f92">the tasks of a computer security incident response team specified in Article 10(1);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para5lg3p4">
						<alampunktNr id="d1197c64-d475-4245-a69d-12f1d591d6ba">4</alampunktNr>
						<kuvatavNr id="9b28938c-81fa-4240-9fd8-a33524b57c7c"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="c88b6ce7-50a8-4153-9d0f-68e8cd4a6b28">
							<tavatekst id="8c0bbbba-c868-461d-ac00-ab9b8ccee3d4">the tasks of the co-ordinator for co-ordinated vulnerability disclosure specified in Article 12(1);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para5lg3p5">
						<alampunktNr id="0da46765-52da-427a-b196-136d888ba372">5</alampunktNr>
						<kuvatavNr id="8ff3f7fc-b896-404b-9fe4-28547f093f2b"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="279fa23a-8fee-4ed7-a3ff-2df811153d58">
							<tavatekst id="d4b45ef9-adc8-447c-82fb-3dbee109a236">the tasks related to participation in the network of national computer security incident response teams specified in Article 15 (hereinafter <i>network</i>).</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para5lg4">
					<loigeNr id="f61f2df6-b1e4-482b-b08d-2c74008b18a6">4</loigeNr>
					<kuvatavNr id="932efcb1-0e80-45c7-9c54-342aa3ce8a11"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="e37625e3-d20f-4cec-8059-9a6d0295310e">
						<tavatekst id="ba8fa2fa-a6d4-4fe9-85fa-d937611cefe7">A security authority performs the tasks of the competent authority specified in Article 8(1) of Directive (EU) 2022/2555 of the European Parliament and of the Council to the extent provided in § 14 of this Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para5b1">
				<paragrahvNr id="a94273c1-e092-46e1-8b92-eaa1ecee0ba1" ylaIndeks="1">5</paragrahvNr>
				<kuvatavNr id="bc79cd9f-9db6-4d2a-9dd1-586618a3d018"><![CDATA[§ 5<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="dde782e1-8d92-4a53-807b-6fea57ff01b4">European Cybersecurity Industrial, Technology and Research Competence Centre and National Coordination Centre</paragrahvPealkiri>
				<loige id="para5b1lg1">
					<loigeNr id="ac5c5360-7be2-403d-8d43-d2b1a37b3aa1">1</loigeNr>
					<kuvatavNr id="b94a1855-074b-46f5-b97e-f4d3302f389b"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="254a9838-c5af-416c-ae65-caf27978dc02">
						<tavatekst id="53159bea-8fe8-420d-a9f4-ad376183f43e">For the purposes of Article 12 of Regulation (EU) 2021/887 of the European Parliament and of the Council establishing the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres (OJ L, 202, 08.06.2021, pp 1–31), the representative and alternate of the Governing Board of the European Cybersecurity Industrial, Technology and Research Competence Centre are appointed by a directive of the minister in charge of the policy sector.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b1lg2">
					<loigeNr id="00d36118-e7a0-47f0-9b66-8395795cc510">2</loigeNr>
					<kuvatavNr id="c0ef0b34-a11e-4577-a872-579b504afd13"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="af85bb7d-c860-43ba-8972-74118a3292b1">
						<tavatekst id="e50be6c3-7070-481e-8938-06ce3be81e8a">For the purposes of Article 6 of Regulation (EU) 2021/887 of the European Parliament and of the Council, the functions of the national coordination centre are performed by the Estonian Cybersecurity Industrial, Technology and Research Coordination Centre.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b1lg3">
					<loigeNr id="b96ecd75-ec17-4612-8ddb-9cc5bd2389ba">3</loigeNr>
					<kuvatavNr id="979586ae-4a45-4e67-977d-31d155609c30"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="d5db3ab0-3341-45b4-b076-e58c44cbfed7">
						<tavatekst id="4a212df3-39aa-49bf-a348-4c299c52c15a">The coordination centre specified in subsection 2 of this section is appointed and the procedure for the performance of its functions is established by a regulation of the minister in charge of the policy sector.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para5b2">
				<paragrahvNr id="76933714-be24-4f6c-84ce-c1a15840f1ec" ylaIndeks="2">5</paragrahvNr>
				<kuvatavNr id="aca8d70d-5d16-4cff-8acc-29e6b03f17dd"><![CDATA[§ 5<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="98de3a6e-7e91-497f-9114-591ae6a270b3">Competent authority carrying out cybersecurity supervision in field of cross-border electricity flows</paragrahvPealkiri>
				<loige id="para5b2lg1">
					<loigeNr id="0aea3f96-a13b-4405-8ed1-35034129e145">1</loigeNr>
					<kuvatavNr id="418b61a4-7dd1-42b9-8835-70f8a28b826f"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="b34d8a10-7ebf-42de-8777-a0deea793c99">
						<tavatekst id="21b3955f-e19c-40e1-a40d-6dedc44dec0f">The competent authority specified in Article 4(1) of Commission Delegated Regulation (EU) 2024/1366 supplementing Regulation (EU) 2019/943 of the European Parliament and of the Council by establishing a network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows (OJ L, 2024/1366, 24.05.2024) is designated by a directive of the minister in charge of the policy sector of national cybersecurity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b2lg2">
					<loigeNr id="ed00d997-3fe4-4afa-9d2b-2592316e8938">2</loigeNr>
					<kuvatavNr id="5b6b8da8-74c9-4ef9-8a4a-1f4907ba46aa"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="c52769d7-69a4-47ef-89fe-a9ff64830873">
						<tavatekst id="25c7224e-c142-4d3d-94d8-78113782cbf8">When designating the competent authority specified in subsection 1 of this section, the requirements provided in Article 4(3) of Commission Delegated Regulation (EU) 2024/1366 and in the Administrative Co-operation Act are taken into account.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para5b2lg3">
					<loigeNr id="23417d71-0268-4a9a-9f35-1e6a99cabba3">3</loigeNr>
					<kuvatavNr id="b798adb8-3369-4362-a904-88b4cc52f85c"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="7f55f606-21db-4fd7-9cf7-c459d3328864">
						<tavatekst id="28c7391b-2995-477e-aa90-176973be3d5e">The Government of the Republic may further delegate the performance of the tasks referred to in Article 39(1), Article 40(4) and Article 41(1) and (2) of Commission Delegated Regulation (EU) 2024/1366 to the regional co-ordination centre established pursuant to Article 35 of Regulation (EU) 2019/943 of the European Parliament and of the Council on the internal market for electricity (OJ L 158, 14.06.2019, pp 54–124), taking into account the requirements provided in the Administrative Co-operation Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para6">
				<paragrahvNr id="43a8e3f7-1b88-4e2e-b5ce-16be168af02e">6</paragrahvNr>
				<kuvatavNr id="fadb695b-7c7e-43c8-89dc-af37eb1a2a62"><![CDATA[§ 6. ]]></kuvatavNr>
				<paragrahvPealkiri id="d4b7a374-2d57-431e-9897-25c1cd2f3754">Principles of ensuring cybersecurity</paragrahvPealkiri>
				<loige id="para6lg1">
					<loigeNr id="0d669a28-32b3-43f9-a8b7-4fff94dd19c9"/>
					<kuvatavNr id="c5bf87ad-1ed8-45cc-9a3e-2217103934db"/>
					<sisuTekst id="9f2d60b0-8d22-422d-8b64-d86b925c8b4c">
						<tavatekst id="2e7db0aa-1f6c-4c45-aa1a-df32393f0ed8">The following principles are taken into account in ensuring cybersecurity:</tavatekst>
					</sisuTekst>
					<alampunkt id="para6lg1p1">
						<alampunktNr id="72e92571-41cd-4422-9323-388c37dd38f0">1</alampunktNr>
						<kuvatavNr id="91a33025-e642-48d1-9c43-d9e314e7fae2"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="1f37b3e1-786f-4ae0-96e9-6d5217d19823">
							<tavatekst id="816d25a2-bbcc-4c79-a7e2-7be631f5aecd">the principle of personality – ensuring the security of a system is arranged by the service provider;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p2">
						<alampunktNr id="604aaad0-722f-488c-a764-7af4264c805c">2</alampunktNr>
						<kuvatavNr id="c74ac0ac-72b9-4923-9741-5036fcac8827"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="642a404b-763f-4f78-8b32-6142fabcfa47">
							<tavatekst id="f10434c1-c7a7-483d-b6b7-b0992c80cfdb">the principle of integral protection – the service provider ascertains potential risks posed to the system and applies appropriate organisational and technical measures for the protection of the system;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 301.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p3">
						<alampunktNr id="00e4d231-a350-45de-a038-96248fd52e5d">3</alampunktNr>
						<kuvatavNr id="5c5317b0-e65f-4241-9f97-7bc5dee23107"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="76bad8e3-cedd-403d-9540-5b842cad6055">
							<tavatekst id="60ca7b90-8579-4ea3-b67f-cf335758274d">the principle of minimising adverse effect – in the case of a cyber incident the service provider applies due care and measures to avoid the escalation of the effect of the cyber incident and its possible spread to another system and notifies the supervisory authority provided in this Act of the cyber incident;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para6lg1p4">
						<alampunktNr id="133763ea-5e83-4aef-8c8a-87e08fca769f">4</alampunktNr>
						<kuvatavNr id="c1eb86e5-5f4c-4fb4-b8f0-b3a5556d86df"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="1c1b1104-6ce4-48bb-a4aa-92ac09c69de2">
							<tavatekst id="41de725f-d640-4cdd-b99d-8452cba498ac">the principle of co-operation – in ensuring cybersecurity and resolving cyber incidents the parties co-operate and, where necessary, take into account the mutual connection between and dependence of the systems and services.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="03b2b263-b14d-4a45-8ebf-324bf188cc4b">
			<peatykkNr id="a3b6d25f-2fd6-4546-990a-c8c0e85ce501">2</peatykkNr>
			<kuvatavNr id="78e52a18-c1f5-4b92-b377-5fc17b01d139"><![CDATA[Chapter 2]]></kuvatavNr>
			<peatykkPealkiri id="2a08d6ab-e7c9-419d-9b19-5b8c6988e321">Obligations for Ensuring Cybersecurity </peatykkPealkiri>
			<paragrahv id="para6b1">
				<paragrahvNr id="45a7fa51-ab81-45a4-be6a-b26b465f824c" ylaIndeks="1">6</paragrahvNr>
				<kuvatavNr id="d6771445-2670-4478-8df6-b454a6f851c5"><![CDATA[§ 6<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="5c7b4a84-5a70-4560-8831-8a9d988d6bb7">Obligations of member of management board of service provider</paragrahvPealkiri>
				<loige id="para6b1lg1">
					<loigeNr id="6615feef-bd56-4fe1-825d-b513ba736ce9">1</loigeNr>
					<kuvatavNr id="9f3c0887-5cc2-4232-a58f-e4f38097b2c7"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="aff9c470-ff7d-473a-adb4-e649a587cc36">
						<tavatekst id="ad26a13a-1773-4a88-a692-7375ac6715d1">A service provider is to designate at least one member of the management board who approves the security measures, oversees their implementation and is responsible therefor. At the request of the Estonian Information System Authority, the service provider submits the name and contact details of the relevant member or members of the management board. The obligation to designate a responsible member of the management board does not apply to a service provider that has one member of the management board.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para6b1lg2">
					<loigeNr id="54b7a4f5-60a3-4bce-8d2b-c99bf8891460">2</loigeNr>
					<kuvatavNr id="afab394a-1ee5-45a0-9781-2018d59ba58a"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="0f26f8b4-3132-490c-8ee7-5058c50326c2">
						<tavatekst id="56c262bf-20d5-4280-9e9c-d6a07cf27160">The member of the management board of a service provider specified in subsection 1 of this section undergoes regular training with the aim of acquiring sufficient knowledge and skills to understand and assess risks, their impact on the services of the service provider and the ways of managing risks.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para6b1lg3">
					<loigeNr id="e0d8ca7e-72ca-473c-9fc0-08e10743273a">3</loigeNr>
					<kuvatavNr id="c2de2d1e-8b45-4596-90a7-ea7e6760f911"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="e9cc515a-5d00-4077-86e9-28ee2a2e3aa0">
						<tavatekst id="b74c7e5d-b0ca-4f00-9993-58797c0b92b7">If a service provider does not designate the member of the management board specified in subsection 1 of this section, the obligations provided in this section apply to all members of the management board.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para6b1lg4">
					<loigeNr id="2853622f-f5b1-4aab-a5eb-21bc070b5dd2">4</loigeNr>
					<kuvatavNr id="581aafa4-a036-4a77-905c-1970329e9063"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="45a53e51-f3bc-4828-9a7f-562af49ce68b">
						<tavatekst id="ff152e2e-2b74-42a4-a02a-89a7c3771e34">If a service provider, due to its legal form or structure, has no member of the management board, the provisions concerning a member of the management board also apply to another person who, under the law, the articles of association or another legal instrument, is designated in the service provider to perform management functions. If the service provider is a sole proprietor, the provisions concerning the obligations of a member of the management board of a service provider apply to the respective natural person.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para7">
				<paragrahvNr id="dc16491c-aa6e-4d7a-aa28-336674cfad0a">7</paragrahvNr>
				<kuvatavNr id="20769a61-0712-48c9-8d7b-c11f88d0ef4b"><![CDATA[§ 7. ]]></kuvatavNr>
				<paragrahvPealkiri id="fa03f7bb-9053-4868-938c-0ab37a20e920">Security measures of service provider’s system</paragrahvPealkiri>
				<loige id="para7lg1">
					<loigeNr id="c0937b08-7e4b-41a0-b568-e10f587a8df4"/>
					<kuvatavNr id="0d23e754-44b5-449d-bca7-66f2cd67d9f8"/>
					<sisuTekst id="f99c2130-11e6-4c6c-b1a0-1e65f63daf92">
						<tavatekst id="b89151a3-b3c3-4843-ae9a-9c4f5436258a">[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg1">
					<loigeNr id="e9c59d5f-2a7c-4949-969b-833fb4577ccd">1</loigeNr>
					<kuvatavNr id="2d5dc8b6-6368-4290-ad8c-6b0c6689b7d5"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="91ba25dc-8ed8-4b9c-96d2-6a23173deb3c">
						<tavatekst id="0ba65f1f-4843-4a25-aaf1-728a2e11a400">A service provider implements, on a permanent basis, appropriate and proportionate technical, operational and organisational security measures in order to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg1p1">
						<alampunktNr id="a9852039-b438-4ba1-ac8f-938e0c0cf974">1</alampunktNr>
						<kuvatavNr id="3f93dab9-0d59-40f6-adab-b13904f815c3"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="dd0b3f42-da68-44ce-9483-e0a186f75dd9">
							<tavatekst id="623297cf-237c-4aca-8888-70807a1e6a91">manage risks posed to the security of the system used in the activities of the service provider or in providing the service, including by preparing a corresponding risk assessment;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg1p2">
						<alampunktNr id="ba9441e8-45e5-48c9-a8e7-8bbd9b3680d0">2</alampunktNr>
						<kuvatavNr id="0160c955-720c-4e43-b72e-3631c655a306"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="044c086d-b38c-4414-9cd9-c7188de60f17">
							<tavatekst id="495c7497-29a7-4343-b49a-2c919148fa64">prevent or minimise the impact of a cyber incident on the recipient of the service provided by the service provider and on another service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg1p3">
						<alampunktNr id="621faee9-7eb7-4260-b5a0-f5fd7fa684eb">3</alampunktNr>
						<kuvatavNr id="b03c7640-77e1-406c-8403-4e81765a1dd3"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="e66c495b-0073-45ff-b016-43ba2daf4c5d">
							<tavatekst id="9c1135e8-fc8f-4ca7-a84f-4bed13c09314">prevent a cyber incident or detect and respond to it.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para7lg2">
					<loigeNr id="c897cadc-9005-41b1-8bda-6ce4c1a45d35">2</loigeNr>
					<kuvatavNr id="5a76d4e5-3080-4f8e-832f-7c1684c5c745"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="49e864a1-13c1-4625-81ad-3ef9ac3085ac">
						<tavatekst id="edc1db43-c23d-40fd-bde2-6a045b2cfd7d">In implementing security measures, the following are taken into account:</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg2p1">
						<alampunktNr id="5935bf31-dfbf-4231-8b4d-812ed4d3842f">1</alampunktNr>
						<kuvatavNr id="6efac787-cb65-4d0f-8025-44375ce0c926"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="243db539-e845-434b-b06d-56173a2de784">
							<tavatekst id="2468edd4-f023-4e60-a777-a214cfd404d1">the needs and security requirements of the service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p2">
						<alampunktNr id="b4543916-63f7-41b8-b002-a0376f35d19c">2</alampunktNr>
						<kuvatavNr id="44f39029-ca43-4b07-ac00-c8281612d1dd"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="0326e492-56b5-429d-9a67-511fb91ad0f8">
							<tavatekst id="67471690-7a6a-45f7-ae87-fe23f9937be3">up-to-date and, where relevant, European and international standards;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p3">
						<alampunktNr id="0bac8689-8bc9-4f38-9e7b-e3a14cbaa258">3</alampunktNr>
						<kuvatavNr id="176eae06-0402-475a-a5cc-b94c49025531"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="5d4840fd-4767-46e9-b7c0-03460ebd0d3e">
							<tavatekst id="e25c27c4-4726-45d4-acbe-e64db11c281a">the costs of implementing security measures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p4">
						<alampunktNr id="1fc91163-2c63-4067-a4e1-9e0c2c8491ec">4</alampunktNr>
						<kuvatavNr id="55842a05-c0ec-4b27-9431-79a7dab7a126"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="0960b8ad-c485-459d-8041-12f915dce6eb">
							<tavatekst id="028ef79b-6150-48ea-8872-2712db3a9a17">the proportionality of implementing security measures, in the assessment of which, among other things, the degree of the service provider’s exposure to risks, the size of the service provider, the likelihood and severity of cyber incidents, including the societal and economic impact of cyber incidents, are taken into account;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg2p5">
						<alampunktNr id="5ff5f39f-87ed-4a41-bf85-15f1df06be30">5</alampunktNr>
						<kuvatavNr id="81058c34-f53f-455f-80bf-9a27c1bf769f"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="f2c97d8f-060f-4332-8c02-3845137abccd">
							<tavatekst id="c4a61c18-84c8-437d-bbf8-84a336125ade">a systematic and comprehensive approach to threats with the aim of protecting systems and the physical environment of those systems against cyber incidents.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para7lg3">
					<loigeNr id="bc8d5595-6006-4587-8bb1-4472cb07c102">3</loigeNr>
					<kuvatavNr id="e59b8935-515f-4dfc-976f-661e67019a7f"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="b10a22ee-8695-47cd-a46b-bdbd6e95df89">
						<tavatekst id="e7a64fbc-0958-4ae6-b29b-ffccf8d9aedb">If a service provider authorises another person to manage the system or hosts the system with another person, the service provider is responsible for making sure that the other person ensures the implementation of the security measures of the system.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg4">
					<loigeNr id="7d6a728e-40c0-421d-a9d2-737ca78731fa">4</loigeNr>
					<kuvatavNr id="da0ffee7-77b3-4b25-a3d1-ce5eb9276e84"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="44ba83f9-ccf7-4990-b3c0-5b98d8441d70">
						<tavatekst id="c2e8c1d1-b5d4-45aa-912f-6aa619de296b">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg5">
					<loigeNr id="8c7ef371-6688-4d9a-aeea-33af6c232a89">5</loigeNr>
					<kuvatavNr id="3355f7cf-c42e-445f-ac77-f78e17c430dd"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="bf5b28b2-85ec-4aa8-ad2a-246966f7223e">
						<tavatekst id="929640bf-a00f-4165-8cca-36c012247528">For ensuring the performance of the obligations provided in this section and the cybersecurity of systems, the Government of the Republic or a minister authorised thereby establishes by a regulation:</tavatekst>
					</sisuTekst>
					<alampunkt id="para7lg5p1">
						<alampunktNr id="d1f9bd00-366c-4aa1-a3f8-0eeeed5cc407">1</alampunktNr>
						<kuvatavNr id="ecc53b91-2fd1-4d3a-b656-5f36e58843c8"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="405a7f98-2acf-4d28-b1dc-6a3da7a25c31">
							<tavatekst id="56217046-b2df-4fdb-8b4d-362330c229ca">requirements for information security management under general title ‘Estonian Information Security Standard’;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg5p2">
						<alampunktNr id="d28d7119-44d7-41eb-84ce-1a74a06766b2">2</alampunktNr>
						<kuvatavNr id="f173a67b-0a5f-47d2-bc8a-418ed18ef8ab"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="b62024b1-0f3e-4a43-8f56-2afbee31a6bb">
							<tavatekst id="608c060e-db8d-43a8-91a8-c468f834e3a8">general requirements for security measures;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para7lg5p3">
						<alampunktNr id="204a2b06-523a-4cd9-b065-eb7b61636009">3</alampunktNr>
						<kuvatavNr id="61b2442c-5e8b-463d-8ed8-73218bd1a06c"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="224c6a05-da97-42a8-b005-b092eec82c39">
							<tavatekst id="990a367c-ecc2-4fae-80c4-81051c28a35d">special requirements for system security measures and the scope of application of such requirements.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para7lg6">
					<loigeNr id="979b9f7e-26c6-4da2-a730-8354ea652824">6</loigeNr>
					<kuvatavNr id="92b39e8e-091f-46ee-a652-adad3aca5749"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="84c48865-7ba8-4e57-8f57-069603c81613">
						<tavatekst id="7a8b7fac-4476-4792-9db0-fb0576112218">The regulation established on the basis of subsection 5 of this section may specify the permanent appropriate and proportionate technical, operational and organisational security measures and the requirements and conditions for implementation thereof, including by taking into account the fields of activity specified in subsections 2–5 of § 3 of this Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para7lg7">
					<loigeNr id="2aaa2830-aa30-425d-bff5-00beb930c614">7</loigeNr>
					<kuvatavNr id="7f4d3722-8ba4-479a-b837-b79aa2761b5b"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="c895d602-06b1-4e1b-8ce0-fce9b89c58f9">
						<tavatekst id="c09660e3-199d-4cb8-bece-83a5fbff05a0">A service provider specified in an implementing act referred to in Article 21(5) of Directive (EU) 2022/2555 of the European Parliament and of the Council, laying down the technical and the methodological requirements, as well as sectoral requirements, as necessary, for the implementation of security measures by the service provider, follows, for the service specified in that implementing act, the requirements established by the same implementing act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para8">
				<paragrahvNr id="bffe5356-064f-4d7e-9c4b-53c9d6f1f53b">8</paragrahvNr>
				<kuvatavNr id="06d5d983-9ff7-4f57-b7d6-633ab0bc1f1f"><![CDATA[§ 8. ]]></kuvatavNr>
				<paragrahvPealkiri id="fd2a8f09-fa17-4e7f-8048-f7daabfba6b2">Obligation of service provider to notify of cyber incident</paragrahvPealkiri>
				<loige id="para8lg1">
					<loigeNr id="ce57df3e-707f-404d-925c-d74b1e9d0f03"/>
					<kuvatavNr id="966475f2-ebea-4803-8927-5ae6bc3e99d0"/>
					<sisuTekst id="6875ae1f-ef9d-4642-9ecc-060827020d20">
						<tavatekst id="b76c9712-64f9-4c74-ab87-c7a5cfd6835f">[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg1">
					<loigeNr id="58ece099-a1e3-4696-9dce-285f14034ebe">1</loigeNr>
					<kuvatavNr id="54882128-afc7-4eb1-a0d9-a6200ed3c928"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="9c25d435-eb65-4771-aad9-40eb62a4635d">
						<tavatekst id="eb36b3cd-c2dc-46ab-8886-e576aeee3e57">A service provider, except for a security authority, submits to the Estonian Information System Authority an initial notification without delay, but no later than 24 hours after becoming aware of a cyber incident:<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
					<alampunkt id="para8lg1p1">
						<alampunktNr id="d5e6d12e-ad3a-45af-833a-9f94557fa896">1</alampunktNr>
						<kuvatavNr id="3a20b914-8229-45f5-bd55-e664c0b2eed3"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="a3249733-1a2c-4053-b44e-9da6d1d536bf">
							<tavatekst id="8660b1ec-7d16-428d-89ae-265dfdebabba">which has a significant impact on the security of the system or the continuity of the service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg1p2">
						<alampunktNr id="8da9146e-ba77-40d9-80d0-9cb1eaa39856">2</alampunktNr>
						<kuvatavNr id="256f32c2-b879-4d0c-bf77-58098e0976d6"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="2eea3fad-4f0e-47d3-8266-cbf880b8e551">
							<tavatekst id="1d7fd435-e57c-40e3-ab2c-b5404139293f">a significant impact of which on the security of the system or the continuity of the service is not obvious but can be reasonably presumed.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para8lg1b1">
					<loigeNr id="e65f38d1-f65e-42f6-8996-2c5d0fcc23c3" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="473f82ed-84a7-44a1-9602-1df409535966"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="85e0612d-48c6-4727-952d-8185449a2a02">
						<tavatekst id="5db23889-2bdc-4a89-85c5-7aa5fab02703">If a service provider authorises another person to manage the system or hosts the system with another person, the service provider is responsible for ensuring that the other person notifies the service provider no later than 24 hours after becoming aware of a cyber incident specified in subsection 1 of this section.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg2">
					<loigeNr>2</loigeNr>
					<kuvatavNr><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst>
						<tavatekst>A cyber incident has a significant impact if at least one of the following conditions is met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para8lg2p1">
						<alampunktNr id="588d983e-d513-4d35-ac18-76bcaa4cfbea">1</alampunktNr>
						<kuvatavNr id="0f171566-3ce8-4c97-91b9-56f1b7a790ad"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="5069dc90-2565-413a-ae60-34b9b5d11391">
							<tavatekst id="f85d9f4a-a373-4b98-8663-4aab84dfd58d">the impact of the cyber incident is at least severe according to the severity of consequences determined in the system risk assessment prepared on the basis of clause 1 of subsection 1 of § 7 of this Act;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p2">
						<alampunktNr id="6c86437d-c936-4883-a0e3-6deb2033d3b9">2</alampunktNr>
						<kuvatavNr id="ffccafa7-be95-4132-af2e-3686e78ba8fd"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="28e931b4-4476-472a-a7f9-4a456652ca08">
							<tavatekst id="2d0cfe91-f689-4b37-867c-ed269b501c74">due to the cyber incident the provision of the service cannot be continued after the passing of the maximum permitted time of disruption of the service provided by the relevant service level agreement or the requirements for the continuity of the service;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p3">
						<alampunktNr id="e5c63731-a3c8-4e83-8d2b-281e84d93c2e">3</alampunktNr>
						<kuvatavNr id="4e52504e-bb9b-45ee-913c-cd20d772cbb0"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="978297c9-be29-49c8-9ca2-153733d2d6ad">
							<tavatekst id="fa9bb98f-458c-4107-a2db-8125799e1096">the continuity of the service of the provider of another service is disrupted due to the cyber incident;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p4">
						<alampunktNr id="f77b29d3-ebcd-4e64-9e1a-3601e0a9051c">4</alampunktNr>
						<kuvatavNr id="ce09f759-36c5-4f11-b5fd-e350764de8d4"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="17d800ff-e56b-4373-ae52-40bef259bbcf">
							<tavatekst id="6788e4ec-7e37-4ea6-85d5-8c589b996d84">the extraordinary measures set out in the system risk assessment prepared under clause 1 of subsection 1 of § 7 of this Act or in another document, if any, describing the restoration of the continuity of the service or the security of the system need to be applied for responding to the cyber incident;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p5">
						<alampunktNr id="13147feb-5f77-404a-917e-549ee044fcab">5</alampunktNr>
						<kuvatavNr id="f85b709e-08dd-4b27-919e-f41e6c369518"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="13197fd3-6fb9-40b5-8e40-5a36ebd7edf5">
							<tavatekst id="be9e99d1-85fa-4a5e-b390-592236039184">the service provider, another service provider or the service users suffer or may suffer significant damage due to the cyber incident;<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8lg2p6">
						<alampunktNr id="57b15d3c-af80-4d56-9c6b-d29d1b93fa31">6</alampunktNr>
						<kuvatavNr id="94c93289-13eb-483f-923a-129bed236cd2"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="0d852f80-75d4-465e-883a-6747d12b62dd">
							<tavatekst id="19ac51fb-7d20-430f-9012-acfd0b02e998">it is a significant incident provided in a European Commission implementing act adopted under Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para8lg3">
					<loigeNr id="0284ae2b-8f77-4916-ab57-e1bfb6129682">3</loigeNr>
					<kuvatavNr id="bc3b830e-4efe-4b94-bcc9-81a7ec927f63"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="18647f3f-29f6-4331-9b5f-024bec07a5a5">
						<tavatekst id="7ef02d85-5cb5-4565-b8c8-8233f77fb236">If as a result of a cyber incident the provision of the service or another service is disrupted in at least one more European Union Member State, the cyber incident is always deemed to be of significant impact.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg4">
					<loigeNr id="11b14e7b-7ad1-4f4f-87a9-4f362f246328">4</loigeNr>
					<kuvatavNr id="919e306d-25e6-4ebc-8f86-50012f9ad781"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="f4dc5d1d-e90f-4ed8-84cf-40ac87021017">
						<tavatekst id="473a3657-68df-4aa7-9a53-e53ad3b35a69">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg4b1">
					<loigeNr id="0dec8775-b55b-4adb-aa5a-3d9965fccbe1" ylaIndeks="1">4</loigeNr>
					<kuvatavNr id="29c2d017-4ac3-4ecd-9e25-a970265a6c5a"><![CDATA[(4<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="e3c869d8-8a44-4224-8764-7b5426e17cc9">
						<tavatekst id="ee8af7dc-1b81-47ea-9b46-5f8c1da3354e">A service provider, except for a security authority, forwards to the Estonian Information System Authority without delay, but no later than 72 hours after becoming aware of a cyber incident with a significant impact, an incident notification updating the information submitted in the initial notification in order to obtain a specified overview of the circumstances of the cyber incident with a significant impact.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg4b2">
					<loigeNr id="41fd44d9-0d34-43fb-afe1-a3d822de419d" ylaIndeks="2">4</loigeNr>
					<kuvatavNr id="5392a10c-8a5f-4e45-87e2-091603c7e34d"><![CDATA[(4<sup>2</sup>)]]></kuvatavNr>
					<sisuTekst id="08c952bb-e6db-4c53-bbe4-c7da43df1ddd">
						<tavatekst id="4956d56d-3b73-4ed0-bea9-cde80ceee1d9">A trust service provider submits the incident notification specified in subsection 4<sup>1</sup> of this section without delay, but no later than 24 hours after becoming aware of a cyber incident with a significant impact.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg4b3">
					<loigeNr id="0ac2aae7-e9d1-4069-b274-b382dc1b50d5" ylaIndeks="3">4</loigeNr>
					<kuvatavNr id="b4e2aac8-ee84-4ea3-9349-0b086add4738"><![CDATA[(4<sup>3</sup>)]]></kuvatavNr>
					<sisuTekst id="74c8506a-09d2-43d4-9408-c5ff0af7de56">
						<tavatekst id="6f774f78-0e41-40e3-9958-b8b06af48041">At the request of the Estonian Information System Authority, a service provider submits, before submitting the final report specified in subsection 7 of this section, an interim report on the status of responding to the cyber incident with a significant impact. The interim report is to contain the data prescribed in the incident notification and, where relevant, additional information requested by the Estonian Information System Authority.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg5">
					<loigeNr id="2a68e995-fb22-4f25-bd03-e108068f205a">5</loigeNr>
					<kuvatavNr id="90dfbb80-ce37-473b-a096-7f41ef44ef62"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="90e1d9f8-9565-47e8-8cc4-4d46e358480f">
						<tavatekst id="492e1c91-28b3-41a8-ae05-2c96b8d960a7">Where relevant, a service provider is required to inform, within a reasonable time, a person who may be affected by a cyber incident with a significant impact or by a significant cyber threat, or the public if the affected persons cannot be informed individually. In the notification, the service provider, where possible, provides information about the significant cyber threat and the measures which the affected person may take in order to respond to the significant cyber threat.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg6">
					<loigeNr id="b251c075-9e81-4ba8-a516-5ccee2178d57">6</loigeNr>
					<kuvatavNr id="aaebe344-2b0b-4058-83b5-a25d670cc57d"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="77e11130-9615-4f71-ab4f-28b14246f7a1">
						<tavatekst id="3ca32086-20ab-49d3-8ea9-4f71e0a16ec0">Where public awareness or the disclosure of a cyber incident is necessary to prevent or deal with a cyber incident with a significant impact or otherwise in the public interest, the Estonian Information System Authority may, after consulting the relevant service provider, inform the public of the cyber incident with a significant impact or require the relevant service provider to do so.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg7">
					<loigeNr id="70db44d8-f373-45c3-b826-792b3fd37554">7</loigeNr>
					<kuvatavNr id="e34e8477-07fa-49d4-a2f3-51827b3eef57"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="9bcde06b-6daf-4334-aa79-86b728f8d589">
						<tavatekst id="5722df5f-ca6d-4d29-a394-0b4dc2dae74e">A service provider submits a final report to the Estonian Information System Authority within one month as of the submission of the incident notification specified in subsection 4<sup>1</sup> of this section. If the cyber incident with a significant impact has not yet been resolved by the time the final report is submitted, the submitted final report is treated as an interim report and the service provider submits a new final report within one month after the cyber incident with a significant impact has been resolved.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg8">
					<loigeNr id="1d3ae234-534a-40b2-b1b8-af9e10710871">8</loigeNr>
					<kuvatavNr id="da396eb9-dec4-4b69-b1c0-baf4355d1f02"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="78344c6f-413b-4c3c-8307-a894437f0b4f">
						<tavatekst id="0cc52acf-9928-4086-bead-4c86473ad84b">The data to be submitted when notifying of a cyber incident and the procedure for notification are established by a regulation of the minister in charge of the policy sector of national cybersecurity.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg8b1">
					<loigeNr id="3dcf6f73-0c92-4d07-b70c-5f8ba7111194" ylaIndeks="1">8</loigeNr>
					<kuvatavNr id="f5cc1490-82e9-46f6-b75b-375a536d3616"><![CDATA[(8<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="1d249d0d-9458-49f9-91bd-33727428badb">
						<tavatekst id="3ec06955-3735-4a8c-8894-7a8283df41d8">If the European Commission adopts an implementing act specified in Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, specifying the format of, and the procedure for submitting, a notification or report on a cyber incident, including a cyber incident with a significant impact, the requirements provided in that implementing act must be followed.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg9">
					<loigeNr id="d01211d3-2b4d-4829-817b-bdb3f485cb89">9</loigeNr>
					<kuvatavNr id="651255d3-fc84-4a4a-9257-f06e44ba92cb"><![CDATA[(9)]]></kuvatavNr>
					<sisuTekst id="e68ee8a3-401c-4e54-8191-b6f4c9d3cf7b">
						<tavatekst id="4ac3fd45-30b9-45d9-8eff-f9a47ee95eb0">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8lg10">
					<loigeNr id="f222c1ee-d39f-4e3b-9df8-d51d57b0b9c4">10</loigeNr>
					<kuvatavNr id="3ba712d0-72a9-4648-b257-96d23d81a611"><![CDATA[(10)]]></kuvatavNr>
					<sisuTekst id="0f3ad68a-7997-4122-a795-3051ebad0b65">
						<tavatekst id="9f8c41d4-af34-40f7-92b7-12369492e71a">A security authority notifies a cyber incident to the relevant security authority, taking into account the requirements provided in this section.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para8b1">
				<paragrahvNr id="5e7f60f2-cc19-4df3-afec-f493be65e93e" ylaIndeks="1">8</paragrahvNr>
				<kuvatavNr id="a238e5e4-c719-49d8-aa7a-4eee2a32a55a"><![CDATA[§ 8<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="96a37716-98d9-42fd-bcb4-cc306a6bfab4">Voluntary notification</paragrahvPealkiri>
				<loige id="para8b1lg1">
					<loigeNr id="c048206a-ce42-4715-80ee-b0c2163184f4">1</loigeNr>
					<kuvatavNr id="2874723e-1842-4679-88c2-e6a3377b1836"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="016a6b18-eee0-4082-b471-9ae37da295e8">
						<tavatekst id="70403022-39c1-49b2-9b00-181a3be83d4e">The Estonian Information System Authority may be:</tavatekst>
					</sisuTekst>
					<alampunkt id="para8b1lg1p1">
						<alampunktNr id="c896d546-88f8-420e-99c9-bc931f875aa2">1</alampunktNr>
						<kuvatavNr id="5e2df090-3ce7-4295-af80-435157db310d"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="723b479f-e7ff-4e80-82cf-10530cc37c80">
							<tavatekst id="d15660be-c7ec-403b-b822-98eb7ee70468">notified of a cyber incident, a vulnerability and a cyber threat by a service provider;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para8b1lg1p2">
						<alampunktNr id="640d4604-5ef4-4150-81fc-c6fd49f1a37e">2</alampunktNr>
						<kuvatavNr id="01754785-0f68-4bf5-968d-d1daf0b518a3"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="28d3a546-366c-4cfc-8bf3-d99e69de2d2d">
							<tavatekst id="bdcf73ee-be1d-4da2-a6c8-38067cb80dea">notified of a cyber incident with a significant impact, a vulnerability and a cyber threat by a person other than a service provider.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para8b1lg2">
					<loigeNr id="ebb10d0f-9e10-4b68-9f69-5ebaf24711f0">2</loigeNr>
					<kuvatavNr id="bd146c12-7655-4f31-9778-9a3640e974bc"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="31ac84dc-2274-4dc8-bd65-0f0bbaaf0437">
						<tavatekst id="58b34071-6470-4da2-89d8-79f6a3924024">A natural or legal person notifying of a potential vulnerability or a vulnerability may submit a notification anonymously. The personal data of the person submitting the notification is information intended for internal use for the purposes of the Public Information Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para8b1lg3">
					<loigeNr id="15c809df-f2c1-4347-86c5-e6129ff5d4b9">3</loigeNr>
					<kuvatavNr id="58838ff7-7faf-4a54-9027-4cf08032a899"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="8c4cca2c-d96b-4ed1-822b-a31e20f97709">
						<tavatekst id="4b01d338-7cd4-4ad7-8f4c-bb5daaaa5679">The Estonian Information System Authority processes notifications submitted on the basis of subsection 1 of this section in accordance with the rules provided in §§ 8 and 12 of this Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para9">
				<paragrahvNr id="1fa87172-c3b9-4fcf-b11a-f430a9c78357">9</paragrahvNr>
				<kuvatavNr id="dc56161d-116a-487e-810d-bfec83ecbd1a"><![CDATA[§ 9. ]]></kuvatavNr>
				<paragrahvPealkiri id="8c2d9f6b-4cd6-4c8b-a372-149d4902f084">Security measures of state and local authority’s system</paragrahvPealkiri>
				<loige id="para9lg1">
					<loigeNr id="3d145979-62b8-494e-b6f7-fcfb2332a70a"/>
					<kuvatavNr id="8d45a6c3-4d72-401e-9d04-b9a61f782016"/>
					<sisuTekst id="dc0338fb-ea0e-4189-9199-e2738513ea9b">
						<tavatekst id="27f913b4-2f72-4099-91eb-993f028be7e6">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para10">
				<paragrahvNr id="6c1f728c-5f22-407c-8d8e-302689a488d7">10</paragrahvNr>
				<kuvatavNr id="2d80bd27-a951-4594-b629-9ceca10b072e"><![CDATA[§ 10. ]]></kuvatavNr>
				<paragrahvPealkiri id="6babbc07-ccd8-46dd-84a8-2dcc9d6d4ad2">Security measures of digital service provider’s system</paragrahvPealkiri>
				<loige id="para10lg1">
					<loigeNr id="14130112-93bd-4159-867a-e2bb9c9a1c0a"/>
					<kuvatavNr id="b5af1eb9-3dac-4747-a547-a3b61a13ae9a"/>
					<sisuTekst id="be9f0a3f-0e7b-42e5-adfc-90f7fb1caf7b">
						<tavatekst id="51c6e37f-01a8-484d-9cc7-08c13f02d9cd">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para11">
				<paragrahvNr id="75f40b95-221f-4b78-8595-041a5b503985">11</paragrahvNr>
				<kuvatavNr id="a5c29fcd-8d3c-41d2-8092-d60db050df39"><![CDATA[§ 11. ]]></kuvatavNr>
				<paragrahvPealkiri id="ac44442e-1dbb-4ac3-9fab-76dad991741d">Obligation of digital service provider to notify of cyber incident</paragrahvPealkiri>
				<loige id="para11lg1">
					<loigeNr id="86990adb-023f-43d0-9dda-4e1335f6e871"/>
					<kuvatavNr id="48b31b38-62a3-40b1-9177-5c5dce108780"/>
					<sisuTekst id="14a2e338-a75b-4571-8dbd-72901cb43296">
						<tavatekst id="eb0c8474-2306-4703-8c24-b1c12d6ad38e">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="82fb2700-1c6f-41f2-877f-956662d5de8a">
			<peatykkNr id="36e2f5ea-ff79-4d1d-ab70-3253fbc68f6c">3</peatykkNr>
			<kuvatavNr id="61df2b41-0ef9-4185-965b-149ed461f582"><![CDATA[Chapter 3]]></kuvatavNr>
			<peatykkPealkiri id="689e65bd-a22e-4840-9c09-42016402741a">Ensuring Cybersecurity </peatykkPealkiri>
			<paragrahv id="para12">
				<paragrahvNr id="37437c4a-eed5-4b64-9f02-d14d825aa48c">12</paragrahvNr>
				<kuvatavNr id="be5b5646-e760-48d5-821e-36d5bd0ffc61"><![CDATA[§ 12. ]]></kuvatavNr>
				<paragrahvPealkiri id="479c0148-15d3-4810-bb98-9acb33edca10">Prevention of and response to cyber incident</paragrahvPealkiri>
				<loige id="para12lg1">
					<loigeNr id="4bd69989-005e-45c3-afab-50d88ce88e69">1</loigeNr>
					<kuvatavNr id="a2d286f9-a34c-47ec-9fed-592f114c5647"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="c4f23011-b128-4f21-ba88-8141e29e9d6d">
						<tavatekst id="475ebd36-d628-4895-b3d0-a8ceb57e9f9d">Ensuring cybersecurity and preventing and responding to a cyber incident to the extent provided by this Act is co-ordinated by the Estonian Information System Authority.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg2">
					<loigeNr id="14d86c61-d822-4300-9a4d-738aee228baa">2</loigeNr>
					<kuvatavNr id="dd86714d-0cf9-47f5-bf05-e60559d42c81"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="7c38d935-91cf-46f4-ba9b-73e110d797e7">
						<tavatekst id="60df299e-b1c2-4b5e-a5f0-b7943d3c2423">For the purpose of ensuring cybersecurity, the Estonian Information System Authority observes domains in the Estonian Internet protocol address space and related to the Estonian country code, analyses risks posed to the security of systems and the impact thereof on the state, society and the security of systems.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg3">
					<loigeNr id="10f6e30b-6cab-4182-a22b-727894887a59">3</loigeNr>
					<kuvatavNr id="f23befb3-4818-40fb-982e-93d659943c03"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="ba19fe8f-554c-4731-965b-584bdc221423">
						<tavatekst id="ae19092f-a954-4f63-b361-d4f112961666">For the purpose of preventing and responding to a cyber incident, the Estonian Information System Authority sends people alerts enabling them to take measures avoiding or reducing the impact of the cyber incident.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg3b1">
					<loigeNr id="152086c4-c299-49cd-8271-ee756cb02552" ylaIndeks="1">3</loigeNr>
					<kuvatavNr id="dd89e842-6a84-4fd3-ab9e-926f6b1b619d"><![CDATA[(3<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="3f5d349f-570a-45bc-9b08-193dd7a70a56">
						<tavatekst id="73e9de7d-6146-41ab-8052-f170eac37d74">The Estonian Information System Authority provides to the entity that has notified it of a cyber incident with a significant impact a response, where possible, within 24 hours, which contains preliminary feedback on the cyber incident with a significant impact and, upon request of the entity submitting the notification, also guidance on measures for responding to the cyber incident with a significant impact.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg3b2">
					<loigeNr id="1db75ef0-9dc6-47ca-830b-11cc9e4bb92f" ylaIndeks="2">3</loigeNr>
					<kuvatavNr id="211b0e98-6801-47ef-9c38-ae8f5142de6f"><![CDATA[(3<sup>2</sup>)]]></kuvatavNr>
					<sisuTekst id="217a9cd4-3850-45f1-88b9-f4c2a2a2bb0e">
						<tavatekst id="7bff7d12-b351-4235-9933-7716f36313df">In responding to a cyber incident, the Estonian Information System Authority may give priority to the processing of a notification submitted on the basis of § 8 of this Act over the processing of a notification submitted on the basis of § 8<sup>1</sup>.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg4">
					<loigeNr id="984f53cc-80ff-4dab-b68b-b5ed54592726">4</loigeNr>
					<kuvatavNr id="e341c6de-80e0-4a9b-a54d-9f5f83ba4ea9"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="4e860653-a121-4e0b-950b-57b09f79d1ed">
						<tavatekst id="ce34a3cc-a5b9-429f-abbe-0502c3b68134">The Estonian Information System Authority has the right to forward to a foreign state or to the European Union Agency for Cybersecurity or to another organisation information related to the prevention of and response to a cyber incident for the performance of the tasks provided in § 5 of this Act or of an obligation arising from European Union law, or in the cases and in accordance with the rules provided in an international agreement, provided the forwarded information does not prejudice national security or criminal proceedings. The forwarding of such information is mandatory in particular where a cyber incident with a significant impact concerns two or more Member States of the European Union, in which case the relevant information concerning the cyber incident with a significant impact must be forwarded to the affected foreign state and to the European Union Agency for Cybersecurity.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg4b1">
					<loigeNr id="e041ad3d-0c5c-4307-8d00-53d683bcbc33" ylaIndeks="1">4</loigeNr>
					<kuvatavNr id="690b1464-bbe6-456e-9f72-dcb2bc75261b"><![CDATA[(4<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="272d4967-ddfd-4b03-bed3-538a253a2365">
						<tavatekst id="73116143-2c31-4704-b619-c22fd45d6a2a">Every three months, the Estonian Information System Authority submits to the European Union Agency for Cybersecurity a consolidated report containing anonymous aggregate data on cyber threats, cyber incidents and cyber incidents with a significant impact.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12lg5">
					<loigeNr id="6c60dadd-284e-4425-ada4-7a13a02aeb2e">5</loigeNr>
					<kuvatavNr id="3fae6d2b-6f27-426c-b2f5-322015faa471"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="e2bdbe6f-9f8a-4b08-92ec-0e94dbf29178">
						<tavatekst id="5783f6c6-3007-489f-a1d6-37837f326130">The Estonian Information System Authority forwards the information specified in subsections 4 and 41 of this section only to the extent necessary and proportionate for the purpose of information sharing, protecting the security and commercial interests of the service provider and abiding by the obligation to maintain business secrecy.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para12b1">
				<paragrahvNr id="82813e14-9863-4626-bc7a-8463ff26ce0f" ylaIndeks="1">12</paragrahvNr>
				<kuvatavNr id="8adf7c71-8a40-42bf-a55b-83ae87cd34d4"><![CDATA[§ 12<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="28675bff-8b65-4e82-b75c-ecc2c8cf1132">Prevention of and response to large-scale cyber incident and crisis</paragrahvPealkiri>
				<loige id="para12b1lg1">
					<loigeNr id="c1b488cc-7d05-4daf-bd92-9810cbadf303">1</loigeNr>
					<kuvatavNr id="d6bfd0e6-1c35-43b2-bbc5-165274eb6546"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="1c885f82-c709-4302-95a3-729219725785">
						<tavatekst id="d924274d-d0bc-46bc-a74c-d030a5f6489b">The provisions of § 12 of this Act and of other sector-specific Acts governing the prevention of and response to crises apply to the prevention of and response to a large-scale cyber incident and crisis.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para12b1lg2">
					<loigeNr id="afe140dd-4bdf-435f-bedf-c429010fb984">2</loigeNr>
					<kuvatavNr id="e72d84fa-2435-443a-8825-fe82f9ada2da"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="f2e0dab1-c62b-4cd4-8b0a-ecec3e920ace">
						<tavatekst id="aa59228f-b530-49f6-b84d-50c228e11266">The Estonian Information System Authority:</tavatekst>
					</sisuTekst>
					<alampunkt id="para12b1lg2p1">
						<alampunktNr id="3eb10d2f-0ca9-454a-b92e-000467c29582">1</alampunktNr>
						<kuvatavNr id="9bc54b2f-cad1-471c-8987-d24192d6c98d"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="4386e930-815d-4158-9b33-93f02e2aee33">
							<tavatekst id="23eb151f-c239-452e-8f50-8374dae69a16">draws up and adopts a large-scale cyber incident and crisis response plan (hereinafter <i>plan</i>), taking into account the requirements provided in Article 9(4) of Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para12b1lg2p2">
						<alampunktNr id="059c5e2b-3018-45f1-ad35-18dfe46b2158">2</alampunktNr>
						<kuvatavNr id="ecc23840-a313-4ec3-9edf-9248299190ec"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="dbf36c25-bdc8-4fd6-98ee-8f92f2270bc8">
							<tavatekst id="6e027200-9ccc-4897-abe9-07e0665e8ba8">notifies the European Commission within three months of the adoption of the plan or of amendments to the adopted plan and submits to the European Commission and to the European cyber crisis liaison organisation network, within three months after the adoption of the plan, relevant information related to the plan.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para12b1lg3">
					<loigeNr id="b9376c9c-66c3-4995-9ea2-7efeb46f5620">3</loigeNr>
					<kuvatavNr id="fda4540d-3b9d-41d1-9bb4-378c5b21057e"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="17742998-902c-4c50-ad60-211a3b4acbc1">
						<tavatekst id="e6bf37c0-697f-4577-be2c-5716fa752928">The plan may be drawn up as part of a document drawn up under another legal instrument.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para13">
				<paragrahvNr id="4076d7ab-e940-4195-940c-acdff7be4ecf">13</paragrahvNr>
				<kuvatavNr id="a7642f2e-26d4-4256-8228-b28d3c49a984"><![CDATA[§ 13. ]]></kuvatavNr>
				<paragrahvPealkiri id="5e135730-5073-49ed-9c71-9a7210bd828f">Cyber incident registry</paragrahvPealkiri>
				<loige id="para13lg1">
					<loigeNr id="f43f5859-4539-4d12-9714-45cd177c8d61">1</loigeNr>
					<kuvatavNr id="682a7619-defc-48c0-b3c6-6d44b2d6e0e2"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="0a88f21e-9020-4f20-9e55-3e4e21848a74">
						<tavatekst id="1648d150-69eb-4617-af14-4d8f48036ace">The cyber incident registry (hereinafter <i>registry</i>) is a database maintained by the Estonian Information System Authority, where data describing the occurrence of a cyber incident, cyber threats and vulnerabilities is entered for the purpose of keeping record of cyber incidents, cyber threats and vulnerabilities and analysing the information submitted to the registry for the prevention of or response to cyber incidents, cyber threats and vulnerabilities, for forwarding alerts and for performing supervisory operations.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg1b1">
					<loigeNr id="57596789-2389-4440-8edb-071dd56f5da5" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="2f5b8d40-80bc-4da1-a6e9-136eff6a9aea"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="041a1b02-2d92-4c88-80e2-88d29bb64008">
						<tavatekst id="f91becc1-114c-4555-91de-8f197f2287ad">The name and contact details of the notifier of a cyber incident, cyber threat or vulnerability (hereinafter collectively <i>data provider</i>) are entered in the registry.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg2">
					<loigeNr id="7c2dc055-020a-424b-a7d3-667dcada1f2f">2</loigeNr>
					<kuvatavNr id="7e315f84-8a0b-496e-9818-a8bf79755aad"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="140d15a8-cffd-4bde-ab97-b6b46f8e5177">
						<tavatekst id="ac40a949-565a-4540-bff0-cca50fa2693b">Access to the registry is restricted and the registry data is intended for internal use, unless otherwise provided by legislation.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg3">
					<loigeNr id="2e0e96a7-9a32-49e6-8ba6-91366581cd36">3</loigeNr>
					<kuvatavNr id="19ef0115-bb2c-4b99-9cbc-fcd4e8d39860"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="8b661c26-d824-4a69-a69e-cd20f53b876d">
						<tavatekst id="65c36240-7902-4687-9e47-975e5f4360f9">The statutes of the registry are established by a regulation of the minister in charge of the policy sector.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para13lg4">
					<loigeNr id="f8e1aec0-ff8e-4f7c-a356-cddba1844170">4</loigeNr>
					<kuvatavNr id="64968ed4-a55a-452b-ae68-e88e826cc23a"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="2acb3dfa-1f7c-430b-9284-05baa9a42aba">
						<tavatekst id="b7145e55-3bc2-42e7-8ff7-1f080498ed79">The regulation specified in subsection 3 of this section provides for:</tavatekst>
					</sisuTekst>
					<alampunkt id="para13lg4p1">
						<alampunktNr id="2a67dc4d-4d38-491b-893a-14a7bc1d49ab">1</alampunktNr>
						<kuvatavNr id="dc65edce-5acb-41c9-ba19-7ea398926a12"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="40490c98-30f6-45dd-9ed1-fd928c421185">
							<tavatekst id="9ea557f8-7ff7-4b8f-ade2-21cff8c647c5">the detailed composition of the data;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p2">
						<alampunktNr id="d9f57251-047a-419f-ab4b-7dd23d2d2792">2</alampunktNr>
						<kuvatavNr id="7b9a61b0-d41e-4da7-ad76-90e0b9570fba"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="8861799a-ac4a-49a3-950d-1f98360a7032">
							<tavatekst id="9170a103-e3d5-4660-a74f-01b642c5d829">the data providers;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p3">
						<alampunktNr id="0bed11b7-e906-4807-aef6-f6418e2c9efd">3</alampunktNr>
						<kuvatavNr id="b31b962b-a2e8-4e9b-88b5-5915ab89ac55"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="4192bb74-c80f-4dca-9dd9-b0da8d6e3018">
							<tavatekst id="bee1cb40-007e-40cd-9ac9-6ad49b2c7f78">the procedure for ensuring the accuracy of the data;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p4">
						<alampunktNr id="dc62c816-2553-4c24-a4d4-6d8091a433cd">4</alampunktNr>
						<kuvatavNr id="913e51e5-079d-4d1d-8619-4e21ccb0cf73"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="1992bbc7-aa17-40eb-8f47-57c7e2e4c012">
							<tavatekst id="d0384053-c617-4743-bfd7-2d3395f5c5c4">the conditions for access to the data;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p5">
						<alampunktNr id="849dcf64-e737-41d6-ab49-475467ae5ca2">5</alampunktNr>
						<kuvatavNr id="b1f63504-0af7-49de-906a-8c7274241881"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="9cb04409-8771-43c2-8ee1-8514349c7355">
							<tavatekst id="eac22459-a656-4017-a4d5-adfd3225a9a7">the detailed conditions for registry operations and for the retention of data entered in the registry;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p6">
						<alampunktNr id="88219d4a-52f2-4c4f-92c2-ee1b74ea8a83">6</alampunktNr>
						<kuvatavNr id="fba008f4-04d4-49d3-ab9b-1d6af2da4ff1"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="06896cdf-2012-4279-bdfc-000d9fc7847e">
							<tavatekst id="2737bb81-a5cb-4729-9787-fdca6c814f65">the financing of the registry;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg4p7">
						<alampunktNr id="a14401f9-c843-4870-be49-d8d05c23fc0f">7</alampunktNr>
						<kuvatavNr id="84dff590-e670-42d9-9f49-0cc6b62d40d4"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="a370faa7-ca0c-4471-a48b-4a600d55559a">
							<tavatekst id="aa4ce698-d16b-46c9-97af-93603b3e1fcc">other organisational requirements related to the registry.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para13lg5">
					<loigeNr id="666d49e7-ddad-4b42-95d0-d9185817dc83">5</loigeNr>
					<kuvatavNr id="63acc5d4-6ebe-45fc-a770-17e0388fc352"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="1bb1b51f-47d5-4747-9426-38f829dd0726">
						<tavatekst id="38ce6bf4-38d3-488b-9188-338041f523e7">Data entered in the registry or related to the registry is retained as follows:</tavatekst>
					</sisuTekst>
					<alampunkt id="para13lg5p1">
						<alampunktNr id="e6876a15-501b-4f1c-8246-ad527d40d264">1</alampunktNr>
						<kuvatavNr id="d1a2aea7-b2ab-4379-b84e-02302a2b4a57"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="97eec53d-645e-4240-bef1-ab108512dd18">
							<tavatekst id="2942ef78-5361-4709-afbe-35aa387819c3">data on cyber incidents entered in the registry is retained for five years as of the response to the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg5p2">
						<alampunktNr id="a904a4d5-5cdd-4d0c-9697-784358e52cae">2</alampunktNr>
						<kuvatavNr id="92eed7e6-49e9-4cf3-9d94-fccf7cd3683b"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="edccfd15-5208-44d3-adb3-42f369f5223c">
							<tavatekst id="6116d1eb-cfb1-4eef-b822-5191586139a4">other data entered in the registry is retained for five years as of entry in the registry;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para13lg5p3">
						<alampunktNr id="7c716193-9a19-42af-a6e9-fc82c6afb625">3</alampunktNr>
						<kuvatavNr id="a061446d-df5d-4ca9-ab9b-1099ddfdbda0"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="5959e2d7-b02e-4db4-a3d8-50cdc5cbcc40">
							<tavatekst id="3da082d9-7ce0-4ab0-a28a-4c13567f2664">data on registry operations is retained for three years.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="1493ecff-8bd1-48ee-8902-fe89a5418be1">
			<peatykkNr id="094bff10-f9bc-41ef-955a-0a115fcd93e9" ylaIndeks="1">3</peatykkNr>
			<kuvatavNr id="614c7d11-e539-4e36-aab2-d9fdaf612f61"><![CDATA[Chapter 3<sup>1</sup>]]></kuvatavNr>
			<peatykkPealkiri id="c489261f-d961-47e5-99a4-d9ede57331f0">Cybersecurity Certification </peatykkPealkiri>
			<muutmismarge>
				<avaldamismarge>
					<RTosa>RT I</RTosa>
					<avaldamineKuupaev>2022-08-06</avaldamineKuupaev>
					<RTartikkel>2</RTartikkel>
					<aktViide>106082022002</aktViide>
				</avaldamismarge>
				<joustumine>2022-08-16</joustumine>
			</muutmismarge>
			<paragrahv id="para13b1">
				<paragrahvNr id="67da53e9-d144-4c57-b192-4de41acc1caf" ylaIndeks="1">13</paragrahvNr>
				<kuvatavNr id="5882b006-60d6-4897-8725-2ca312e61023"><![CDATA[§ 13<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="3bb754cf-7808-49b5-afa6-47123d4242a3">National cybersecurity certification authority</paragrahvPealkiri>
				<loige id="para13b1lg1">
					<loigeNr id="ed91661e-97c1-4e66-bdbb-a2fbe2fcd9e5"/>
					<kuvatavNr id="7852c3be-1ebd-4bf8-b66b-7c771538db63"/>
					<sisuTekst id="037f104b-ab81-4ec8-b7c5-85efa34e8ac0">
						<tavatekst id="24676ea1-5209-4fbc-81df-393d273db21d">The national cybersecurity certification authority for the purposes of Article 58(1) of Regulation (EU) 2019/881 of the European Parliament and of the Council is the Consumer Protection and Technical Regulatory Authority.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para13b2">
				<paragrahvNr id="cb774767-833d-4fb7-9913-7b643656a1a1" ylaIndeks="2">13</paragrahvNr>
				<kuvatavNr id="f8b4aefc-9537-4f43-b22f-54df95682999"><![CDATA[§ 13<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="137fb069-7a62-4e8b-941f-638906f9de52">Cybersecurity conformity assessment body</paragrahvPealkiri>
				<loige id="para13b2lg1">
					<loigeNr id="b1549eec-598d-4a71-8a23-786bd2b95806"/>
					<kuvatavNr id="d90e7588-eead-458b-b3c8-bc1d0955b061"/>
					<sisuTekst id="1c0c5f1f-7d79-40f1-ab55-2742c5c84ed7">
						<tavatekst id="799ace13-ca75-4303-8cd2-68d7c6f23341">Operating as a conformity assessment body and issuing an activity licence to a conformity assessment body are subject to §§ 22–31 and 33 and subsection 1 of § 35 of the Product Conformity Act, taking into account the specifications set out in Articles 60 and 61 and in an implementing act of the European Commission adopted under Article 61 of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="b692f157-c2af-484b-8c3e-8f6dd659cf09">
			<peatykkNr id="7e9c15f1-1aa0-42a5-8331-40efee98e68f">4</peatykkNr>
			<kuvatavNr id="a367f90c-5dcd-4e52-9863-c320a14a7160"><![CDATA[Chapter 4]]></kuvatavNr>
			<peatykkPealkiri id="633a3e3c-95d8-4759-8da3-1d3c952a10fe">State and Administrative Supervision </peatykkPealkiri>
			<paragrahv id="para14">
				<paragrahvNr id="c822e0ff-73ef-493b-bccc-3dc5c972e09f">14</paragrahvNr>
				<kuvatavNr id="ad7a41ff-1496-4d20-8d4a-d7851d1c6dd2"><![CDATA[§ 14. ]]></kuvatavNr>
				<paragrahvPealkiri id="71c38679-cce2-4e9e-af3d-f53061d80b2e">Exercise of state and administrative supervision</paragrahvPealkiri>
				<loige id="para14lg1">
					<loigeNr id="1b912d04-b299-4598-a0dc-01890bfbc93e">1</loigeNr>
					<kuvatavNr id="77a60e51-31bf-4abd-ad58-32683ab37374"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="8f589431-120c-44cd-9513-277349d6bf67">
						<tavatekst id="e178dd99-1925-4d5e-8eb3-7c326f940dcb">State and administrative supervision over compliance with the requirements provided in this Act and in legislation established on the basis of this Act is exercised by the Estonian Information System Authority.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg2">
					<loigeNr id="b63eca91-ffc9-4f6f-a7f6-ae31d8ea5771">2</loigeNr>
					<kuvatavNr id="8d60999e-2d0a-49fd-93cd-0567e6c1238f"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="32f6e5e1-b2e1-49ad-b731-cac352287675">
						<tavatekst id="85c322e0-fbc5-47aa-a19c-77b2c9c8aad9">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg3">
					<loigeNr id="8cbfb096-8f76-4cac-9482-e6d1c9527d6f">3</loigeNr>
					<kuvatavNr id="dff0d22d-f6c1-4a75-9c63-95f00c17affd"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="12a67611-bc3f-410b-9834-6d25d33f4fb4">
						<tavatekst id="b4472965-27fb-4f3f-a54e-ad6dcff96d66">[Repealed – RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg4">
					<loigeNr id="8714b55a-bf7f-4aaa-a628-681ccf5289f6">4</loigeNr>
					<kuvatavNr id="c986c6e1-3693-41ea-b0d8-10d7c45124cd"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="1985cc86-3c7a-43ed-a1ce-504930c39363">
						<tavatekst id="ebe24519-694d-478b-9c78-7763cca150ec">The Consumer Protection and Technical Regulatory Authority exercises state and administrative supervision to the extent provided in Article 58(7) of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg5">
					<loigeNr id="0c83735c-79be-4b45-a294-85413655d3e2">5</loigeNr>
					<kuvatavNr id="afc28ef1-6d75-488b-92f4-d4246de2da6d"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="04afc57c-e83c-4609-8376-bb6e5a49ecf6">
						<tavatekst id="9c32c2c3-ba21-495f-9553-fdc3dfef708b">Administrative supervision over compliance with requirements for systems of a security authority as provided by this Act and legislation established on the basis of this Act is exercised by the relevant security authority. The provisions of subsections 1<sup>1</sup>–3 of § 17 of this Act apply to the security authority exercising administrative supervision.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para14lg6">
					<loigeNr id="56a04798-1598-47e2-980b-609b30f39c03">6</loigeNr>
					<kuvatavNr id="902b1c95-b422-4473-a9de-e4a975520a7e"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="9134dbdf-6d5c-42ed-ba26-7a90574ff263">
						<tavatekst id="022cfa66-7a83-4a5a-a225-6c454c913d40">The Estonian Information System Authority:</tavatekst>
					</sisuTekst>
					<alampunkt id="para14lg6p1">
						<alampunktNr id="c6c412d6-132e-4034-b9ae-967760b5bc01">1</alampunktNr>
						<kuvatavNr id="48ff5bfd-7700-414c-bda2-35611b36f28f"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="f2d4c783-bef2-42b2-a85b-6e06890756bf">
							<tavatekst id="c76b8c80-9fb4-46eb-8682-54683184c5f8">may, in exercising supervision, prioritise the performance of the tasks provided in this Act, taking into account a risk- or threat-prognosis-based approach;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg6p2">
						<alampunktNr id="37ace494-e52a-4857-af61-b7c12cf2c61b">2</alampunktNr>
						<kuvatavNr id="27e741e6-d6b7-450a-9e5d-f439ba8eddee"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="61927583-9ddc-4bd0-b0c2-7f8a008981ca">
							<tavatekst id="c74b5a60-f211-4a42-9ae1-4331e264401d">exercises state and administrative supervision in respect of an essential entity;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg6p3">
						<alampunktNr id="0f8ce578-14fe-4a55-9329-5e8d5c3339d9">3</alampunktNr>
						<kuvatavNr id="ac1d1672-3a51-4631-bfd1-9005fa436453"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="aafe95de-5d66-4840-85bb-387ed9fd578c">
							<tavatekst id="d53fc291-5a94-4795-bbb2-3b3ddb5d7c3d">exercises state and administrative supervision in respect of an important entity by way of ex post inspection where the supervisory authority has reason to believe that the important entity does not comply with the requirements provided in this Act and, in particular, in §§ 7 and 8 of this Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para14lg7">
					<loigeNr id="7b5a6bc5-7233-44d6-b4cf-7424841cac5d">7</loigeNr>
					<kuvatavNr id="8d9f2d47-09a9-40ef-bec8-1729624ff0c3"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="cf082ed0-f7a4-47a7-8975-fd2c08efd155">
						<tavatekst id="703ba2fb-f0c6-4e40-a51a-ae0e9b6d1c8e">In applying a state or administrative supervision measure, the circumstances of each individual case are taken into account, in particular:</tavatekst>
					</sisuTekst>
					<alampunkt id="para14lg7p1">
						<alampunktNr id="a75c7acb-7743-4705-9419-c1505524e420">1</alampunktNr>
						<kuvatavNr id="6b224096-5d3d-478e-b570-092e4572fbc5"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="a04fd0a0-6046-4a58-ac7f-872f7f0fa9af">
							<tavatekst id="df179670-e698-423e-a202-a717f49fb8fc">the seriousness of the infringement and the importance of the requirements breached;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p2">
						<alampunktNr id="8a264c52-eaab-420f-823e-88572c62f6ef">2</alampunktNr>
						<kuvatavNr id="e954c378-3726-4476-98f6-b8bf3a04837b"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="6158cad2-73d3-4510-ae32-0ca3748e50cb">
							<tavatekst id="da2ec82c-01e6-44a7-a3db-0cd8ceab376d">the duration of the infringement;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p3">
						<alampunktNr id="70e7b5f3-5b4e-4257-97fe-0410169bea66">3</alampunktNr>
						<kuvatavNr id="7a49bc49-09e5-4886-992c-e69376e17fbf"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="34237614-40af-4da6-9f22-915b841a8753">
							<tavatekst id="9a6b2f21-648a-4429-84e1-dc80fe075824">previous relevant infringements by the service provider concerned;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p4">
						<alampunktNr id="9a6806f7-5e9e-4eb7-96a6-7f5b92b31a95">4</alampunktNr>
						<kuvatavNr id="61061d6b-e180-4d07-b0b0-7f6dd1a18212"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="47a77ae9-6306-4919-bb67-32f298b01256">
							<tavatekst id="43d8be59-d483-4017-8d04-e0e65f5dc249">the material or non-material damage caused, including the effects of financial or economic loss on other services;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p5">
						<alampunktNr id="a336ad12-6ecc-4073-9414-a8a8925a6be2">5</alampunktNr>
						<kuvatavNr id="42971c22-db12-4e39-996e-380a330e6fd7"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="231b923d-57bb-44b0-80fe-76aac8f25fe6">
							<tavatekst id="80e3b251-9d47-40ef-b598-74f8c4490cba">the number of persons affected by the infringement;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p6">
						<alampunktNr id="6c0b19e7-cda4-4186-b709-abe624b0fac1">6</alampunktNr>
						<kuvatavNr id="2286d454-6b62-488a-ae49-b33efcbf4ce8"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="defd7b35-8aec-4352-8429-2692ae60a44b">
							<tavatekst id="81100dab-0faf-4b75-a033-b6936a57b917">the intent or negligence on the part of the perpetrator of the infringement;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p7">
						<alampunktNr id="ca253cc9-302d-4bde-9f98-4bcb74600cae">7</alampunktNr>
						<kuvatavNr id="80b5537a-f15c-4afd-8976-1f81af1cab36"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="b207e0cf-14aa-435c-9287-de1ad811c6f2">
							<tavatekst id="470fc93f-1729-49fe-ac1b-2d08c966b4d9">the security measures taken by the service provider to prevent or mitigate material or non‑material damage;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p8">
						<alampunktNr id="bcd2cbb4-a4e2-4ac2-b0fe-7240e91e9f40">8</alampunktNr>
						<kuvatavNr id="6c01dbe9-54f7-41b9-af17-12e58316aa3b"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="624bbdab-834e-439a-9d1e-783447c79420">
							<tavatekst id="50813cc0-e280-4a68-88d7-b91e097bba9e">the status of adherence to approved codes of conduct or of implementation of approved certification mechanisms;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg7p9">
						<alampunktNr id="be6ab70d-a8c4-48af-bb68-56ea870fafd9">9</alampunktNr>
						<kuvatavNr id="53898334-bf62-4266-b628-cf06578fdab9"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="6adaac28-976c-498c-bce3-aa19a6bf8843">
							<tavatekst id="625b5d09-35e5-4b48-a74e-01aa2d5ce46b">co-operation between the supervisory authority specified in subsections 1 and 5 of this section and the service provider.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para14lg8">
					<loigeNr id="173f0c24-1b69-4025-9b81-d519293dcadd">8</loigeNr>
					<kuvatavNr id="eee2b37c-401e-4d17-96fb-5d6cbdc41a1b"><![CDATA[(8)]]></kuvatavNr>
					<sisuTekst id="c9aa3ef6-9a50-4fca-8ee8-2030f023a276">
						<tavatekst id="69e8d511-aca0-4c94-b8af-d10620cd6496">For the purposes of clause 1 of subsection 7 of this section, the following infringements are deemed serious infringements:</tavatekst>
					</sisuTekst>
					<alampunkt id="para14lg8p1">
						<alampunktNr id="0fb83080-11e6-4f81-a4b0-cc56175bb472">1</alampunktNr>
						<kuvatavNr id="425907ec-9159-48ee-be6a-719d5ad80a6d"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="6cc765b3-1fa2-4e9b-90c6-bd319d80f30d">
							<tavatekst id="2f384021-5699-4e92-a9df-08365758f638">repeated violations;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg8p2">
						<alampunktNr id="b58374fb-e061-4967-a12a-c883593a92a3">2</alampunktNr>
						<kuvatavNr id="89972513-6c51-428f-a437-3d2fc7d1cb02"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="1f00e45a-c4dd-4943-896a-40a79a5623e6">
							<tavatekst id="5657231f-875a-4fd1-ae07-c7aa76f983ad">a failure by a service provider to fulfil the obligation provided in subsection 1 of § 8 of this Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg8p3">
						<alampunktNr id="45fa0358-3575-4390-988c-ef4e3444b1ca">3</alampunktNr>
						<kuvatavNr id="116db967-5c67-4291-87f9-e74bba8b872f"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="ec0f7b98-653f-479e-b800-11ca0ef1dd60">
							<tavatekst id="ce505bbc-bb82-43e4-afff-24d3edbf8aae">in the event of a cyber incident with a significant impact, failure by the service provider to apply security measures to respond to the incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg8p4">
						<alampunktNr id="3a16cb33-5511-4c3a-9157-36640eb8c2f2">4</alampunktNr>
						<kuvatavNr id="f5b1093b-f47f-47d2-aa1f-8e6c5e76282c"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="569abc47-909c-499b-96e0-c06d82e5a933">
							<tavatekst id="cdbdb360-bc88-431f-9bda-af7451c9e850">a failure to remedy the deficiencies indicated in a compliance notice of the supervisory authority specified in subsections 1 and 5 of this section;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg8p5">
						<alampunktNr id="438de73d-58c3-43f3-9e0f-d6f61e3f76c5">5</alampunktNr>
						<kuvatavNr id="f30f28d9-5ad9-4bb6-839a-3031e8b513a1"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="9918b330-2626-4353-9773-38534603588b">
							<tavatekst id="72e5b550-84f1-4c75-88be-cf5c4b40ba10">the obstruction of audits or state supervision or administrative supervision ordered by the competent authority specified in subsections 1 and 5 of this section following the finding of an infringement;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para14lg8p6">
						<alampunktNr id="b454b636-5d00-477c-b384-e35c3e00b811">6</alampunktNr>
						<kuvatavNr id="ed6fd036-5ad3-49fb-96c7-6dc9d0314d9b"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="1087d133-a7f9-4554-a3fb-75b23f556c4e">
							<tavatekst id="aae7d1d1-4e48-46f0-9624-2f318a939c6c">providing false or grossly inaccurate information in relation to the implementation of the security measures provided in § 7 of this Act and the notification of a cyber incident with a significant impact provided in § 8 of this Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
			</paragrahv>
			<paragrahv id="para15">
				<paragrahvNr id="a6941943-02df-4cf7-8b02-d72eaf2f753b">15</paragrahvNr>
				<kuvatavNr id="1a9d62e5-497b-4c40-8581-222abc6384ec"><![CDATA[§ 15. ]]></kuvatavNr>
				<paragrahvPealkiri id="4ca24d78-af03-4df5-a42b-41d62951290c">Special state supervision measures</paragrahvPealkiri>
				<loige id="para15lg1">
					<loigeNr id="36720d2d-65c4-449b-a921-27124512d79c">1</loigeNr>
					<kuvatavNr id="de3db819-fada-4ae1-abc2-23fdece918ac"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="9a150b38-c481-4d8c-a551-f76ad3aa974c">
						<tavatekst id="8f59198c-2aef-44a4-906b-e3a156fac21d">In order to exercise the state supervision provided by this Act, law enforcement agencies may apply the special state supervision measures provided in §§ 30, 31, 32, 49, 50 and 51 of the Law Enforcement Act on the grounds and in accordance with the rules provided in the Law Enforcement Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para15lg2">
					<loigeNr id="830ffc32-62f1-44a5-8441-441d87932c62">2</loigeNr>
					<kuvatavNr id="e910763b-a804-448d-9f8a-620b68b6c5c3"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="34f55b52-4114-4fbd-aad8-b4096239f225">
						<tavatekst id="d66d557d-26cf-462c-92b3-af04ccdad688">In exercising state supervision over compliance with the requirements provided in §§ 7 and 8 of this Act and legislation established on the basis thereof, or in an implementing act adopted on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, a law enforcement agency may, in addition to the special measures specified in subsection 1 of this section, also apply the special state supervision measure provided in § 52 of the Law Enforcement Act on the grounds and in accordance with the rules provided in the Law Enforcement Act.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para16">
				<paragrahvNr id="564bf6e1-a827-46e5-9d38-ee38bd9d5cb4">16</paragrahvNr>
				<kuvatavNr id="e56eb070-4b4a-49ec-9d39-4bfe84f41105"><![CDATA[§ 16. ]]></kuvatavNr>
				<paragrahvPealkiri id="13c738eb-230a-4473-9cc6-cf4de04ccd2c">Specifications of state supervision</paragrahvPealkiri>
				<loige id="para16lg1">
					<loigeNr id="bfb4173f-944c-4cd7-b531-c35deee6449b">1</loigeNr>
					<kuvatavNr id="dcf727e5-b74f-41b0-94d7-38f3e8877e51"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="00cb0a05-5f2c-4ba0-80b0-2e4704c0dfd2">
						<tavatekst id="4d137632-feb7-4055-abd1-cdf1fdcd8c27">For countering an immediate serious threat or eliminating a disturbance in case of a cyber incident the Estonian Information System Authority may restrict the use of or access to a system provided all the following conditions are met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para16lg1p1">
						<alampunktNr id="f798bb23-8962-4f79-a922-88324d071603">1</alampunktNr>
						<kuvatavNr id="759063a1-b4d6-4fcb-93bd-8c41c0d6d740"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="1b03ae70-ae5a-45fa-a88c-2b0a8dbd1e3a">
							<tavatekst id="50929a0d-9726-4c91-bfdc-7a72b6cfcd2b">the cyber incident compromises or harms the security of another system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p2">
						<alampunktNr id="0f8596ba-66dc-4a71-92b4-1415ea3b6c6d">2</alampunktNr>
						<kuvatavNr id="e1dc0c5c-d8d1-4aa1-8bd4-325a9822d4a4"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="8832e940-faa4-474f-86e6-095bd83aecb6">
							<tavatekst id="0519ae74-cb1f-4dc8-ad6c-94fb6befc911">the system administrator is unable or is unable in a timely manner to counter the serious threat or eliminate the disturbance originating from the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p3">
						<alampunktNr id="f75fb6bc-872d-41ce-bfc4-f9f5bbb1255b">3</alampunktNr>
						<kuvatavNr id="e5a2d633-bcef-42ff-8971-a4f683f106f1"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="ae2a4045-f158-431e-a1b8-a56796876e0f">
							<tavatekst id="37702163-fef6-4c65-9f74-118fcdc62b90">it is not possible to counter the serious threat or eliminate the disturbance originating from the cyber incident by using a less infringing measure;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1p4">
						<alampunktNr id="4e941cc6-2e3e-4eb0-8fa9-0b4a0e0c8941">4</alampunktNr>
						<kuvatavNr id="c2c6488f-7e6c-482b-8747-7ef689cfc5e4"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="df0bd563-a580-4ef2-b4fb-8ba0f732ed13">
							<tavatekst id="efc4efdc-7ef5-40f2-9521-397e6b683b30">a person is not caused disproportional damage by countering the serious threat or eliminating the disturbance originating from the cyber incident.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para16lg1b1">
					<loigeNr id="0642365e-2f7d-4819-8047-bcfff088e958" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="1fdc68af-579f-4f31-98d3-cd0f8ba168f9"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="ec6972cd-3581-490e-91c9-4d30a1589d24">
						<tavatekst id="5fce92de-9b23-451b-93aa-198ecaf21871">In performing the tasks of state supervision, the Estonian Information System Authority has the right to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para16lg1b1p1">
						<alampunktNr id="fcca146b-d379-4ad2-a706-681267fd4fed">1</alampunktNr>
						<kuvatavNr id="f0dc77f0-c711-451e-8c94-db0d390f94ef"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="78dcea45-1995-4ad1-8871-bf5a0ba7f7ca">
							<tavatekst id="8d5f80eb-02c2-44aa-9214-79cdfec27ac4">carry out on-site inspections and off-site supervision in respect of a service provider, proceeding from clauses 2 and 3 of subsection 6 of § 14 of this Act, including to carry out random supervision in respect of an essential entity, which may, among other things, be prompted by a cyber incident with a significant impact or by a breach of a requirement provided in this Act or in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p2">
						<alampunktNr id="84b78b68-86a7-4a38-95e7-5e7be8754d41">2</alampunktNr>
						<kuvatavNr id="3ce38830-dcc9-485b-bb06-164d0502d3fb"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="a729c903-1a63-4f1c-8988-f67d5b32aaef">
							<tavatekst id="faab81a8-f6f7-449e-946c-2924ceccdcb8">carry out targeted security audits in respect of a service provider, based on a risk assessment performed by the Estonian Information System Authority or by the audited service provider, or on other available risk information, the costs of which are covered by the service provider, except in the cases specified in the regulation established on the basis of subsection 1<sup>2</sup> of this section;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p3">
						<alampunktNr id="1da76ea1-1c6f-42f3-b8bf-87a848f86eb2">3</alampunktNr>
						<kuvatavNr id="c1ac9459-0164-4471-bbfb-494106336e1d"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="a730e874-ce22-4e5b-8aef-2f6a42855abe">
							<tavatekst id="5775ad20-7976-4e31-9e73-381a5c42c4e1">carry out security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the co-operation of the service provider concerned;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p4">
						<alampunktNr id="ffe241c7-5aa7-4b27-a5ab-880bbb473155">4</alampunktNr>
						<kuvatavNr id="a81edb99-f45d-4a5a-849c-c1478b24af85"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="2b8de4c7-47c3-4e44-acdc-760699afaaea">
							<tavatekst id="dc6c74dd-62d0-4034-a9fa-2c517ea8bcda">issue a warning to a service provider where the service provider breaches this Act, or a requirement provided in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p5">
						<alampunktNr id="b37c90aa-7885-4cba-8b89-ca5a67a79eb7">5</alampunktNr>
						<kuvatavNr id="7edec32c-cc7e-435d-83e4-28336d4ee28e"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="7824fcb8-729e-4844-97cd-289073f7f172">
							<tavatekst id="70ada9bf-08cf-480d-aab5-54a257fd4730">issue a compliance notice requiring the addressee of the compliance notice to cease an activity or practice which breaches a requirement provided in this Act, or in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, and to refrain from using the same activity or practice;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p6">
						<alampunktNr id="2fb766c8-fbb3-4be7-a76d-544cf9a1dc21">6</alampunktNr>
						<kuvatavNr id="74a9e41c-06f1-4f89-98ef-b82a540ffdf8"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="f782bbc6-02ec-4dc1-806b-f527a2e2505f">
							<tavatekst id="fdcf18c1-0ca3-469a-83fd-baf07983a26a">issue a compliance notice requiring the addressee of the compliance notice to comply with the requirements provided in § 7 of this Act and in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) of Directive (EU) 2022/2555 of the European Parliament and of the Council, and to submit a notification provided in § 8 of this Act in the manner referred to in that section and within the time limit specified;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p7">
						<alampunktNr id="06a2e000-cef7-4cd0-b0f7-b3749aa77acb">7</alampunktNr>
						<kuvatavNr id="8c45b336-b4f3-47ff-b36e-fc1965489025"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="15733926-aaa9-4b4b-9594-cadc8955ad33">
							<tavatekst id="bdcc9c6b-c028-46f9-9cbc-9c7eb9e62b89">issue a compliance notice requiring the addressee of the compliance notice to notify an entity where the service or activity provided to that entity by the addressee of the compliance notice may be affected by a significant cyber threat, by providing in the notification information on the significant cyber threat and, where possible, explanations as to which measures the affected entity may take to respond to the cyber threat;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p8">
						<alampunktNr id="e1a08e94-458c-45bd-b737-39484057c8bc">8</alampunktNr>
						<kuvatavNr id="7edb6d73-8ac2-4b5b-baef-30a1d373be4d"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="06a3a843-a055-4968-aafe-3caa9c53d2d8">
							<tavatekst id="6f50944d-cc42-4985-a633-a5b11baa5404">issue a compliance notice requiring the addressee of the compliance notice to implement recommendations made on the basis of a security audit within a reasonable time;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p9">
						<alampunktNr id="4bbcc321-ad62-4654-918d-fb25dcc7cf30">9</alampunktNr>
						<kuvatavNr id="4909d19f-2855-4db4-ac66-d9c337f9d6cb"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="5dec74f0-8f5c-4014-bf69-31ba38e82ba1">
							<tavatekst id="71b44c8b-3391-4440-8b71-c5f05ec8423f">issue a compliance notice requiring the addressee of the compliance notice to disclose the circumstances of a breach of a requirement provided in this Act or in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, in the manner prescribed in the compliance notice;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b1p10">
						<alampunktNr id="08a11163-0dd2-4a62-a64b-2422d47943f2">10</alampunktNr>
						<kuvatavNr id="0adcf641-f7e2-4cfb-9422-dcdbe7355af2"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="0b4539e1-dfcd-4af2-ba11-2eeef5ccc421">
							<tavatekst id="d54acf85-294b-4911-8b54-2a79b91cb632">issue to an essential entity a compliance notice requiring the addressee of the compliance notice to designate, for a specified period, a compliance officer who monitors whether the addressee of the compliance notice complies with the requirements provided in §§ 7 and 8 of this Act and the requirements provided in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para16lg1b2">
					<loigeNr id="194450a4-5b6f-4600-ad58-042fb10bd9a8" ylaIndeks="2">1</loigeNr>
					<kuvatavNr id="b4aa128b-3d3c-4a64-a66f-fcdf6715618b"><![CDATA[(1<sup>2</sup>)]]></kuvatavNr>
					<sisuTekst id="64dfc6db-edbb-4dbf-b121-39bbc83075a3">
						<tavatekst id="55af382a-985b-4763-8b5d-95b921870e58">The detailed conditions and procedure for organising the targeted security audit specified in clause 2 of subsection 1<sup>1</sup> of this section, including a list of situations in which the Estonian Information System Authority reimburses the service provider the costs of the security audit, and the procedure for reimbursing the costs of the security audit are established by a regulation of the minister in charge of the policy sector of national cybersecurity.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg1b3">
					<loigeNr id="539376ad-74d8-4645-a69a-95415df4b062" ylaIndeks="3">1</loigeNr>
					<kuvatavNr id="0f46a254-7679-4af1-8c4c-7ca49490e48b"><![CDATA[(1<sup>3</sup>)]]></kuvatavNr>
					<sisuTekst id="abd213a8-2a34-4075-a524-6bcd95a8b72f">
						<tavatekst id="4ef0105c-5c09-40ee-8cbe-244ff6218c9a">The compliance notice issued to an essential entity specified in clause 5 of subsection 1<sup>1</sup> of this section may also include security measures intended to prevent or remedy a cyber incident and requirements regarding the deadline for implementing the security measures and notifying of implementation.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg1b4">
					<loigeNr id="aefabfb2-1a86-41c6-8292-2294f638f439" ylaIndeks="4">1</loigeNr>
					<kuvatavNr id="c3301645-d767-4ddb-b489-dccd9a69059e"><![CDATA[(1<sup>4</sup>)]]></kuvatavNr>
					<sisuTekst id="f81b8403-dee0-42fd-ad37-41b5e7ed23d5">
						<tavatekst id="7c79d15d-cdf1-4f16-98f6-b518cec161d2">If the supervisory measures specified in clauses 4–6 and 8 of subsection 1<sup>1</sup> of this section in respect of an essential entity are ineffective, the Estonian Information System Authority sets the essential entity a new deadline for remedying deficiencies or for complying with the requirements set by the Estonian Information System Authority.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg1b5">
					<loigeNr id="17ba491f-6c0a-4503-b999-b7eb16395b65" ylaIndeks="5">1</loigeNr>
					<kuvatavNr id="d55eda5e-4848-4d0f-bffc-a66f58d3ef56"><![CDATA[(1<sup>5</sup>)]]></kuvatavNr>
					<sisuTekst id="daf66479-cdb6-4944-ab73-e05ed074e9ee">
						<tavatekst id="db41acc4-3205-4bc9-8440-aef669e93cfd">If an essential entity does not remedy deficiencies or comply with the requirements of the Estonian Information System Authority by the deadline set on the basis of subsection 1<sup>4</sup> of this section, the Estonian Information System Authority has the right to require by a compliance notice:</tavatekst>
					</sisuTekst>
					<alampunkt id="para16lg1b5p1">
						<alampunktNr id="b99c9227-a4d3-48e8-b3b4-9ec0c7523874">1</alampunktNr>
						<kuvatavNr id="f879150e-d06c-4ce5-9059-8686644f17b8"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="6141011f-2c8d-465b-9f45-1b073864858c">
							<tavatekst id="4ecbaded-8031-4c28-a36d-e207a7895a11">the authorisation body to temporarily suspend a certification or authorisation concerning part or all of the relevant services or activities provided by the essential entity, or, where it has the relevant competence, to perform said actions itself;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para16lg1b5p2">
						<alampunktNr id="7eccef25-c09e-4dba-9d3a-b491510a2e72">2</alampunktNr>
						<kuvatavNr id="c2969384-a74c-4c85-92af-b31e67b62299"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="48cd96e6-a738-4b10-baa0-029f64210aec">
							<tavatekst id="42f9a83b-880c-4275-addd-46678bdfaa9f">the essential entity to temporarily suspend the powers of a member of the management board.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para16lg1b6">
					<loigeNr id="50da4b95-9bfe-4c30-8840-16b9b842816a" ylaIndeks="6">1</loigeNr>
					<kuvatavNr id="a9a3dc25-8a21-4dc0-974a-a843b46c1ffc"><![CDATA[(1<sup>6</sup>)]]></kuvatavNr>
					<sisuTekst id="cd63dab7-8548-49ce-b1b0-1a68b8e8db92">
						<tavatekst id="5340f083-f3ab-4e49-a0e3-6f468862089b">The measures provided in clauses 1 and 2 of subsection 1<sup>5</sup> of this section are applied until the essential entity concerned takes the necessary measures to remedy deficiencies or to comply with the requirements of the Estonian Information System Authority.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg1b7">
					<loigeNr id="3c3b4701-31d7-421d-873c-b8a87d631c64" ylaIndeks="7">1</loigeNr>
					<kuvatavNr id="5422a85c-9029-477f-a294-23c1727241ea"><![CDATA[(1<sup>7</sup>)]]></kuvatavNr>
					<sisuTekst id="98539987-22ba-44ae-9354-64508cb17455">
						<tavatekst id="05f43d10-d08b-4428-a7ce-97869785a111">For the exercise of state supervision, the Consumer Protection and Technical Regulatory Authority may take measures provided in Article 58(8) of Regulation (EU) 2019/881 of the European Parliament and of the Council.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026 – the number of the section changed from 1.1 to 1.7]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg2">
					<loigeNr id="e3dffc12-22d0-4f73-ab9b-bca16287cf64">2</loigeNr>
					<kuvatavNr id="76165c9e-2275-4643-bc4b-8dfdcaee7c3a"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="a29be351-cc5f-4b9b-adba-d81f2ed6ba7c">
						<tavatekst id="47b1d4ac-7459-4188-862c-dd2d9fa4ab9e">The addressee is to be notified of the application of a measure provided in this section at the first opportunity.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para16lg3">
					<loigeNr>3</loigeNr>
					<kuvatavNr><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst>
						<tavatekst>It is required to record a measure provided in this section.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17">
				<paragrahvNr id="6b007f8f-d6ee-430e-83f2-8405af9cc941">17</paragrahvNr>
				<kuvatavNr id="2369c150-54cc-4f41-8e24-aac5a4c5924d"><![CDATA[§ 17. ]]></kuvatavNr>
				<paragrahvPealkiri id="d30c9540-2f2c-4a06-a08b-3e4efb39d7b9">Administrative supervision measures</paragrahvPealkiri>
				<loige id="para17lg1">
					<loigeNr id="b617a609-a42d-4b43-aec9-a4036e89096e">1</loigeNr>
					<kuvatavNr id="1501d623-e485-4c53-8e9c-33f33a4c1cb4"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="6f7bfc9d-6d05-42f1-bcf9-b97069ea3a92">
						<tavatekst id="402e6642-3ac4-4e05-8bb7-19a246c48f16">Upon exercising administrative supervision, the Estonian Information System Authority is authorised to access a system and restrict the use of or access to the system provided all the following conditions are met:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17lg1p1">
						<alampunktNr id="f0a397c3-24b4-4e26-b6bc-3877fa5601d4">1</alampunktNr>
						<kuvatavNr id="7c1fa260-c4c5-4b63-9376-ee83625f9235"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="6f74b16d-1d45-491b-a86e-68e3c3d16d0c">
							<tavatekst id="edf8d213-91b2-47fb-bd3a-f08d8a335afc">a cyber incident compromises or harms the security of another system;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p2">
						<alampunktNr id="5c98f59e-adde-4c63-9e9e-afeff047df0c">2</alampunktNr>
						<kuvatavNr id="eeb1255a-c0f4-470f-89b4-00b19221c5d2"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="1bdd74ab-3b2c-4a34-8dc7-202e754a6e1b">
							<tavatekst id="79654399-4e1a-4c4d-887a-8e18b9e0e8c5">the system administrator is unable or is unable in a timely manner to counter a threat originating from the cyber incident or eliminate the cyber incident;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p3">
						<alampunktNr id="97546537-e2c7-42b0-8832-b1753308922b">3</alampunktNr>
						<kuvatavNr id="6f530e56-9bc6-41c0-aa0d-28641aa1567b"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="4a3be3fd-a91d-47b0-ad63-1c7bdc74e432">
							<tavatekst id="de071ac6-c69a-4790-9635-d9aae2b7848f">it is not possible to counter the threat originating from the cyber incident or eliminate the cyber incident by using a less infringing measure in respect of a person;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1p4">
						<alampunktNr id="c19eeace-438b-4a2d-b0c6-418aee3200a0">4</alampunktNr>
						<kuvatavNr id="99eee0da-6006-49e4-8373-416ebc3f1bd9"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="15465404-2c9d-4c44-8ff8-46a392d7a74b">
							<tavatekst id="7fd96e76-a787-4bd2-a026-bb7c4c66abdc">a person is not caused disproportional damage by countering the threat originating from the cyber incident or by eliminating the cyber incident.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17lg1b1">
					<loigeNr id="09e6521f-6025-4bcf-805b-95b9c71caf70" ylaIndeks="1">1</loigeNr>
					<kuvatavNr id="39300e29-c781-43df-8e0b-22dee97864e4"><![CDATA[(1<sup>1</sup>)]]></kuvatavNr>
					<sisuTekst id="1e8fa140-935b-4dce-9634-bebf39196721">
						<tavatekst id="4ccdc2c5-573a-4d4b-9951-9d57bfa4eff9">In performing the tasks of administrative supervision, the Estonian Information System Authority has the right to:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17lg1b1p1">
						<alampunktNr id="bfefc229-06d6-4534-bd1f-00adf2d0fcf9">1</alampunktNr>
						<kuvatavNr id="84bf9287-1255-413d-9761-93ede34ad0b0"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="2801c2c2-e62e-4db7-8ba9-819037fc170a">
							<tavatekst id="dbea67b5-a4f6-4ad6-9138-2658183a220a">carry out on-site inspections and off-site supervision in respect of a service provider, proceeding from clauses 2 and 3 of subsection 6 of § 14 of this Act, including to carry out random supervision in respect of an essential entity, which may, among other things, be prompted by a cyber incident with a significant impact or by a breach of a requirement provided in this Act or in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p2">
						<alampunktNr id="0af1d0c4-4df2-441a-b6d2-a80117ef13b8">2</alampunktNr>
						<kuvatavNr id="ecfc5111-2d12-4605-b34a-2fe5ed63ff7e"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="eeb169a4-2424-4530-b878-f452b896f68e">
							<tavatekst id="5166ac2e-9194-45e1-8587-ad0c4729b407">carry out targeted security audits in respect of a service provider, based on a risk assessment performed by the Estonian Information System Authority or by the audited service provider, or on other available risk information, the costs of which are covered by the service provider, except in the cases specified in the regulation established on the basis of subsection 1<sup>2</sup> of this section;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p3">
						<alampunktNr id="c5463454-ee87-49b8-b0c0-272ac1eabe66">3</alampunktNr>
						<kuvatavNr id="d12013d7-1890-421d-96ba-08fb48cf1ebf"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="70f8fbfc-5536-4166-a960-010bb4564ef6">
							<tavatekst id="fa2b6f89-8e89-4699-8227-170098c7a8fd">carry out security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the co-operation of the service provider concerned;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p4">
						<alampunktNr id="5d09e9c3-87e8-4cb5-8517-ca9648deb6e1">4</alampunktNr>
						<kuvatavNr id="36cd463b-9139-4244-aec7-4342cb81f21f"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="099fa550-8f3e-4f90-9cc5-314aa15ad12d">
							<tavatekst id="207b4c04-c950-4e55-ab9f-7721169bb844">issue a warning to a service provider where the service provider breaches this Act, or a requirement provided in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p5">
						<alampunktNr id="129e33fb-cc21-4876-9089-8f3f92a5911a">5</alampunktNr>
						<kuvatavNr id="0922b0ce-39f8-4ddf-b31c-7e5a4efd587d"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="5f95ec68-053a-4da5-9518-5d1c1883f63c">
							<tavatekst id="ffbf0ee5-6b5a-49e2-994c-20a099bde815">issue a compliance notice requiring the addressee of the compliance notice to cease an activity or practice which breaches a requirement provided in this Act, or in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, and to refrain from using the same activity or practice;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p6">
						<alampunktNr id="40074531-3f33-4712-aa30-4fedb763b775">6</alampunktNr>
						<kuvatavNr id="b8363926-554d-4520-81cd-cc87a48e795d"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="65892783-69fa-4aca-87c5-ea7b673ff449">
							<tavatekst id="5850cbae-420d-4207-ab8d-8af8a665907f">issue a compliance notice requiring the addressee of the compliance notice to comply with the requirements provided in § 7 of this Act and in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) of Directive (EU) 2022/2555 of the European Parliament and of the Council, and to submit a notification provided in § 8 of this Act in the manner referred to in that section and within the time limit specified;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p7">
						<alampunktNr id="fd2400e0-4141-4756-90d0-b1f44f472da4">7</alampunktNr>
						<kuvatavNr id="e3b010f0-196a-4e7e-b84f-119e0fb61885"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="493f03c5-0159-4ca9-b821-755ed07676c2">
							<tavatekst id="a8760b83-89a0-4b81-a6a8-8ed124980a17">issue a compliance notice requiring the addressee of the compliance notice to notify an entity where the service or activity provided to that entity by the addressee of the compliance notice may be affected by a significant cyber threat, by providing in the notification information on the significant cyber threat and, where possible, explanations as to which measures the affected entity may take to respond to the cyber threat;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p8">
						<alampunktNr id="f1a50081-9771-4674-8524-048439a9b881">8</alampunktNr>
						<kuvatavNr id="7c2f729f-64f0-4316-931d-328f8e57a6ab"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="d80727e8-dd15-498e-8f99-ce7b6a9769de">
							<tavatekst id="2694335c-b396-43b1-bc0c-969b825e1669">issue a compliance notice requiring the addressee of the compliance notice to implement recommendations made on the basis of a security audit within a reasonable time;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p9">
						<alampunktNr id="e5483b76-d323-4bf2-99a3-6209540b37e3">9</alampunktNr>
						<kuvatavNr id="05f62053-5cff-45dc-849c-512a2721dd87"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="1d08fc56-f431-4f00-b311-5050cf266991">
							<tavatekst id="b76f12f0-c590-40ce-a42e-318b66173e8a">issue a compliance notice requiring the addressee of the compliance notice to disclose the circumstances of a breach of a requirement provided in this Act or in an implementing act adopted on the basis of this Act or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council, in the manner prescribed in the compliance notice;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17lg1b1p10">
						<alampunktNr id="93638eb9-a0a5-4fd6-b1ae-0e8e55b918bb">10</alampunktNr>
						<kuvatavNr id="7a96e2af-0c86-4b8e-8151-979f265b0e38"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="204ea31b-f7a5-4ea0-b941-e2ca48027217">
							<tavatekst id="0d17e20d-88cd-47e9-9666-085f77c059c6">issue to an essential entity a compliance notice requiring the addressee of the compliance notice to designate, for a specified period, a compliance officer who monitors whether the addressee of the compliance notice complies with the requirements provided in §§ 7 and 8 of this Act and the requirements provided in an implementing act adopted on the basis thereof or on the basis of Article 21(5) or Article 23(11) of Directive (EU) 2022/2555 of the European Parliament and of the Council.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17lg1b2">
					<loigeNr id="2b38eef1-ecbf-443f-af70-1d76b52a8d77" ylaIndeks="2">1</loigeNr>
					<kuvatavNr id="e84c69cf-6461-4fba-87f8-40aec6d51f11"><![CDATA[(1<sup>2</sup>)]]></kuvatavNr>
					<sisuTekst id="2d241b45-7a1c-499b-828d-6c9d82612f7e">
						<tavatekst id="b200febe-30fc-479b-b212-1265b80e962f">The detailed conditions and procedure for organising the targeted security audit specified in clause 2 of subsection 1<sup>1</sup> of this section, including a list of situations in which the Estonian Information System Authority reimburses the service provider the costs of the security audit, and the procedure for reimbursing the costs of the security audit are established by a regulation of the minister in charge of the policy sector of national cybersecurity.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17lg1b3">
					<loigeNr id="5d6b9806-dd55-4d74-b89b-8746752f9fd7" ylaIndeks="3">1</loigeNr>
					<kuvatavNr id="b157461f-8984-4795-8a16-318bdc1a003c"><![CDATA[(1<sup>3</sup>)]]></kuvatavNr>
					<sisuTekst id="268eaaec-a0b6-46cc-96cc-fdebdbc8bcea">
						<tavatekst id="404aa143-4e6f-4ff5-af05-f494be4e634a">The compliance notice issued to an essential entity specified in clause 5 of subsection 1<sup>1</sup> of this section may also include security measures intended to prevent or remedy a cyber incident and requirements regarding the deadline for implementing the security measures and notifying of implementation.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17lg2">
					<loigeNr id="c984bbd2-aa28-43b3-9313-0067fd4cfa09">2</loigeNr>
					<kuvatavNr id="920426d1-47f4-48d0-bd8c-9e8fc5fe9ba9"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="83bc309d-f47d-4273-b77c-5e9be195cb02">
						<tavatekst id="bd43a8f6-71dd-43bb-91e4-3e136a8255f7">The addressee must be notified of the application of a measure provided in this section at the first opportunity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17lg3">
					<loigeNr id="c4c47c10-d314-4da7-b14e-4cf6380f4c79">3</loigeNr>
					<kuvatavNr id="29a4d899-d97c-4c1f-9d38-98c52e3ea2df"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="7f3cacc4-7b4c-476c-a5df-e92e025c6739">
						<tavatekst id="09fd3286-88bf-49af-9338-92e50043ea62">It is required to record a measure provided in this section.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b1">
				<paragrahvNr id="063e626f-1ad4-4989-b0c9-dee9a785ed12" ylaIndeks="1">17</paragrahvNr>
				<kuvatavNr id="3dfa7664-57ed-4c3e-aa98-579603e21ec8"><![CDATA[§ 17<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="eab7054d-cd9e-4bb7-9aec-08b7fd9d66b6">Rate of non-compliance levy</paragrahvPealkiri>
				<loige id="para17b1lg1">
					<loigeNr id="4d606912-f0e6-4b1c-b4fd-c64c724ecc96"/>
					<kuvatavNr id="dd023707-19ff-497b-88b2-132d70595682"/>
					<sisuTekst id="42a21349-5353-4e9f-b965-f53d7c6868ee">
						<tavatekst id="4c0bbdfd-9b6d-4f21-8290-9bbffe2e7d1b">Upon failure to comply with a compliance notice, the upper limit of non-compliance levy for each imposition thereof in accordance with the rules provided in the Substitutional Performance and Non-Compliance Levies Act is 70,000 euros.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b2">
				<paragrahvNr id="82ab8bb6-c727-4b7f-b690-7fbbe3ca0587" ylaIndeks="2">17</paragrahvNr>
				<kuvatavNr id="9fe272b1-73c7-43a6-ae7e-7755fe45bf08"><![CDATA[§ 17<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="23322617-c679-418b-8355-0bf8dd904212">Term for review of complaint</paragrahvPealkiri>
				<loige id="para17b2lg1">
					<loigeNr id="25aa0c3c-6a9c-4583-ac46-8a6cd184aede">1</loigeNr>
					<kuvatavNr id="7bfec7dd-b191-4394-9d79-294ecd7e851a"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="cf1e4e9c-c2a6-4cd2-aaa0-0a633e42e8b9">
						<tavatekst id="c8b755ee-980d-47c3-9102-270aa270e9a0">The Consumer Protection and Technical Regulatory Authority settles a complaint provided in Article 63 of Regulation (EU) 2019/881 of the European Parliament and of the Council no later than on the 90th day as of the receipt of the complaint.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b2lg2">
					<loigeNr id="8ae6131a-a38f-46df-b845-b4cb8fb46a5e">2</loigeNr>
					<kuvatavNr id="a198bdf3-c650-4e12-b804-c04e7c245aba"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="7edc78cc-ea44-452b-9946-7cfe9ad77f58">
						<tavatekst id="242e51e3-7081-4ad3-b5ce-36317d052441">Should the settlement of a complaint specified in subsection 1 of this section require co-operation with the national cybersecurity certification authority of another state, the Consumer Protection and Technical Regulatory Authority has the right to extend the term for review of the complaint by a period of time necessary for hearing the opinion of said authority. The person who lodged the complaint is informed of the extension of the term for review of the complaint in writing.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b3">
				<paragrahvNr id="df6221f9-afa5-4786-898f-eead0ba7311b" ylaIndeks="3">17</paragrahvNr>
				<kuvatavNr id="7b8a7892-bdca-4334-aa3d-a11a7c185c91"><![CDATA[§ 17<sup>3</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="14b3c0e9-0c80-448d-b32a-e9979c7c2c25">Mutual assistance</paragrahvPealkiri>
				<loige id="para17b3lg1">
					<loigeNr id="ad6bdff2-a7e1-49f8-a0c6-dc0a35b19e47">1</loigeNr>
					<kuvatavNr id="7b4ac2a6-031f-49eb-9914-4b16c4c0fbf9"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="6a9b756b-39be-4346-b9ba-faa63b702db2">
						<tavatekst id="45ceecbf-ff9c-43a7-aea3-61806d2cd10e">Where an entity provides services in more than one Member State of the European Union, or provides services in one or more Member States of the European Union and its systems are located in one or more other Member States of the European Union, the Estonian Information System Authority and the competent authorities designated in another Member State of the European Union on the basis of Article 8 of Directive (EU) 2022/2555 of the European Parliament and of the Council co-operate with and assist each other as necessary.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b3lg2">
					<loigeNr id="927b3c6d-6c6e-4052-8c72-c4b2ec50c2e7">2</loigeNr>
					<kuvatavNr id="231ac44f-7bdd-4d5e-b28f-c69a1006d052"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="db55cdc1-f928-44cb-99fe-02567008be37">
						<tavatekst id="3d0e7544-af88-4b81-a440-b2a522ce40b2">Upon a substantiated request from the supervisory authority of another Member State of the European Union, the Estonian Information System Authority provides the other supervisory authority with assistance proportionate to its own resources so that the supervisory or enforcement measures can be implemented in an effective, efficient and consistent manner. Mutual assistance may, in particular, cover information requests and supervisory measures, including requests to carry out on-site inspections or off-site supervision or targeted security audits.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b3lg3">
					<loigeNr id="317aac42-d621-451c-93d2-49292f47a5fe">3</loigeNr>
					<kuvatavNr id="0b00dd93-4839-429a-b757-1cd0bd5f0ed1"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="341e13c7-1b49-48a3-8fe3-d285d60afb7c">
						<tavatekst id="fdba2f02-70b4-4bc1-8650-45b470b25a8a">In the case specified in subsection 1 of this section, the Estonian Information System Authority may submit a request for assistance referred to in subsection 2 of this section to the competent authority designated in another Member State of the European Union on the basis of Article 8 of Directive (EU) 2022/2555 of the European Parliament and of the Council.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b3lg4">
					<loigeNr id="e1ac74e4-4e0e-46d0-9bd5-c8144b8bce0b">4</loigeNr>
					<kuvatavNr id="76e3abf2-a773-4d06-8153-8c6703c79d95"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="2ba5b87d-6a13-4fc3-a13b-fef4ee102872">
						<tavatekst id="743cff3b-3066-4e4d-a561-7fe63c47826c">The Estonian Information System Authority may refuse a request for assistance submitted by the competent authority designated in another Member State of the European Union on the basis of Article 8 of Directive (EU) 2022/2555 of the European Parliament and of the Council if:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17b3lg4p1">
						<alampunktNr id="743529e1-5b7b-45dd-9dab-38ccad29b193">1</alampunktNr>
						<kuvatavNr id="645b4862-19e7-4ed9-9442-77fc76131c14"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="9401f036-3477-49a1-ab0f-38de67f0972b">
							<tavatekst id="15a7d7cf-ffac-4bc3-970e-9db72261ba5b">the Estonian Information System Authority does not have the competence to provide the requested assistance;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b3lg4p2">
						<alampunktNr id="98a25648-5e01-4716-92fc-c686080572f5">2</alampunktNr>
						<kuvatavNr id="aeb8b13b-e2db-453f-89ca-76e96c55bf66"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="e153b968-a8be-4027-b177-2b39180301c4">
							<tavatekst id="832ba34f-9c7b-4e39-a2b6-15ae1958484d">the requested assistance is not proportionate to the tasks of the Estonian Information System Authority; or</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b3lg4p3">
						<alampunktNr id="1efa788e-3038-4db8-b811-77b62b5cbb7c">3</alampunktNr>
						<kuvatavNr id="71ca39c4-ca71-436e-924d-8d8f247a78a5"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="fb988e83-1007-4855-9bd6-7b963d32beb4">
							<tavatekst id="189c178e-3bcc-483b-b674-7c36fd758c56">the request concerns information or entails activities which, if disclosed or carried out, would be contrary to the essential interests of national security, public security or national defence.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17b3lg5">
					<loigeNr id="b7598228-c04e-4132-8d2f-68960893ff37">5</loigeNr>
					<kuvatavNr id="7b25bbdc-a5f7-43cf-80f8-b37985371ac6"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="0a8811d8-1179-4909-873f-d9a693a30df9">
						<tavatekst id="94df276c-49a3-4ebf-811e-5b49975a73e8">Before refusing a request for assistance, the Estonian Information System Authority consults other relevant competent authorities and, upon the request of one of the Member States of the European Union concerned, also the European Commission and the European Union Agency for Cybersecurity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b3lg6">
					<loigeNr id="85921ce9-50e1-48a2-801a-aaad5adc5efa">6</loigeNr>
					<kuvatavNr id="15887ccd-1526-4550-9670-19aea26ef811"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="a8801145-5d24-43e5-a5e3-a88dd6855fea">
						<tavatekst id="926ba316-c56e-4a4c-904b-b290d586c541">Taking into account the supervisory measures specified in this Act, the Estonian Information System Authority may apply joint supervisory measures involving employees or officials of a competent authority designated on the basis of Article 8 of Directive (EU) 2022/2555 of the European Parliament and of the Council. The authorities agree among themselves on the procedure and operations for joint activities.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b3lg7">
					<loigeNr id="dec5fd1f-5c4b-4fdc-b1fd-e534efbbc8ee">7</loigeNr>
					<kuvatavNr id="170a1f6b-6e90-4a50-9c0b-5644f46c9053"><![CDATA[(7)]]></kuvatavNr>
					<sisuTekst id="b5cecdea-12fd-4caa-9c5a-f9dd1717e288">
						<tavatekst id="01ba58e9-4037-4e10-8f71-f1d9f6314105">If Estonia receives, in relation to a digital service provider, a request for mutual assistance, the Estonian Information System Authority may, within the scope of the request, take appropriate supervisory and enforcement measures in respect of the digital service provider specified in the request, where that digital service provider provides services or manages systems within the territory of the Republic of Estonia.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="afb2b392-a115-416c-8d8e-f5d1472138eb">
			<peatykkNr id="0898cd8d-4649-4f0b-9072-c339d625150f" ylaIndeks="1">4</peatykkNr>
			<kuvatavNr id="ec4a5ee6-d091-4788-b8a0-ce00e617a84d"><![CDATA[Chapter 4<sup>1</sup>]]></kuvatavNr>
			<peatykkPealkiri id="a63d682a-5425-4d50-810a-927dde00abb1">Co-operation, Information Sharing and Peer Review</peatykkPealkiri>
			<muutmismarge>
				<avaldamismarge>
					<RTosa>RT I</RTosa>
					<avaldamineKuupaev>2025-12-30</avaldamineKuupaev>
					<RTartikkel>4</RTartikkel>
					<aktViide>130122025004</aktViide>
				</avaldamismarge>
				<joustumine>2026-01-01</joustumine>
			</muutmismarge>
			<paragrahv id="para17b4">
				<paragrahvNr id="de6ca9ea-462b-4226-ad33-69b135097e5c" ylaIndeks="4">17</paragrahvNr>
				<kuvatavNr id="4dc4b810-ab49-4867-97f3-7ca8e984db26"><![CDATA[§ 17<sup>4</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="6b477ff2-ebd7-4d65-96c8-bbce0ae0ab9d">Co-operation tasks of Estonian Information System Authority and security authority</paragrahvPealkiri>
				<loige id="para17b4lg1">
					<loigeNr id="d0b8f0ef-5088-424e-a236-c890abe001cd">1</loigeNr>
					<kuvatavNr id="df9540f4-681e-4a24-9de6-f4f30e91b342"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="01ff369e-ac9e-407f-9494-ce752a6b21f2">
						<tavatekst id="107853f8-2705-4abc-b073-a0a2de71cb48">In performing their tasks, the Estonian Information System Authority and a security authority co-operate with the following authorities and communities:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17b4lg1p1">
						<alampunktNr id="ecf7c752-d014-4c3c-abf3-0ec5c2857370">1</alampunktNr>
						<kuvatavNr id="38e122fc-c91c-4859-b527-c8b9d134840b"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="4ffd1b1d-afb5-4a25-b8c2-c627d9aeb976">
							<tavatekst id="ca9da9df-b986-45bf-82fe-fc80e6182825">national authorities pursuant to Regulation (EC) No 300/2008 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p2">
						<alampunktNr id="d247b8cc-2f23-4df0-bedf-f6e1defa874a">2</alampunktNr>
						<kuvatavNr id="2a58d48b-3954-4e06-b398-fe5ff9558275"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="d3ac8056-d787-41c3-90a9-46eba4d28cd6">
							<tavatekst id="1db9cb7a-4ee6-4796-960d-0a19aac1321c">supervisory authorities pursuant to Regulation (EU) No 910/2014 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p3">
						<alampunktNr id="960144ca-a2f2-4369-a5c0-9930f5db428d">3</alampunktNr>
						<kuvatavNr id="68af375d-7b4a-4634-bf6d-2901d6682105"><![CDATA[3) ]]></kuvatavNr>
						<sisuTekst id="8d73797b-135e-45ae-b33a-64024c080a28">
							<tavatekst id="c6598680-e2b1-4303-bbbc-440e1610b152">national authorities pursuant to Regulation (EU) 2018/1139 of the European Parliament and of the Council on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.08.2018, pp 1–122);</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p4">
						<alampunktNr id="53aefac2-d118-4994-a432-a288638737ea">4</alampunktNr>
						<kuvatavNr id="08d0a31c-f942-4acb-9db8-463216237ed7"><![CDATA[4) ]]></kuvatavNr>
						<sisuTekst id="e1efc7c8-c303-4e77-a485-c67b41c39eae">
							<tavatekst id="b43a0a8c-b615-43ad-b00f-473d2f5e5445">competent authorities pursuant to Regulation (EU) 2022/2554 of the European Parliament and of the Council;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p5">
						<alampunktNr id="02766c41-ce40-46bf-9675-d5a20077ec99">5</alampunktNr>
						<kuvatavNr id="3ac735d6-d8cf-4e16-a1c1-159cf1e14b73"><![CDATA[5) ]]></kuvatavNr>
						<sisuTekst id="0e6dd550-0bf0-41a6-a0c8-91afa0035462">
							<tavatekst id="6e297383-8ce1-494f-8a48-fa77fb0bf299">personal data protection supervisory authorities;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p6">
						<alampunktNr id="1ed513f8-f65a-44d0-9270-d324be2667ab">6</alampunktNr>
						<kuvatavNr id="55cfa1a3-1766-461d-8d81-6001b3e498d5"><![CDATA[6) ]]></kuvatavNr>
						<sisuTekst id="20589474-a870-400b-b553-a54f22117249">
							<tavatekst id="a2463872-58ad-46fc-b42a-432d61829903">a security authority;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p7">
						<alampunktNr id="5914d583-988f-4647-a648-0a693145377d">7</alampunktNr>
						<kuvatavNr id="ed5e6582-ba32-41e9-8598-519db967ea68"><![CDATA[7) ]]></kuvatavNr>
						<sisuTekst id="ee87f0cb-060a-4c9f-9f73-d323725458e5">
							<tavatekst id="a4ad2c8e-553b-4b8e-80e6-d220fe417da5">competent authorities pursuant to other European Union legal acts;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p8">
						<alampunktNr id="a1dc5882-82b6-4fa8-b631-6a0bdb6abc95">8</alampunktNr>
						<kuvatavNr id="550ebd7b-06e2-4309-a911-92b8c39ed2ef"><![CDATA[8) ]]></kuvatavNr>
						<sisuTekst id="6360c519-af94-4a00-a836-28cf680a8836">
							<tavatekst id="f414db72-56f3-4086-8e70-c17943610bff">the Consumer Protection and Technical Regulatory Authority;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p9">
						<alampunktNr id="83aecb76-9259-4d91-8c8e-900dc33de01f">9</alampunktNr>
						<kuvatavNr id="7b703ac9-48c4-4d05-a361-14be7578505d"><![CDATA[9) ]]></kuvatavNr>
						<sisuTekst id="1118b4e7-ae56-4f99-ae9a-7d40b2b3fe97">
							<tavatekst id="606d81c5-7dcd-46cf-aed1-fb6123aec35c">sector-specific or cross-sector communities of service providers, including, where necessary, exchange information with them, taking into account the requirements provided in § 17<sup>5</sup> of this Act;</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b4lg1p10">
						<alampunktNr id="3282ad7a-5308-40af-9e75-61b9258e5cf7">10</alampunktNr>
						<kuvatavNr id="5c9ac81d-fa0b-49b5-adc5-36e291ece0dd"><![CDATA[10) ]]></kuvatavNr>
						<sisuTekst id="077991bb-3b04-4d69-b6b0-4472f6a03dea">
							<tavatekst id="8022ddb4-2917-4136-8dc6-a6ab67d9407d">law enforcement agencies for the purposes of the Personal Data Protection Act.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17b4lg2">
					<loigeNr id="50bd9c1c-b417-461f-b10c-1cfb8e3bfc7d">2</loigeNr>
					<kuvatavNr id="81abf456-5479-4f16-b3f3-290bc784dd62"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="72662d93-d8ad-404c-bef9-87128a19f978">
						<tavatekst id="b7ec37ff-477f-4f43-a253-6287f87b2ac1">The Estonian Information System Authority co-operates comprehensively with an authority organising a vital service or an authority designated by it on the basis of subsection 5 of § 37 of the Emergency Act, the Rescue Board and the Government Office, and shares with them information regarding the designation of a provider of a vital service and the risks, cyber threats, cyber incidents and cyber incidents with a significant impact notified by a provider of a vital service, as well as other relevant situations, other than risks, cyber threats and cyber incidents, affecting essential entities that are regarded as providers of a vital service, and the measures taken to respond to such risks, threats and incidents. In addition, the Estonian Information System Authority notifies said authority if, in the course of state or administrative supervision, the Estonian Information System Authority applies a supervisory measure in respect of a provider of a vital service. The same authority may, where relevant, request the Estonian Information System Authority to apply a supervisory measure provided for in state or administrative supervision proceedings in respect of a provider of a vital service.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b4lg3">
					<loigeNr id="0333861d-1bf4-491c-9578-922e89e19dc5">3</loigeNr>
					<kuvatavNr id="65b36eba-52b9-4302-beed-33b3ea028710"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="ded36cdc-4132-495d-87ce-037e8e905835">
						<tavatekst id="2fca92f3-cbb8-4058-8e4e-d6c68a7628d3">The Estonian Information System Authority notifies the Oversight Forum established pursuant to Article 32(1) of Regulation (EU) 2022/2554 of the European Parliament and of the Council if, in the course of state supervision, the Estonian Information System Authority applies a supervisory measure to ensure compliance, by a service provider falling within the scope of application of this Act and designated as a critical ICT third-party service provider pursuant to Article 31 of that Regulation, with the requirements established in this Act or on the basis of this Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b4lg4">
					<loigeNr id="e79dca2a-5e71-49e9-bdbb-977baf6c28d7">4</loigeNr>
					<kuvatavNr id="d9df67d1-0808-4dc9-97b6-319eed3bb912"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="68b05aab-a793-44a0-8cae-f3e869e65469">
						<tavatekst id="3b14ca76-32e8-406d-9732-9b7a0d5d38ba">The Estonian Information System Authority and the authorities specified in clauses 2, 4, 6 and 8 of subsection 1 of this section share relevant information regularly, including information on relevant cyber incidents and cyber threats.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b4lg5">
					<loigeNr id="692e7318-511c-4cfe-8bfc-18e3541fc38d">5</loigeNr>
					<kuvatavNr id="44a8965f-9f87-498c-8d47-302a7ebe8b35"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="cbf7cf51-d8de-4f2d-90a7-0eac5d600c3b">
						<tavatekst id="98c321c2-cca0-49d2-bd9f-6089b112f030">As the competent authority designated on the basis of Article 8(1) of Directive (EU) 2022/2555 of the European Parliament and of the Council, the Estonian Information System Authority exercises a liaison function to ensure cross-border co-operation, in the field of cybersecurity, between Estonian authorities and the relevant competent authorities of other Member States of the European Union and, where relevant, also the European Commission and the European Union Agency for Cybersecurity.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b4lg6">
					<loigeNr id="154e7411-b0ee-4ee1-becb-ae9962e19cc7">6</loigeNr>
					<kuvatavNr id="1278ce70-a7c9-4929-a5a0-969491083749"><![CDATA[(6)]]></kuvatavNr>
					<sisuTekst id="68464d57-2308-4ef4-96c3-4a52d7b6588c">
						<tavatekst id="ea5ed286-1e1d-48a0-8430-f0c4b68696fc">In sharing information, the security of the information transmitted is ensured and, where relevant, agreed information-sharing protocols are used, including the traffic light protocol.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b5">
				<paragrahvNr id="01a17f37-17a7-4d93-9027-7cb02f2ad57e" ylaIndeks="5">17</paragrahvNr>
				<kuvatavNr id="97a9505b-7fa9-4d81-b50b-cf5433188480"><![CDATA[§ 17<sup>5</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="a4c93c53-7c80-4aaa-ae56-6b9cb43253dc">Cybersecurity information-sharing arrangements</paragrahvPealkiri>
				<loige id="para17b5lg1">
					<loigeNr id="1db17eda-a802-44ab-a2a8-f00e9ef322b1">1</loigeNr>
					<kuvatavNr id="70f7cb88-f1e6-44dc-852a-b3476d49cdf9"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="e11ac53e-1d0b-43d2-935e-25b03c1fee19">
						<tavatekst id="5e4ec730-cca6-48c7-a08e-bb5a027689b7">Service providers and other persons may exchange on a voluntary basis relevant cybersecurity information among themselves, including information relating to cyber threats, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, threat-actor-specific information, cybersecurity alerts and recommendations regarding configuration of cybersecurity tools to detect cyberattacks, where such information sharing:</tavatekst>
					</sisuTekst>
					<alampunkt id="para17b5lg1p1">
						<alampunktNr id="1b7f2d61-8198-4190-85a6-a131bdafe7a0">1</alampunktNr>
						<kuvatavNr id="988e4e96-140e-4b32-a946-0b709db643ee"><![CDATA[1) ]]></kuvatavNr>
						<sisuTekst id="9b410635-8959-4921-b27e-0f554fd38adb">
							<tavatekst id="2adbc8d6-252d-4f0f-b131-801d6b317291">aims to prevent, detect, respond to or recover from cyber incidents or to mitigate their impact; or</tavatekst>
						</sisuTekst>
					</alampunkt>
					<alampunkt id="para17b5lg1p2">
						<alampunktNr id="5a76a58e-766d-4fce-bc36-1c3a24b5285d">2</alampunktNr>
						<kuvatavNr id="8837d3ce-88f9-45e7-b453-44920b4395ad"><![CDATA[2) ]]></kuvatavNr>
						<sisuTekst id="0406f811-96a4-439d-a3ab-91b1111d2daa">
							<tavatekst id="565c3d63-e657-4b7a-bfb3-cd3ac6611575">enhances cybersecurity, in particular through raising awareness in relation to cyber threats, limiting or impeding the ability of such threats to spread, supporting a range of defensive capabilities, vulnerability remediation and disclosure, threat detection, containment and prevention techniques, mitigation strategies, or response and recovery stages or promoting collaborative cyber threat research between public and private entities.</tavatekst>
						</sisuTekst>
					</alampunkt>
				</loige>
				<loige id="para17b5lg2">
					<loigeNr id="6a816027-cf1b-4bc4-9842-4b3347cf128f">2</loigeNr>
					<kuvatavNr id="0aa1306e-052e-4358-87d8-7fd44c1bb6fb"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="a0feba1d-105a-4f68-99be-d8c882aa0274">
						<tavatekst id="3d97e17d-c1c9-4981-b0dc-0b279b0f9ca5">The information sharing specified in subsection 1 of this section takes place on the basis of a cybersecurity information-sharing arrangement (hereinafter <i>information-sharing arrangement</i>). There may be more than one information-sharing arrangement.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b5lg3">
					<loigeNr id="515393f1-c664-4746-a691-f92b227ff2d5">3</loigeNr>
					<kuvatavNr id="f2052693-60cf-42e8-a45a-b929cf6f58c8"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="3eaec4ae-8760-42dc-acb1-6a1075dc1e3c">
						<tavatekst id="7435a773-f33f-434f-8a69-83e6184e24a6">An information-sharing arrangement may specify operational elements, including the use of dedicated information and communications technology platforms and automation tools, and other content and conditions, taking into account the confidentiality of the information shared.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b5lg4">
					<loigeNr id="8ccfbc79-635c-4739-a570-7759cffb72e3">4</loigeNr>
					<kuvatavNr id="a5ceb832-851e-4bb0-b448-98fa3245c314"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="de54f91c-9f11-4987-954a-6200466a2e8f">
						<tavatekst id="50d2d719-5b16-41d2-aa72-1e41698e8da9">The Estonian Information System Authority may impose conditions on the information made available by it under an information-sharing arrangement if a central government public administration entity or a local government public administration entity participates in the information-sharing arrangement.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b5lg5">
					<loigeNr id="1b1f09b4-135b-46d7-9883-dbb4f4fd854b">5</loigeNr>
					<kuvatavNr id="c2a0379c-56bd-46d9-9909-c66df77031ce"><![CDATA[(5)]]></kuvatavNr>
					<sisuTekst id="78b98b3b-baf5-4ac9-9411-e649c6d60ddc">
						<tavatekst id="8338a2ce-4c9a-4f79-9d05-d3a47756554f">A service provider notifies the Estonian Information System Authority upon entering into an information-sharing arrangement or where withdrawal from an information-sharing arrangement has taken effect.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para17b6">
				<paragrahvNr id="18806a57-6112-42cb-b8e4-bde33f6011bd" ylaIndeks="6">17</paragrahvNr>
				<kuvatavNr id="e7b82c07-86d3-4487-940e-488ae9999029"><![CDATA[§ 17<sup>6</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="7f82224a-e8b9-4e8a-a605-f8106f88ba15">Peer review</paragrahvPealkiri>
				<loige id="para17b6lg1">
					<loigeNr id="67526797-5d4d-4e73-a5c3-80b83cafd272">1</loigeNr>
					<kuvatavNr id="8c33a233-71ad-4f8f-bb83-932431b00678"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="ffa9e4ba-4a7f-41aa-8a6e-94c6e89064cf">
						<tavatekst id="4c55c6f5-57dd-44a3-a3e3-fd1dae26e1c6">Participation in the peer review provided in Article 19 of Directive (EU) 2022/2555 of the European Parliament and of the Council (hereinafter <i>peer review</i>) is voluntary.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b6lg2">
					<loigeNr id="fdc88893-0d6c-403c-8209-89429c260900">2</loigeNr>
					<kuvatavNr id="50bec403-29b3-444c-a00f-4c469fa6a137"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="680b1d80-5b40-414e-9b2a-be76a97a6c94">
						<tavatekst id="deed3a03-e921-4b8e-aac3-f89f72938c22">In the course of the peer review, the participating cybersecurity experts are not to disclose to third parties information obtained in the course of the peer review, unless an equivalent obligation of confidentiality is provided by law.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para17b6lg3">
					<loigeNr id="03e24b4e-af09-4b2a-8dd7-dd645119e1d0">3</loigeNr>
					<kuvatavNr id="1fda098d-14d0-451c-a86f-63316f4f2805"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="dfe4aec0-4d9e-479b-be73-0b0f61c0216c">
						<tavatekst id="62a4f55c-1929-447a-bda6-f9175700e8a4">The minister in charge of the policy sector of national cybersecurity may establish by a regulation the detailed conditions and procedure for participation in the peer review, including requirements for the organisation of the peer review, the tasks of the authorities participating in it, and the persons participating in the peer review.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="78883401-7ffb-4ff4-8f3c-3a34dca666c7">
			<peatykkNr id="5f4a6af2-d945-4d98-9603-aeaf8ee8a95c">5</peatykkNr>
			<kuvatavNr id="a028232b-1c84-4744-94e8-2aa88c97d7d0"><![CDATA[Chapter 5]]></kuvatavNr>
			<peatykkPealkiri id="d7c9e5ac-58ab-4fb3-80a5-1249f97ca15f">Liability </peatykkPealkiri>
			<paragrahv id="para18">
				<paragrahvNr id="6c01faa0-5fe4-426c-b5cf-b9e8563c473b">18</paragrahvNr>
				<kuvatavNr id="1300e80b-278f-4ff7-8a64-94811686b60c"><![CDATA[§ 18. ]]></kuvatavNr>
				<paragrahvPealkiri id="36fb0021-4113-4cf6-8692-395a5a567eb5">Violation of requirements of Act</paragrahvPealkiri>
				<loige id="para18lg1">
					<loigeNr id="6e8a9b46-8761-4e3f-aaee-4190b3dd00c2"/>
					<kuvatavNr id="45308bcc-14be-4dcb-8e50-5c7ee43be32a"/>
					<sisuTekst id="8d931996-8444-4e67-b1e5-0201b8ea1345">
						<tavatekst id="e0a35e5e-b560-48ea-9909-9a582523995f">[Repealed – RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b1">
				<paragrahvNr id="ec579ce6-4576-4789-9932-dfed74829409" ylaIndeks="1">18</paragrahvNr>
				<kuvatavNr id="bea06960-6daf-480d-8e54-4b9bf9ebb5c5"><![CDATA[§ 18<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="4056d830-9820-4bfe-b396-d44a85ea9aee">Violation of requirements of Regulation (EU) 2019/881 of the European Parliament and of the Council</paragrahvPealkiri>
				<loige id="para18b1lg1">
					<loigeNr id="97f41c8e-05e8-49dd-8e48-0ab766222edf">1</loigeNr>
					<kuvatavNr id="a7a6f79a-0701-4a95-9059-41352338a80f"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="195b2b23-5b9a-47bc-934b-2e4e9baf184d">
						<tavatekst id="a56f38d9-3ec1-45a8-912c-5ff035f26647">Issue of a statement of conformity that does not comply with the conditions provided in Article 53(2) of Regulation (EU) 2019/881 of the European Parliament and of the Council or, in the event of information specified in Article 55(1), violation of the requirements provided in paragraph 2 of the same Article –<reavahetus/>is punishable by a fine of up to 200 fine units.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b1lg2">
					<loigeNr id="b275b609-ef74-4f31-81bd-787ae07618e5">2</loigeNr>
					<kuvatavNr id="ae0e613c-23da-4534-8ec5-31a93c9c6e0e"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="f9c6145d-6a09-4237-adcf-23b143c120ec">
						<tavatekst id="67bf4532-6c0e-4c12-86d1-bb4959098699">The same act, if committed by a legal person, –<reavahetus/>is punishable by a fine of up to 20,000 euros.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b2">
				<paragrahvNr id="54a78385-bb3d-46e3-a591-11c883607eca" ylaIndeks="2">18</paragrahvNr>
				<kuvatavNr id="77e41142-d877-4856-8083-174adb77c5fb"><![CDATA[§ 18<sup>2</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="58687217-6097-4b4e-8523-a0bb7e6e60e9">Violation of requirements of Act by essential entity</paragrahvPealkiri>
				<loige id="para18b2lg1">
					<loigeNr id="6c36c27d-47f4-4be3-a2a8-271e024a117b">1</loigeNr>
					<kuvatavNr id="f0807a99-ad73-49d2-84ee-050a8f5f557e"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="d0d878c4-c2a7-4fb5-9035-657c389edf4a">
						<tavatekst id="8b70c1c7-db1b-47ee-b539-240b91aa468f">Violation, by an essential entity, of the requirements provided in subsection 1, 2, 3, 5 or 7 of § 7, or in subsection 1, 1<sup>1</sup>, 4<sup>1</sup>, 4<sup>2</sup>, 4<sup>3</sup>, 5, 7 or 8<sup>1</sup> of § 8 of this Act, where the elements of a misdemeanour provided in § 18<sup>4</sup> of this Act are absent, –<reavahetus/>is punishable by a fine of up to 10,000,000 euros.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b2lg2">
					<loigeNr id="9b837fa9-cbf0-4789-a9d1-2251feec3a6f">2</loigeNr>
					<kuvatavNr id="6e0d183e-d99a-40de-bff0-2556a3868a50"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="2e7c7589-89e8-4b2d-8d59-f5b2885984dc">
						<tavatekst id="6c15ac9e-9eba-4225-907a-2d51d9be93fc">The same act, if committed by a legal person, –<reavahetus/>is punishable by a fine of up to 10,000,000 euros or up to 2 per cent of the total worldwide annual turnover of the essential entity in the preceding financial year, whichever amount is higher.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b3">
				<paragrahvNr id="61958186-77c9-4bfd-bc0c-e475befa4a69" ylaIndeks="3">18</paragrahvNr>
				<kuvatavNr id="ef321964-1fef-46aa-ba3a-162fb0308192"><![CDATA[§ 18<sup>3</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="220b6150-2af4-46b2-bb8b-c3dc10d2f3bb">Violation of requirements of Act by important entity</paragrahvPealkiri>
				<loige id="para18b3lg1">
					<loigeNr id="673277c9-a853-4bad-a561-64ee7a4a9b6c">1</loigeNr>
					<kuvatavNr id="d8647fc9-65b6-44a5-8156-0c4441516322"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="57f39fab-e357-4502-a2a9-f192dc2f39f8">
						<tavatekst id="d746d901-3e1a-4b70-b5f0-14bc74888f70">Violation, by an important entity, of the requirements provided in subsection 1, 2, 3, 5 or 7 of § 7, or in subsection 1, 1<sup>1</sup>, 4<sup>1</sup>, 4<sup>2</sup>, 4<sup>3</sup>, 5, 7 or 8<sup>1</sup> of § 8 of this Act, where the elements of a misdemeanour provided in § 18<sup>4</sup> of this Act are absent, –<reavahetus/>is punishable by a fine of up to 7,000,000 euros.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b3lg2">
					<loigeNr id="dbdfb1d7-ebc1-4ff8-bf0d-e69b2c10a5fa">2</loigeNr>
					<kuvatavNr id="e7de2c42-45cd-44dd-9c2e-3aa444ecc72c"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="30b7e930-0ea7-4c83-a693-2b29012c8e30">
						<tavatekst id="97644038-e566-4347-8c82-54d9525d62e5">The same act, if committed by a legal person, –<reavahetus/>is punishable by a fine of up to 7,000,000 euros or up to 1.4 per cent of the total worldwide annual turnover of the important entity in the preceding financial year, whichever amount is higher.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b4">
				<paragrahvNr id="bc4395fe-c8fb-4032-87ca-b9d63d275669" ylaIndeks="4">18</paragrahvNr>
				<kuvatavNr id="67fe7c62-8a52-430c-9b5f-a3eb04acd182"><![CDATA[§ 18<sup>4</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="2b359555-2df3-48fd-aa8f-6bf13636dd8b">Violation of requirements of Act by entity in field of cross-border electricity flows</paragrahvPealkiri>
				<loige id="para18b4lg1">
					<loigeNr id="b0b217d1-fea0-4387-9216-49b37ed451bb">1</loigeNr>
					<kuvatavNr id="7b77c61f-bb64-4d6d-a318-5494544b707b"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="3361299a-52f5-4a36-a428-cf53c0c2d048">
						<tavatekst id="c4927940-ed04-48e0-8d8c-7080161266ea">Violation, by an entity specified in Article 2(1) of Commission Delegated Regulation (EU) 2024/1366, of the requirements provided in that Regulation, –<reavahetus/>is punishable by a fine of up to 10,000,000 euros.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b4lg2">
					<loigeNr id="17a5da86-c6b5-4926-818f-98056aac353c">2</loigeNr>
					<kuvatavNr id="799123c0-d0be-4f71-8860-176d3805722c"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="04439c57-3b44-401d-825d-665152aff3dc">
						<tavatekst id="eaa131c7-3056-4d59-ad9d-08d27914c960">The same act, if committed by a legal person, –<reavahetus/>is punishable by a fine of up to 10,000,000 euros or up to 2 per cent of the total worldwide annual turnover of the entity in the preceding financial year, whichever amount is higher.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para18b5">
				<paragrahvNr id="c1f1329c-54e7-4922-8049-d67b02c09db7" ylaIndeks="5">18</paragrahvNr>
				<kuvatavNr id="86140ac2-c043-4069-9092-1ff3cf933c95"><![CDATA[§ 18<sup>5</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="d2c0ca80-39d2-405b-9e25-39046d3bc298">Violation of requirements of Act by legal representative of entity in field of cross-border electricity flows</paragrahvPealkiri>
				<loige id="para18b5lg1">
					<loigeNr id="d7fe6cd5-a27e-4b0e-bcec-bc9c980328db">1</loigeNr>
					<kuvatavNr id="c543bf34-0fae-4023-93c8-f6d5c3b5743f"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="4869abf6-9fae-4b2f-9cd8-d71ed7881576">
						<tavatekst id="3046fb3b-cf6a-4e04-a369-82fe4d6e8ed7">Violation, by a legal representative designated on the basis of Article 15(1) of Commission Delegated Regulation (EU) 2024/1366, of the requirements provided in that Regulation, –<reavahetus/>is punishable by a fine of up to 300 fine units.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para18b5lg2">
					<loigeNr id="a0bb6a88-beee-4ab8-9c0d-f9d08ea302ca">2</loigeNr>
					<kuvatavNr id="fdc8970b-4967-44d3-89e0-bbd03fb42f42"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="4eb990de-9514-4d4f-86d4-f3a5a5719f5d">
						<tavatekst id="294fcd0c-9400-4355-b170-c15e0e94a7e2">The same act, if committed by a legal person, –<reavahetus/>is punishable by a fine of up to 32,000 euros.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para19">
				<paragrahvNr id="08f5598d-46bc-49e5-be34-ffc02d822d79">19</paragrahvNr>
				<kuvatavNr id="38b66539-dd06-4827-9e2d-58bbcbe1ef61"><![CDATA[§ 19. ]]></kuvatavNr>
				<paragrahvPealkiri id="eb4db10d-01b7-4f87-823e-71c77b4549dc">Proceedings</paragrahvPealkiri>
				<loige id="para19lg1">
					<loigeNr id="595702d5-793c-4c17-a3e3-2b00619c6eeb">1</loigeNr>
					<kuvatavNr id="254b6bb3-15e7-43b1-840d-a6411cb7f4d6"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="167475ca-12c3-435c-bfd3-7a8d5db1ff09">
						<tavatekst id="b318ab4d-372c-45c9-8a59-7e0c42e3c19a">The body conducting extra-judicial proceedings pertaining to the misdemeanours provided in §§ 18<sup>2</sup>–18<sup>5</sup> of this Act is the Estonian Information System Authority.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para19lg2">
					<loigeNr id="83580f8a-636d-4a7f-8f02-7a9ec5eb66ec">2</loigeNr>
					<kuvatavNr id="8a61ab4b-e095-41a2-a4c5-229ad53aee93"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="5827bf33-2cf3-4232-9f7f-62f9d3ce8bdb">
						<tavatekst id="1fb73de0-2fc8-4630-a25b-fd6432c64f69">If a misdemeanour provided in §§ 18<sup>2</sup>–18<sup>5</sup> of this Act is related to a violation of the requirements for the processing of personal data, the Personal Data Protection Act is applied to the misdemeanour proceedings.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para19lg3">
					<loigeNr id="4d976379-d282-4613-99b8-cab9c1772249">3</loigeNr>
					<kuvatavNr id="d4018bdb-15ff-4460-b134-185516a2a4ee"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="3e9076f3-a567-4c3a-bd2d-f11d569ff0e8">
						<tavatekst id="ffa6cbfc-9f5d-46ba-bd40-9b0a7af80b9f">The body conducting extra-judicial proceedings pertaining to the misdemeanour provided in § 18<sup>1</sup> of this Act is the Consumer Protection and Technical Regulatory Authority.<reavahetus/>[RT I, 06.08.2022, 2 – entry into force 16.08.2022]</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para19lg4">
					<loigeNr id="6262741b-e553-4846-b790-d1c93549c343">4</loigeNr>
					<kuvatavNr id="7f5ab6f6-8c04-455f-9894-2b4d4cef7578"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="ac730132-98f3-405e-87ca-aa9a99afc87a">
						<tavatekst id="e79bcc20-dabe-41d6-8a11-176926483ed8">The limitation period for the misdemeanours provided in §§ 18<sup>2</sup>–18<sup>4</sup> of this Act is three years.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
		<peatykk id="cb5b1ce7-c07e-4f06-9ecc-aa57c268ff39">
			<peatykkNr id="2807cb4f-ca0f-4f4c-8967-e2d9b6c29f6e">6</peatykkNr>
			<kuvatavNr id="a51d6907-88cc-4926-9442-dd6c2f3910f6"><![CDATA[Chapter 6]]></kuvatavNr>
			<peatykkPealkiri id="e6f1e207-97f9-4742-aae2-2626ae8d3956">Implementing Provisions </peatykkPealkiri>
			<paragrahv id="para20">
				<paragrahvNr id="7da5ccf1-ce73-4562-9f2e-34dee6b18dee">20</paragrahvNr>
				<kuvatavNr id="bdde56b5-baf5-452d-b04c-5b23bd2eb8c1"><![CDATA[§ 20. ]]></kuvatavNr>
				<paragrahvPealkiri id="34f79e75-d85f-40e6-b399-4c603366e32b">Tasks of Estonian Information System Authority</paragrahvPealkiri>
				<loige id="para20lg1">
					<loigeNr id="87e4082b-2575-473a-a04e-fe1e060e28ee">1</loigeNr>
					<kuvatavNr id="5829c472-a0ed-4d04-8e52-7db517e9597c"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="c92c3cd3-7c11-4172-b507-4bb2080564d5">
						<tavatekst id="009b4e23-d404-4045-bc37-9014d9f448fa">The Estonian Information System Authority compiles the list specified in subsection 2 of § 3<sup>1</sup> of this Act within six months as of the entry into force of that subsection.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para20lg2">
					<loigeNr id="6b73e651-b860-459e-ae02-1250e0da78ef">2</loigeNr>
					<kuvatavNr id="accef068-ac7f-4c46-89fa-fc49beb7acbe"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="7ac472bf-d41e-41ac-94ce-fb42f0fb814b">
						<tavatekst id="15581944-ba27-4403-b2df-86539b68f01e">The Estonian Information System Authority forwards the information specified in subsections 5–7 of § 3<sup>1</sup> of this Act within six months as of the entry into force of those subsections.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para20lg3">
					<loigeNr id="6fecfb1c-c746-415d-a442-0b59152d603e">3</loigeNr>
					<kuvatavNr id="8c771833-9441-4be2-a771-1a2dff132e25"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="84942341-4a6c-4b49-9064-5749945a8b11">
						<tavatekst id="9c0ec271-df6a-4502-a7bb-31632a4b66fb">The Estonian Information System Authority forwards the first consolidated report pursuant to subsection 4<sup>1</sup> of § 12 of this Act within three months as of the entry into force of that subsection.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para21">
				<paragrahvNr id="d874be6d-6494-4cfb-bd1c-6219be121ded" kehtiv="0">21</paragrahvNr>
				<kuvatavNr id="747db6ec-133b-4357-8c9f-65812995bb77"><![CDATA[§ 21. ]]></kuvatavNr>
				<sisuTekst id="0c8602c6-2b3a-439f-bcbf-134b84de56f6">
					<tavatekst id="8fe2bb38-10aa-4b60-bd3f-4dab5c8c1c1e"> – </tavatekst>
				</sisuTekst>
			</paragrahv>
			<paragrahv id="para28">
				<paragrahvNr id="ed042ce6-4dc5-4d3b-95ca-abd0c0eb9ed8" kehtiv="0">28</paragrahvNr>
				<kuvatavNr id="d5bfced5-1c97-4169-990b-a858c50eab03"><![CDATA[§ 28. ]]></kuvatavNr>
				<sisuTekst id="2a55467c-06b9-4014-8ac2-a8c2c5434830">
					<tavatekst id="6c347431-b1ff-436b-934c-410215b94d41">[Provisions governing the amendment of other Acts are omitted from this translation.]</tavatekst>
				</sisuTekst>
			</paragrahv>
			<paragrahv id="para28b1">
				<paragrahvNr id="85b6bc00-f3ee-4915-89ff-551b88813d31" ylaIndeks="1">28</paragrahvNr>
				<kuvatavNr id="23b750c8-8236-4334-92f7-1e06918404e2"><![CDATA[§ 28<sup>1</sup>. ]]></kuvatavNr>
				<paragrahvPealkiri id="81b8dcd6-cb73-4c0a-ab41-496e1a893148">Bringing activities of service provider into conformity with this Act in connection with transposition of Directive (EU) 2022/2555 of European Parliament and of Council</paragrahvPealkiri>
				<loige id="para28b1lg1">
					<loigeNr id="d38d39e8-124e-40d0-913c-d1e8fc0553fe">1</loigeNr>
					<kuvatavNr id="0926c851-d5f6-40c6-9dfb-33713c3961aa"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="a5ac8bf9-c9ea-4b73-a5f5-76892f2b4dec">
						<tavatekst id="bd2470bc-c380-43cc-a8dc-f38cedd6fa2f">A service provider which, before the entry into force of subsection 1 of § 3<sup>1</sup> of this Act, met the characteristics of a service provider provided in this Act, is to fulfil the obligation provided in that subsection within three months as of the entry into force of that subsection.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para28b1lg2">
					<loigeNr id="c0ad214b-9d29-4d75-a645-93dfd3d8f21d">2</loigeNr>
					<kuvatavNr id="26ad142e-0362-4b36-bdcb-02507d99195f"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="c3963abf-1d4a-4d53-aeea-d0f20ff93483">
						<tavatekst id="6c51d4e0-1697-47bd-8b90-6f6da49de63c">A digital service provider which, before the entry into force of subsection 7 of § 4 of this Act, met the characteristics of a service provider provided in this Act, is to fulfil the obligations provided in subsections 1 and 10 of § 4 of this Act within three months as of the entry into force of subsection 7 of § 4 of this Act.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para28b1lg3">
					<loigeNr id="b9025bac-08a3-4159-b037-c2b4742aa365">3</loigeNr>
					<kuvatavNr id="84071cf2-8ca5-4e09-b6e6-2a0f4c394b5a"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="0da2caae-7223-478c-a3b5-3119adfce211">
						<tavatekst id="c14160b7-2227-43a6-9861-2678d91e6ccb">A service provider, including a digital service provider, which, before the entry into force of subsection 1 of § 3<sup>1</sup> of this Act, met the characteristics of a service provider provided in this Act, is to bring its activities into conformity with the requirements of this Act and the requirements established on the basis thereof within three years as of the entry into force of that subsection. The service provider is to fulfil the obligation provided in subsections 1 and 2 of this section within the time limits specified in those subsections.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para28b1lg4">
					<loigeNr id="61c3a937-9b24-4fc6-b7d1-a2841c9a1f82">4</loigeNr>
					<kuvatavNr id="cfd85d5e-bab3-4201-89b7-f04448059669"><![CDATA[(4)]]></kuvatavNr>
					<sisuTekst id="2bb1b56d-2e6f-43bb-bc56-f3c857840681">
						<tavatekst id="0bb9d324-7b6c-42bd-aac9-5da0312eb22d">A provider of a vital service which became, for the first time, subject to the obligation to comply with this Act after 18 October 2024 and which, before the entry into force of subsection 1 of § 3<sup>1</sup> of this Act, met the characteristics of a service provider provided in this Act, is to bring its activities into conformity with the requirements of this Act and the requirements established on the basis thereof within the time limit determined in accordance with the rules provided in clause 3 of subsection 1<sup>3</sup> of § 38 of the Emergency Act. A provider of a vital service is to fulfil the obligation provided in subsections 1 and 2 of this section within the time limits specified in those subsections.<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
			<paragrahv id="para29">
				<paragrahvNr id="8753a002-c0d4-4cae-a68a-3d2dffce4dcc">29</paragrahvNr>
				<kuvatavNr id="2efbdb22-fe1e-45eb-9e69-3e44445efa86"><![CDATA[§ 29. ]]></kuvatavNr>
				<paragrahvPealkiri id="a8fbaaca-bebf-4805-b868-8a1e23c8637e">Entry into force of Act</paragrahvPealkiri>
				<loige id="para29lg1">
					<loigeNr id="236421e9-8786-4017-81c6-922b1399f667">1</loigeNr>
					<kuvatavNr id="76fef70f-5e5a-4a89-9245-9f77c998faaf"><![CDATA[(1)]]></kuvatavNr>
					<sisuTekst id="e1e4c7ed-87f9-4e7e-9bd0-28b73bea1a9f">
						<tavatekst id="29954f91-d50e-4577-9d31-d3a3444a82fe">This Act enters into force on the day following its publication in <i>Riigi Teataja</i>.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para29lg2">
					<loigeNr id="ef12308c-d21f-4096-8a70-dc8c95293633">2</loigeNr>
					<kuvatavNr id="b1cfcc86-a9ab-44ce-ae2b-fce8b59cce3a"><![CDATA[(2)]]></kuvatavNr>
					<sisuTekst id="8d280845-ae7b-4e81-bb44-b3f42a174699">
						<tavatekst id="2e985075-90c0-4e76-a737-a4625cda962e">Clause 8 of subsection 1 of § 3, subsection 3 of § 3, § 9 and clause 3 of § 23 of this Act enter into force on 1 January 2020.</tavatekst>
					</sisuTekst>
				</loige>
				<loige id="para29lg3">
					<loigeNr id="7dd3d6fa-ab1e-489d-9445-f5f2b1d3e964">3</loigeNr>
					<kuvatavNr id="abc3595c-02e4-459b-888a-95db0d10a62b"><![CDATA[(3)]]></kuvatavNr>
					<sisuTekst id="59a51327-fe15-4d19-baa4-b9580599fffa">
						<tavatekst id="1bcf8426-5305-4f28-aabf-85c55dc08a81">Clauses 7 and 10 of subsection 1 of § 3, § 21 and clauses 1 and 5 of § 28 of this Act enter into force on 1 January 2022.</tavatekst>
					</sisuTekst>
				</loige>
			</paragrahv>
		</peatykk>
	</sisu>
	<normtehnmarkus id="8872b516-4cfa-41c2-a67f-55f851dc5504" kuuluvus="04724735-693d-4919-a796-cf162ff6e76b">
		<normtehnmarkusNr id="cac73e14-ffeb-460e-9c9f-382abdb900e9">1</normtehnmarkusNr>
		<normtehnmarkusTekst id="66ef164b-5659-47e4-b2a2-6f1b095869ed"> Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, pp 80–152).<reavahetus/>[RT I, 30.12.2025, 4 – entry into force 01.01.2026]</normtehnmarkusTekst>
	</normtehnmarkus>
</oigusakt>