Collect
State the purpose, minimum fields, audience, notice, choice, and sensitive-data boundaries.
Privacy and data
GDPR, Estonian data-protection law, tracking, processors, transfers, retention, rights, security, and public-sector rules should be mapped to the actual service.
State the purpose, minimum fields, audience, notice, choice, and sensitive-data boundaries.
Name ownership, access roles, processors, AI use, automated decisions, and data-quality checks.
List hosting locations, vendors, transfers, subprocessors, backups, and remote access.
Set retention, deletion, account closure, legal holds, audit evidence, and recovery.
Assign rights requests, security events, breach decisions, escalation, and communications.
The Estonia microsite has its own GA4 property. That separation improves reporting; it does not remove any notice or consent duty that applies to the visitor. Advertising or profiling tags require a separate decision.
Next step
The clearest scope starts with the actual Estonia operation: people, access, content, transactions, deadlines, support, and acceptance.