FFFaith Forge LabsEstonia delivery deskPlan a project

Privacy and data

Follow the Estonia data from collection to deletion.

GDPR, Estonian data-protection law, tracking, processors, transfers, retention, rights, security, and public-sector rules should be mapped to the actual service.

01

Collect

State the purpose, minimum fields, audience, notice, choice, and sensitive-data boundaries.

02

Use

Name ownership, access roles, processors, AI use, automated decisions, and data-quality checks.

03

Move

List hosting locations, vendors, transfers, subprocessors, backups, and remote access.

04

Keep

Set retention, deletion, account closure, legal holds, audit evidence, and recovery.

05

Respond

Assign rights requests, security events, breach decisions, escalation, and communications.

Analytics follows the same consent analysis.

The Estonia microsite has its own GA4 property. That separation improves reporting; it does not remove any notice or consent duty that applies to the visitor. Advertising or profiling tags require a separate decision.

Next step

Turn the Estonia context into a workable brief.

The clearest scope starts with the actual Estonia operation: people, access, content, transactions, deadlines, support, and acceptance.

Use the project briefEmail Faith Forge Labs