LegalWise

Riigisaladuse ja salastatud välisteabe kaitse kord (RSVKK)

действуетс 02.02.2026· RT I, 22.01.2026, 7· Vabariigi Valitsus

Официальный перевод на английский: Procedure for Protection of State Secrets and Classified Information of Foreign States · RT V, 09.07.2025, 1

Официальный перевод на английский язык опубликован в Riigi Teataja для информации. Юридическую силу имеет только эстонский текст.

Перевод сделан с редакции, действовавшей с 01.01.2025, а не с действующей. Нормы, эстонский текст которых с тех пор изменился, отмечены. Действует эстонский текст.

Перевод в Riigi Teataja ↗
Содержание

Нажмите на точку перед параграфом, частью или пунктом: точная ссылка, ссылка на место, объяснение, история редакций, судебная практика и заметки.

1. peatükk ÜLDSÄTTED

§ 1. Määruse reguleerimisala

Käesoleva määrusega kehtestatakse riigisaladuse ja salastatud välisteabe kaitse kord ning riigisaladuseks oleva teabe alaliigid, teabe alaliigi salastamistase ja -tähtaeg.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 1. Scope of application of Regulation

This Regulation establishes the procedure for the protection of state secrets and foreign classified information, and the subcategories of information classified as a state secret, the levels and terms of classification of subcategories of information.

§ 2. Mõisted

Käesolevas määruses kasutatakse mõisteid järgmises tähenduses:

salastatud teave – riigisaladus või salastatud välisteave;

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

avalik ruum – ala, mis ei ole turva- ega administratiivala;

salastamisandmete parandamine – õigusliku aluseta riigisaladusena töödeldava teabe salastatuse kustutamine; valel tasemel, valel õiguslikul alusel või vale tähtajaga salastatud riigisaladuse taseme, õigusliku aluse või tähtaja muutmine;

avatud hoiuala – turvaala, kus ei pea kasutama seifi ega lukustatavat kappi või sahtlit;

kuller – isik, kes veab salastatud teabekandjat;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

rahvusvaheline külastustaotlus – rahvusvahelise külastuse puhul vastuvõtva riigi asjaomasele asutusele esitatav taotlus, mis hõlmab juurdepääsu teise riigi või rahvusvahelise organisatsiooni salastatud teabele, kui see on välislepinguga ette nähtud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Эстонский текст этой нормы изменился после переведённой редакции (01.01.2025): перевод не соответствует действующему тексту.

§ 2. Definitions

In this Regulation, the following definitions are used:

1) classified information – state secrets or foreign classified information;

3) administrative area – an area in which the processing of state secrets or foreign classified information and the classified media containing such information classified at the ‘restricted’ level is permitted;

4) public area – an area which is not a security or administrative area;

5) correction of classification data – declassification of information which has been processed as state secret without a legal basis; modification of the level, legal basis or term of state secret that has been classified at the incorrect level, on an incorrect legal basis or for an incorrect term;

6) open storage area – a security area where the use of safes or lockable cabinets or drawers is not required;

7) courier – a person who carries a classified medium.

8) international visit request – in the case of an international visit, a request made to the relevant authority of the host State for access to classified information of another State or international organisation, in case it is prescribed by an international agreement.

§ 2¹. Riigi julgeoleku volitatud esindaja

Riigi julgeoleku volitatud esindaja on Välisluureameti struktuuriüksus.

[RT I, 22.11.2016, 7 – вступ. в силу 01.01.2017]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 2¹. Estonian National Security Authority

The Estonian National Security Authority is a structural entity of the Estonian Foreign Intelligence Service.

§ 3. Ministeeriumi kantsleri volitamine

Minister võib ministeeriumi kantslerit volitada tegema kõiki toiminguid ja otsuseid, mida minister saab käesoleva korra kohaselt teha asutuse juhina.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 3. Authorisation of secretary general of ministry

A minister may authorise the secretary general of the ministry to perform all acts and take all decisions which the minister is authorised to perform as the head of the authority in accordance with the current procedure.

2. peatükk RIIGISALADUSE ALALIIGID

§ 4. Välissuhete riigisaladuse alaliigid

Välissuhtlemisasutuse loodud rahvusvahelisi suhteid käsitleva sellise teabe ja välissuhtlemisasutuse loodud sellise teabe osas, mille avalikuks tulek kahjustaks oluliselt Eesti Vabariigi välissuhtlemist, on riigisaladuseks:

välissuhtlemisasutuse töötaja või esindaja rahvusvahelisel kohtumisel saadud või kohtumist käsitlev teave, mille avalikustamine võib oluliselt kahjustada riigi julgeolekut. Selline teave salastatakse salajasel tasemel 50 aastaks;

välissuhtlemisasutuse töötaja või esindaja rahvusvahelisel kohtumisel saadud või kohtumist käsitlev teave, mille avalikustamine võib kahjustada riigi julgeolekut või oluliselt kahjustada välissuhtlemist. Selline teave salastatakse piiratud tasemel kohtumisel osalenud poolte kokkulepitud tähtpäeva või sündmuse saabumiseni, kuid mitte kauemaks kui 50 aastaks;

välissuhtlemisasutuse loodud teave rahvusvaheliste läbirääkimiste või kohtumiste ettevalmistamise ja läbiviimise kohta, mille avalikuks tulek enne läbirääkimiste või kohtumise toimumist võib kahjustada riigi julgeolekut või oluliselt kahjustada välissuhtlemist. Selline teave salastatakse piiratud tasemel kuni kohtumise toimumiseni või 50 aastaks, kui teabe avalikustamine pärast kohtumist või kohtumise ärajäämise korral kahjustaks riigi julgeolekut või oluliselt kahjustaks välissuhtlemist;

rahvusvaheliste visiitide või tseremooniate (selles punktis edaspidi üritus) ettevalmistamist või läbiviimist kajastav teave, välja arvatud juhul, kui selle avalikuks tulek ei kahjusta riigi julgeolekut ega kahjusta oluliselt välissuhtlemist. Selline teave salastatakse piiratud tasemel kuni ürituse toimumiseni või 50 aastaks, kui teabe avalikustamine pärast üritust või ürituse ärajäämise korral kahjustaks riigi julgeolekut või oluliselt kahjustaks välissuhtlemist;

rahvusvahelisel kohtumisel saadud või kohtumist kajastav välissuhtlemisasutuse loodud teave, mida kaitstakse avalikuks tuleku eest rahvusvaheliste tavade kohaselt või mille kaitsmises on kohtumisel või muul üritusel osalejate vahel kokku lepitud. Selline teave salastatakse osalejate kokkuleppel või rahvusvahelise tava kohaselt määratud tasemel ja tähtajaks, kuid mitte kõrgemal kui salajasel tasemel ja mitte kauemaks kui 50 aastaks;

välissuhtlemisasutuse loodud teave, mis käsitleb rahvusvahelisi suhteid, välisriiki või rahvusvahelist institutsiooni või nende esindajat, kui teabe sisu, selle edastamise viisi või allika avalikustamine kahjustaks riigi julgeolekut või kahjustaks oluliselt välissuhtlemist. Selline teave salastatakse piiratud tasemel 50 aastaks;

välissuhtlemisasutuse loodud teave, mis käsitleb rahvusvahelisi suhteid, välisriiki või rahvusvahelist institutsiooni või nende esindajat, kui teabe sisu, selle edastamise viisi või allika avalikustamine kahjustaks oluliselt riigi julgeolekut. Selline teave salastatakse salajasel tasemel 50 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Strateegilise kauba sisseveo, väljaveo, transiidi, sõjalise kaubaga seotud teenuse osutamise ja strateegilise kauba lõppkasutuse kohta Välisministeeriumi juures tegutseva strateegilise kauba komisjoni kogutud ja koostatud teabe osas on riigisaladuseks:

strateegilise kauba komisjoni ülesannete täitmiseks kogutud teave strateegilise kauba sisseveo, väljaveo, transiidi, sõjalise kaubaga seotud teenuse osutamise ja strateegilise kauba lõppkasutuse kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

strateegilise kauba komisjoni ülesannete täitmiseks koostatud teave strateegilise kauba sisseveo, väljaveo, transiidi, sõjalise kaubaga seotud teenuse osutamise ja strateegilise kauba lõppkasutuse kohta, milles analüüsitakse strateegilise kauba levikut ja sellega seotud ohtu julgeolekule. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

strateegilise kauba komisjoni koostatud teave sõjalise kauba, välja arvatud massihävitusrelvadega seotud materjalide, rajatiste ja seadmete, sisseveo- või väljaveolitsentsi, transiidiloa või lõppkasutuse järelevalve dokumendi väljastamisest keeldumise kohta; samuti teave sellist keeldumist arutanud strateegilise kauba komisjoni koosolekul käsitletu kohta. See teave salastatakse piiratud tasemel 50 aastaks, välja arvatud juhul, kui selle avalikuks tulek ei kahjusta riigi julgeolekut ega kahjusta oluliselt välissuhtlemist;

strateegilise kauba komisjoni edastatav teave rahvusvahelistele kontrollsüsteemidele, välisriikidele ja Euroopa Liidule, mida kaitstakse avalikuks tuleku eest rahvusvaheliste tavade kohaselt või mille kaitsmises on kohtumisel või muul üritusel osalejate vahel kokku lepitud. Selline teave salastatakse salajasel tasemel 50 aastaks, välja arvatud juhul, kui osalejate kokkuleppel või rahvusvahelise tava kohaselt on määratud muu salastatuse tase või salastamistähtaeg.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 4. Subcategories of state secrets related to foreign relations

(1) With regard to information related to international relations created by bodies conducting foreign relations and such information created by bodies conducting foreign relations, the disclosure of which would significantly damage the foreign relations of the Republic of Estonia, the following is a state secret:

1) information received by an employee or representative of a foreign relations institution during an international meeting or information concerning such meeting, the disclosure of which may significantly damage national security. Such information is classified as ‘secret’ for 50 years;

2) information received by an employee or representative of a foreign relations institution during an international meeting or information concerning such meeting, the disclosure of which may damage national security or significantly damage foreign relations. Such information is classified as ‘restricted’ until the arrival of the date or event agreed upon by the parties participating in the meeting but not for longer than for 50 years;

3) information created by a foreign relations institution concerning the preparation for and conduct of international negotiations or meetings, the disclosure of which before the holding of the negotiations or meetings may damage national security or significantly damage foreign relations. Such information is classified as ‘restricted’ until the holding of the meeting or for 50 years in case the disclosure of information after the meeting, or in the case of cancellation of the meeting, would damage national security or significantly damage foreign relations;

4) information concerning the preparation or conduct of international visits or ceremonies (hereinafter in this clause event) unless the disclosure of such information damages national security or significantly damages foreign relations. Such information is classified as ‘restricted’ until the event takes place or for 50 years in case the disclosure of the information after the event or in the case of cancellation of the event would damage national security or significantly damage foreign relations;

5) information received during an international meeting or information concerning such meeting created by a foreign relations institution, which is subject to protection against disclosure according to international practices, or whose protection has been agreed upon by the participants in the meeting or another event. Such information is classified at the level and for the term determined on an agreement between the participants or pursuant to international practices, but not at a level of classification higher than ‘secret’ and not for longer than for 50 years;

6) information created by a foreign relations institution, which concerns international relations, a foreign state or international organisation or their representative in case the disclosure of the contents of information, the manner of transmission or the source of information would damage national security or significantly damage foreign relations. Such information is classified as ‘restricted’ for 50 years.

(2) With regard to information collected and prepared by the Strategic Goods Commission operating at the Ministry of Foreign Affairs concerning the import, export and transit of strategic goods, provision of services related to military goods and the end use of strategic goods, the following is a state secret:

1) information about the import, export and transit of strategic goods, the provision of services related to military goods and the end-use of strategic goods collected by the Strategic Goods Commission, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

2) information about the import, export and transit of strategic goods, the provision of services related to military goods and the end-use of strategic goods collected by the Strategic Goods Commission, in which analyses are made of the dissemination of strategic goods and the related danger to security. Such information is classified as ‘confidential’ for 30 years;

3) information prepared by the Strategic Goods Commission concerning refusal to issue an import or export licence, transit permit or document on supervision of the end-use of military goods, except materials, construction works and equipment related to weapons of mass destruction, as well as information concerning the contents of the meeting of the Strategic Goods Commission which discussed such refusal. Such information is classified as ‘restricted’ for 50 years, except in the case the disclosure of such information does not damage national security or significantly damage foreign relations;

4) the information communicated by the Strategic Goods Commission to international control systems, foreign states and the European Union, which is protected from disclosure in accordance with international practice or the protection of which has been agreed between the participants in a meeting or other event. Such information is classified as ‘confidential’ for a period of 50 years, unless a different level of classification or a longer period of classification has been agreed by the participants or in accordance with international practice.

§ 5. Riigikaitse riigisaladuse alaliigid

Riigikaitse ettevalmistamist, juhtimist ja tegevust käsitleva teabe osas on riigisaladuseks:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

Kaitseväe sõjalise riigikaitse riigi ulatuses operatsiooniplaanimist ja operatsioonijuhtimist kajastav teave. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe sõjalise riigikaitse riigi territoriaalsel jaotusel põhinevat operatsiooniplaanimist ja operatsioonijuhtimist kajastav teave. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe väeliigi, väejuhatuse, brigaadi ja Kaitseväe korralduse seaduse § 37 lõike 1 punktides 1, 2 ja 5 ning lõikes 2 nimetatud viisil teavet koguva kaitseväeluure ülesannet või erioperatsioonide korraldamise ülesannet täitva üksuse operatsiooniplaanimist ja operatsioonijuhtimist kajastav teave. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe sõjaaja üksuse operatsiooniplaanimist ja operatsioonijuhtimist kajastav teave, mida ei salastata punktide 3–4 alusel. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Kaitseväe sõjalisel operatsioonil osalemist kajastav teave, mille avalikuks tulek võib ohustada operatsiooni korraldamist või kahjustada osaleva üksuse julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks sõjalise operatsiooni lõppemisest arvates;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

sõjaajal kasutatava elektroonilise side võrgu tehniline teave ja tööparameetrid, mille avalikuks tulek kahjustaks Eesti Vabariigi julgeolekut. See teave salastatakse § 22 lõike 1 punkti 17 alusel kehtestatud korras salajasel või madalamal tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe mereseiresüsteemide andmeedastusseadmete parameetrid ja tegevusvõime. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

Kaitseväe sõjalaevade magnet- ja akustiliste väljade mõõtmise tulemused. See teave salastatakse salajasel tasemel 10 aastaks;

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Kaitseväe jõu kasutamise kord, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Kaitseväe erioperatsioonide korraldamise ülesannet täitva alaliselt tegutseva struktuuriüksuse ning sõjaaja üksuse, välja arvatud üksuse ülema ametikoht, ja nende allüksuse koosseis ja komplekteeritus, ülesandeid ja teenistujate ülesandeid, eelarve kulude liigendust, eelarve täitmise aruandlust, eelarve planeerimist ja investeeringuid kajastav teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teave Kaitseväe erioperatsioone korraldava struktuuriüksuse ülesande täitmisel kasutatavate meetodite ja vahendite kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teave küberoperatsioonide korraldamiseks kasutatavate meetodite ja vahendite kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

riigikaitse ühtseks planeerimiseks töödeldav riigikaitseülesannetega täidesaatva riigivõimu asutuse või asutuste tegevusi, võimeid ja vajadusi kajastav koondteave, välja arvatud teave, mille avalikuks tulek ei kahjusta riigi julgeolekut. See teave salastatakse salajasel tasemel kuni 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

riigikaitseülesandega täidesaatva riigivõimu asutuse riigikaitseks valmistumist, sealhulgas tegevusi, võimeid ja vajadusi kajastav teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel kuni 50 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Mobilisatsiooni ettevalmistamist ja läbiviimist käsitleva teabe osas on riigisaladuseks:

mobilisatsiooniregistrisse kantud andmed kogumis. See teave salastatakse salajasel tasemel 30 aastaks;

Утратил силу

[RT I, 28.06.2018, 6 – вступ. в силу 01.07.2018]

Утратил силу

[RT I, 28.06.2018, 6 – вступ. в силу 01.07.2018]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe sõjaaja üksuste lahinguvalmidust kajastavad koondandmed, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

ühe Kaitseväe sõjaaja üksuse lahinguvalmidust kajastavad koondandmed, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 20 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Mobilisatsiooni korraldamiseks vajalikku varu käsitleva teabe osas on riigisaladuseks teave mobilisatsiooni korraldamiseks vajaliku varu ja vahendite üldkoguste kohta. See teave salastatakse salajasel tasemel 30 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe ja Kaitseliidu sõjaväerelvi, lahingumoona ja laskemoona käsitleva teabe osas on riigisaladuseks:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe ja Kaitseliidu sõjaväerelvade, lahingumoona ja laskemoona koondandmeid ja -jaotust kajastav teave, välja arvatud teave, mille avaldamine on kohustuslik välislepingu alusel. See teave salastatakse salajasel tasemel 20 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

mereväe relvasüsteemide taktikalised andmed. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks.

[RT I, 27.08.2022, 1 – вступ. в силу 01.09.2022]

Kaitseväe radariteabe ja seiresüsteemidelt kogutud teabe osas on riigisaladuseks:

Утратил силу

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

õhuväe õhuseireradari võime parameetrid, mille avalikuks tulek võib kahjustada õhuseiret. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

õhuväe õhuseiresüsteemi koondparameetrid ja radarite võime parameetrid, mille avalikuks tulek võib kahjustada õhuseiret. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

radari elektroonilise sõjapidamise meetmete ja vahendite tehniline kirjeldus. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

radari elektroonilise sõjapidamise võime testi tulemused. See teave salastatakse salajasel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

radari kasutatavad töörežiimid, filtreeritud alad ja sihtmärgi kriteeriumid. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

radari tegevusseisund ja hooldusajad üldise kaitsevalmiduse ajal. See teave salastatakse piiratud tasemel üheks aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

radari tegevusseisund ja hooldusajad kõrgendatud kaitsevalmiduse, sõjaseisukorra, erakorralise seisukorra ja mobilisatsiooni ajal. See teave salastatakse salajasel tasemel üheks aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

radari ja seiresüsteemi kõrgendatud kaitsevalmiduse, sõjaseisukorra, erakorralise seisukorra ja mobilisatsiooni ajaks planeeritud asukoht täpsusega üle ühe sekundi. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave õhukaitsesüsteemi koodnimetuse rakendamise ja kindlale süsteemile määramise kohta. See teave salastatakse piiratud tasemel 10 aastaks. Õhukaitsesüsteemi koodnimetus ei ole riigisaladus;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

radari hoolduse ja analüüsi tulemused. See teave salastatakse piiratud tasemel viieks aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

sekundaarradari identifitseerimiskriteeriumide tuvastamist võimaldavad krüptoseadmed ja krüptovõtmed. See teave salastatakse salajasel tasemel 10 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

õhuseiresüsteemi kogutud ja töödeldud terviklik radariteave, mille avalikuks tulek võib kahjustada õhuseiresüsteemi. See teave salastatakse § 22 lõike 1 punkti 17 alusel kehtestatud korras salajasel või madalamal tasemel 15 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teave õhukaitsesüsteemi paiknemise kohta täpsusega üle ühe sekundi ning vastutus- ja jälgimisala kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

teave õhukaitsesüsteemi tegevusseisundi kohta üldise kaitsevalmiduse ajal. See teave salastatakse piiratud tasemel üheks aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave õhukaitsesüsteemi tegevusseisundi kohta kõrgendatud kaitsevalmiduse, sõjaseisukorra, erakorralise seisukorra ja mobilisatsiooni ajal. See teave salastatakse salajasel tasemel üheks aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

mereseirevahenditega kogutud ja analüüsitud teave. See teave salastatakse salajasel tasemel 10 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

teave mereseiresüsteemi merepildi tuvastus- ja analüüsivõime kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

teave konkreetsetes kasutustingimustes laevadele paigutatud mereseiresüsteemide seadistuse kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Riigikaitselisi leiutisi ja uuringuid ning nende tulemusi käsitleva teabe osas on riigisaladuseks riigikaitselisi leiutisi ja uuringuid käsitlev teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel või madalamal tasemel kuni 30 aastaks.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Sõjalise otstarbega asja omadusi, projekteerimist, valmistamist ja kohandamist käsitleva teabe puhul on riigisaladuseks teave, mis käsitleb riigi tellimusel loodava sõjalise otstarbega asja või selle osa omadusi, projekteerimist, valmistamist, parandamist, kohandamist või ümbertegemist, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel või madalamal tasemel kuni 30 aastaks.

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

Kaitseväeluurega tegeleva Kaitseväe struktuuriüksuse kogutud ja sünteesitud teabe osas on riigisaladuseks:

sideluure vahenditega kogutud teave või selle põhjal sünteesitud teave, mille põhjal on võimalik tuvastada kogumisviis. See teave salastatakse täiesti salajasel tasemel 50 aastaks;

elektroonilise luure vahenditega kogutud teave või selle põhjal sünteesitud teave. See teave salastatakse salajasel tasemel 30 aastaks;

varjatud jälgimise teel kogutud teave või selle põhjal sünteesitud teave. See teave salastatakse salajasel tasemel 30 aastaks;

inimluure kaudu kogutud teave või selle põhjal sünteesitud teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

julgeolekuluure teave või selle põhjal sünteesitud teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

punktides 3–3² nimetatud teave, kui selle avaldamisega kaasneks oht inimese elule või tervisele. See teave salastatakse täiesti salajasel tasemel 50 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave, mis kajastab riigi julgeolekut ähvardava ohu allikaid. See teave salastatakse konfidentsiaalsel tasemel 15 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave, mis kajastab välisriike, rahvusvahelisi organisatsioone, välismaiseid sõjalisi tegureid ja tegevust. See teave salastatakse piiratud tasemel 15 aastaks;

kaitseväeluuret teostava Kaitseväe struktuuriüksuse poolt koostatud ohuhinnangut käsitlev teave. See teave salastatakse salajasel tasemel 50 aastaks;

kaitseväeluuret teostava Kaitseväe struktuuriüksuse poolt julgeolekuasutuste korraldatud luure- ja vastuluureoperatsioonide käigus kogutud teave või selle alusel sünteesitud teave. See teave salastatakse salajasel tasemel 30 aastaks;

punktides 5 ja 6 nimetatud teave, mille lähteandmed on salastatud nendes punktides sätestatuga võrreldes kõrgemal tasemel või pikemaks tähtajaks. See teave salastatakse lähteandmete kõrgeimast salastatuse tasemest ja pikimast salastamistähtajast lähtudes;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

piltluure kaudu kogutud teave või selle põhjal sünteesitud teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 15 aastaks.

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

Kaitseväe korralduse seaduse § 37 lõike 1 punktides 1, 2 ja 5 ning lõikes 2 nimetatud viisil teavet koguva Kaitseväe struktuuriüksuse koosseisu, ülesandeid ja eelarve jaotust käsitleva teabe osas on riigisaladuseks:

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

alaliselt tegutseva struktuuriüksuse või sõjaaja üksuse või nende allüksuse ülesehitust, koosseisu, ameti- ja töökohti käsitlev teave, välja arvatud alaliselt tegutseva struktuuriüksuse või sõjaaja üksuse ülema ametikoht ja teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

alaliselt tegutseva struktuuriüksuse või sõjaaja üksuse või nende allüksuse ja teenistujate ülesandeid käsitlev teave, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

alaliselt tegutseva struktuuriüksuse või sõjaaja üksuse või nende allüksuse teenistujate koondandmed, samuti andmed kaitseväeluure värbamisstatistika ja sellega seotud ametikohtade komplekteerimise ning täituvuse kohta. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

alaliselt tegutseva struktuuriüksuse või sõjaaja üksuse või nende allüksuse eelarve kulude liigendus, eelarve täitmise aruandlus, eelarve planeerimist ja investeeringuid kajastav teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

«Kaitseväe korralduse seaduse» § 37 lõike 1 punktides 1 ja 2 ning lõikes 2 nimetatud viisil teavet koguva kaitseväeluuret teostava Kaitseväe struktuuriüksusepoolt teabe kogumist kajastava teabe, kaasa arvatud kogumiseks kasutatavate meetodite, vahendite ja jälgitavaid objekte käsitleva teabe osas on riigisaladuseks:

struktuuriüksuse poolt teabe varjatud kogumisel kasutatavad meetodid, taktika ja vahendid ning neid kajastav teave. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

signaalluure ja muude tehniliste luurevahendite võimeid käsitlev teave. See teave salastatakse salajasel tasemel 50 aastaks;

signaalluure ja muude tehniliste luurevahendite võimet tagavad süsteemid või vahendid. See teave salastatakse konfidentsiaalsel tasemel 20 aastaks;

teabe kogumise alustamiseks ja lõpetamiseks tehtud otsuseid käsitlev teave. See teave salastatakse salajasel tasemel 50 aastaks;

andmed Kaitseväe poolt „Kaitseväe korralduse seaduse“ alusel salajasele koostööle kaasatud isiku ja variisiku kohta. See teave salastatakse täiesti salajasel tasemel 75 aastaks. Salastatus kustub, kui isiku surmast on möödunud 20 aastat, kuid mitte varem kui 50 aastat teabe salastamisest arvates;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

andmed, millest nähtub Kaitseväe poolt teeseldud juriidilise isiku, tema struktuuriüksuse, organi või äriühingu filiaali seotus Kaitseväega. See teave salastatakse salajasel tasemel 50 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväeluurealast rahvusvahelist koostööd käsitleva teabe osas on riigisaladuseks:

teave välissuhtluse kohta, kui see ei sisalda käesoleva lõike punktides 2–4 nimetatud teavet või ei kahjusta riigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

teave koostöö kohta välisriigi ja rahvusvahelise organisatsiooniga, kui see ei sisalda käesoleva lõike punktides 3 ja 4 nimetatud teavet. See teave salastatakse konfidentsiaalsel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti. Teavet ei salastata, kui see on õiguspäraselt avalikustatud;

rahvusvahelise koostöö käigus varjatult kogutud teave ja selle teabe vahetamist kajastav teave. See teave salastatakse salajasel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti;

koos välisriigi politsei- või julgeolekuasutusega varjatult kogutud luure- ja vastuluure alane teave ja selle kogumist kajastav teave. See teave salastatakse täiesti salajasel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti.

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

Kaitseväe ja Kaitseliidu militaargeograafia valdkonda käsitleva teabe osas on riigisaladuseks:

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

riigi sõjalist kaitsmist ja selle ettevalmistamist toetav militaargeograafiline teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 15 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Эстонский текст этой нормы изменился после переведённой редакции (01.01.2025): перевод не соответствует действующему тексту.

§ 5. Subcategories of state secret of national defence

(1) With regard to information concerning the preparation, command and operation of national defence, the following is a state secret:

3) information reflecting the nationwide operations planning and command of the national military defence activities of the Defence Forces. Such information is classified as ‘secret’ for 50 years;

3¹) information reflecting the operations planning and command of the national military defence activities of the Defence Forces based on territorial division of the state. Such information is classified as ‘confidential’ for 30 years;

4) information reflecting the duties of an armed service, command, brigade of the Defence Forces and military intelligence collecting information in a manner specified in clauses 1, 2 and 5 of subsection 1 and subsection 2 of § 37 of the Defence Forces Organisation Act or information reflecting the operations planning and command of a unit performing the duty to organise special operations. Such information is classified as ‘confidential’ for 30 years;

5) information concerning operations planning and command of the wartime unit of the Defence Forces, which is not classified on the basis of clauses 3–4. Such information is classified as ‘restricted’ for 30 years;

10) information reflecting the participation in a military operation of the Defence Forces, the disclosure of which may endanger the organisation of the operation or damage the security of the participating unit. Such information is classified as ‘confidential’ for 10 years as of the end of the military operation;

13) technical information and operating parameters of electronic communications networks used in wartime, the disclosure of which would damage the security of the Republic of Estonia. Such information is classified as ‘secret’ or lower level for a period of 50 years in accordance with the procedure established on the basis of clause 17 of subsection 1 of § 22;

14) the parameters and operational capacity of the data transmission equipment of the maritime surveillance systems of the Defence Forces. Such information is classified as ‘confidential’ for 10 years;

15) the measurement results of the magnetic and acoustic fields of military vessels of the Defence Forces. Such information is classified as ‘secret’ for 10 years;

17) the procedure for the use of force by the Defence Forces, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘confidential’ for 10 years.

19) Information reflecting the composition and staffing of the permanent structural unit performing the duty to organise special operations of the Defence Forces as well as of the wartime unit, except the position of the commander of the unit, and of their subunit, functions and duties of the servants, breakdown of budgetary expenditure, budget execution reports, budget planning and investments, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

20) information concerning the methods and means used for execution of the duty of a structural unit organising special operations of the Defence Forces, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years.

21) information concerning the methods and means used to organise cyber operations, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

22) aggregate information processed for the purpose of coherent planning of national defence, reflecting the activities, capabilities and needs of an authority or authorities of executive power with national defence tasks, except information the disclosure of which would not damage national security. Such information is classified as ‘secret’ for up to 50 years;

23) information reflecting the preparation for national defence, including activities, capabilities and needs, of an authority of executive power with a national defence task, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for up to 50 years.

(2) With regard to information concerning the preparation and conduct of mobilisation, the state secret is:

1) the set of data entered in the state central register of mobilisation. Such information is classified as ‘secret’ for 30 years;

6) the aggregate data reflecting combat readiness of the wartime units of the Defence Forces, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 30 years.

7) the aggregate data reflecting combat readiness of one wartime unit of the Defence Forces, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘confidential’ for 20 years;

(3) With regard to information concerning the mobilisation stockpile, the information concerning the total quantities of the mobilisation stockpile and means is a state secret. Such information is classified as ‘secret’ for 30 years.

(4) As regards information concerning the military weapons, munition and ammunition of the Defence Forces and the National Defence League, the following is a state secret:

1) information concerning the aggregate data and breakdown of the military weapons, munition and ammunition of the Defence Forces and the National Defence League, except the information which is subject to disclosure based on an international agreement. Such information is classified as ‘secret’ for 20 years;

2) ;

3) tactical data of the weapon systems of the Navy. Such information is classified as ‘confidential’ for 10 years.

(5) As regards information collected by radars and surveillance systems of the Defence Forces, the following is a state secret:

2) capacity parameters of air surveillance radars of the Air Force, the disclosure of which may damage air surveillance. Such information is classified as ‘restricted’ for 30 years;

3) the aggregate parameters of the air surveillance system of the Air Force and capacity parameters of radars, the disclosure of which may damage air surveillance. Such information is classified as ‘confidential’ for 30 years;

4) technical specifications of electronic warfare measures and means of a radar. Such information is classified as ‘confidential’ for 30 years;

5) the results of the test on electronic warfare capability of a radar. Such information is classified as ‘secret’ for 30 years;

6) the operational regimes, filtered areas and target criteria used by radars. Such information is classified as ‘confidential’ for 30 years;

7) the operational status and times for scheduled maintenance of a radars during the general defence readiness. Such information is classified as ‘restricted’ for one year;

8) operational status and maintenance times of a radar during the general defence readiness, state of war, state of emergency and mobilisation. Such information is classified as ‘secret’ for one year;

9) the planned location of a radar and air surveillance system for the period of increased defence readiness, state of war, state of emergency and mobilisation with the accuracy of more than one second. Such information is classified as ‘confidential’ for 10 years;

10) information on the implementation of the code name of the air defence system and assignment to a specific system. Such information is classified as ‘restricted’ for 10 years. The code name of the air defence system is not a state secret;

11) results of the maintenance and analysis of a radar. Such information is classified as ‘restricted’ for five years;

12) crypto devices and cryptokeys enabling establishment of identification criteria of a secondary radar. Such information is classified as ‘secret’ for 10 years;

13) comprehensive radar data collected and processed by the air surveillance system, the disclosure of which may damage the air surveillance system. Such information is classified as ‘secret’ or lower level of classification for 15 years in accordance with the procedure established on the basis of clause 17 of subsection 1 of § 22;

14) information concerning the location of the air surveillance system with the accuracy of more than one second and concerning the responsibility and surveillance areas. Such information is classified as ‘confidential’ for 10 years;

15) information concerning the operational status of the air surveillance system during the general defence readiness. Such information is classified as ‘restricted’ for one year;

16) information concerning the operational status of the air surveillance system during the increased defence readiness, state of war, state of emergency and mobilisation. Such information is classified as ‘secret’ for one year;

17) information collected and analysed by means of marine surveillance equipment. Such information is classified as ‘secret’ for 10 years;

18) information concerning the capacity of marine surveillance system to identify and analyse a maritime picture. Such information is classified as ‘confidential’ for 10 years;

19) information concerning the settings of marine surveillance systems installed on ships under specific operating conditions. Such information is classified as ‘confidential’ for 10 years;

(6) With regard to information concerning inventions and research related to national defence and their outcome thereof, information concerning inventions and research related to national defence is deemed to be a state secret, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ or lower level of classification for up to 30 years.

(7) With regard to information collected and synthesised by a structural unit of the Defence Forces dealing with military intelligence, the following is a state secret:

1) information collected by means of communications intelligence or information synthesised on the basis thereof which allows establishing the method of collection. Such information is classified as ‘top secret’ for 50 years;

2) information collected by means of electronic intelligence or information synthesised on the basis thereof. Such information is classified as ‘secret’ for 30 years;

3) information collected by covert surveillance or information synthesised on the basis thereof. Such information is classified as ‘secret’ for 30 years;

3¹) information collected by human intelligence or information synthesised on the basis thereof, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

3²) security intelligence or information synthesised on the basis thereof, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

4) information specified in clauses 3–3² in case the disclosure thereof would endanger the life or health of a person. Such information is classified as ‘top secret’ for 50 years;

5) information which reflects the sources of threat to national security. Such information is classified as ‘confidential’ for 15 years;

6) information concerning foreign states, international organisations, foreign military factors and activities. Such information is classified as ‘restricted’ for 15 years;

7) information concerning the threat assessment prepared by a structural unit of the Defence Forces executing military intelligence. Such information is classified as ‘secret’ for 50 years;

8) information collected by a structural unit of the Defence Forces in the course of intelligence and counterintelligence operations organised by security authorities or information synthesised on the basis thereof. Such information is classified as ‘secret’ for 30 years;

9) information specified in clauses 5 and 6 the source data for which is classified at a higher level or for a longer period compared to the provisions of those clauses. Such information is classified based on the highest level and longest term of classification for source data;

10) information collected through image intelligence or information synthesised on the basis thereof, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 15 years.

(8) With regard to information related to the composition, tasks and breakdown of the budget of a structural unit of the Defence Forces, which collects information in a manner specified in clauses 1, 2 and 5 of subsection 1 and subsection 2 of § 37 of the Defence Forces Organisation Act, the following is a state secret:

1) information concerning the structure, composition of staff, posts and employment of a permanent structural unit or a wartime unit or their subunit, except the post of the commander of a permanent structural unit or a wartime unit and information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

2) information concerning the functions of a permanent structural unit or a wartime unit or their subunit and the staff, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

3) aggregate data on the staff of a permanent structural unit or a wartime unit or their subunit, as well as data on the recruitment statistics of military intelligence of the Defence Forces and the staffing and occupancy of posts related thereto. Such information is classified as ‘secret’ for 50 years;

4) the breakdown of budgetary expenditure of a permanent structural unit or a wartime unit or their subunit, budget execution reports, data reflecting budget planning and investments, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years.

(10) With regard to information reflecting the collection of information by a structural unit of the Defence Forces executing military intelligence, collecting information in a manner specified in clauses 1 and 2 of subsection 1 and subsection 2 of § 37 of the Defence Forces Organisation Act, including information concerning the methods and means used for collecting information and objects under surveillance the following is a state secret:

1) the methods, tactics and means used for covert collection of data by a structural unit and the information reflecting thereof. Such information is classified as ‘secret’ for 50 years;

2) information concerning the capacity of the signals intelligence and other technical means of intelligence. Such information is classified as ‘secret’ for 50 years;

3) systems or means ensuring the capacity of the signals intelligence or other technical means of intelligence. Such information is classified as ‘confidential’ for 20 years;

4) information concerning the decisions made to commence and terminate collection of information. Such information is classified as ‘secret’ for 50 years;

5) information with regard to a person and undercover agent involved in secret cooperation with the Defence Forces on the basis of the Defence Forces Organisation Act. Such information is classified as ‘top secret’ for 75 years. The classification expires after 20 years have passed since the death of the person but not earlier than 50 years since the classification of information;

6) information indicating to the connection with the Defence Forces of a legal person simulated by the Defence Forces, its structural unit, body or subsidiary of a company. Such information is classified as ‘secret’ for 50 years.

(11) With regard to information concerning the international cooperation in the area of military intelligence, the following is a state secret:

1) information concerning international relations in case it does not include information specified in clauses 2–4 of this subsection or does not damage national security. Such information is classified as ‘restricted’ for 30 years;

2) information concerning cooperation with a foreign state and international organisation in case it does not include information specified in clauses 3 and 4 of this subsection. Such information is classified as ‘confidential’ for 50 years unless otherwise agreed upon. The information is not classified in case it is disclosed lawfully;

3) information covertly collected in the course of international cooperation and information reflecting the exchange of such information. Such information is classified as ‘secret’ for 50 years unless otherwise agreed upon;

4) information in the area of intelligence and counterintelligence which was covertly collected together with the police or security authority of a foreign state and the information reflecting the collection thereof. Such information is classified as ‘top secret’ for 50 years unless otherwise agreed upon.

(12) Regarding the information concerning military geography of the Defence Forces and the National Defence League, the following is a state secret:

4) military geographic information supporting the military defence of the state and its preparation, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 15 years.

§ 6. Korrakaitse riigisaladuse alaliigid

Jälitusasutuste poolt jälitustegevuse käigus kogutud teabe ning teabe kogumisel kasutatud meetodeid, taktikat ja vahendeid käsitleva teabe osas on riigisaladuseks:

tunnistajakaitse teostamiseks jälitustegevuse käigus kogutud teave. See teave salastatakse salajasel tasemel 25 aastaks;

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

jälitusasutuse poolt „Karistusseadustiku“ 8., 15., 16. ja 22. peatükis sätestatud kuritegudes ning Kaitsepolitseiameti uurimisalluvuses olevates kuritegudes jälitustoiminguga kogutud teave, kui selle avalikuks tulek võib kahjustada Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 25 aastaks. Sellise teabe salastatus kustub selles ulatuses, mis on kantud kriminaaltoimikusse või mida tutvustatakse isikule, kelle suhtes jälitustoiming tehti, või isikule, kelle perekonna- või eraelu puutumatust jälitustoiminguga riivati;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

jälitusasutuse poolt jälitustegevuses salajasele koostööle kaasatud isikult saadud ja variisiku poolt kogutud teave. See teave salastatakse piiratud tasemel 50 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Politsei- ja Piirivalveameti poolt koostatud organiseeritud ja muu raske kuritegevuse ohuhinnangutes ning ülevaadetes kajastuv jälitustegevuse käigus kogutud teave. See teave salastatakse piiratud tasemel 50 aastaks;

[RT I 2009, 65, 448 – вступ. в силу 01.01.2010]

jälitustegevuses kasutatavaid meetodeid, taktikat ja vahendeid kajastav teave, välja arvatud teave, mis on tuletatav õiguspäraselt avaldatud jälitustoiminguga kogutud teabest. See teave salastatakse piiratud tasemel 25 aastaks;

teave jälitusasutuse poolt jälitustegevuses salajasele koostööle kaasatud isiku tasu, hüvitise ja neilt tasutud maksude ning neid kajastavate dokumentide kohta. See teave salastatakse piiratud tasemel 25 aastaks;

andmed jälitusasutuse poolt teeseldud isiku või organi kohta, mis võivad paljastada tema seotust jälitusasutusega. See teave salastatakse piiratud tasemel 25 aastaks.

Jälitusasutuste poolt jälitustegevuses salajasele koostööle kaasatud isiku ja variisiku kohta käivate andmete osas on riigisaladuseks andmed jälitusasutuse poolt jälitustegevuses salajasele koostööle kaasatud isiku ja variisiku identiteedi kohta. See teave salastatakse piiratud tasemel 75 aastaks. Salastatus kustub, kui isiku surmast on möödunud 20 aastat, kuid mitte varem kui 50 aastat teabe salastamisest arvates.

Andmed jälitusasutuste politseiagendi kohta on riigisaladus. See teave salastatakse piiratud tasemel 75 aastaks. Sellise teabe salastatus kustub selles ulatuses, mis on kantud kriminaaltoimikusse. Kriminaaltoimikusse kandmata teabe salastatus kustub, kui isiku surmast on möödunud 20 aastat, kuid mitte varem kui 50 aastat teabe salastamisest arvates.

Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse struktuuri, koosseisu ja ülesandeid kajastava teabe osas on riigisaladuseks Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse struktuuri, koosseisu ja selle ametikohtadel töötavaid isikuid ning nende ülesandeid kajastav teave Politsei- ja Piirivalveameti juhi käskkirjaga määratud ulatuses. See teave salastatakse salajasel tasemel 50 aastaks.

[RT I 2009, 65, 448 – вступ. в силу 01.01.2010]

Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse kasutuses olevat vara ja eelarve jaotust kajastava teabe osas on riigisaladuseks:

teave Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse poolt kasutatavate transpordivahendite kohta, kui selle avalikuks tulek ohustaks tunnistajakaitse kohaldamist või tunnistajakaitse struktuuriüksuse või kaitse alla võetud isiku turvalisust. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

teave Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse poolt kasutatava vara kohta, kui selle avalikuks tulek ohustaks tunnistajakaitse kohaldamist või tunnistajakaitse struktuuriüksuse või kaitse alla võetud isiku turvalisust. See teave salastatakse salajasel tasemel 25 aastaks;

Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse eelarve kulude liigendus ja eelarve täitmise aruandlus. See teave salastatakse salajasel tasemel 25 aastaks.

[RT I 2009, 65, 448 – вступ. в силу 01.01.2010]

Tunnistajakaitse kaitseabinõusid käsitleva teabe osas on riigisaladuseks:

tunnistajakaitse kaitseabinõude kohaldamise meetodeid ja taktikaid käsitlev teave. See teave salastatakse salajasel tasemel 50 aastaks;

„Tunnistajakaitse seaduse“ § 14 lõike 6 ja § 19 alusel määrusega kehtestatav tunnistajakaitse kaitselepingu vorm ning kaitsetoimiku pidamise ja säilitamise kord. See teave salastatakse piiratud tasemel 25 aastaks.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Konkreetse isiku suhtes tunnistajakaitse kaitseabinõude kohaldamist kajastava teabe osas on riigisaladuseks:

konkreetse isiku suhtes tunnistajakaitse kaitseabinõude kohaldamist kajastav teave, välja arvatud teave, mis kajastab üksnes tunnistajakaitse alla võtmise fakti. See teave salastatakse täiesti salajasel tasemel 75 aastaks. Salastatus kustub, kui tunnistajakaitse all olnud isiku surmast on möödunud 20 aastat, kuid mitte vähem kui 50 aastat teabe salastamisest arvates;

Politsei- ja Piirivalveameti tunnistajakaitse struktuuriüksuse eelarve kulude liigendus ja eelarve täitmise aruandlus, kui selles kajastuvad konkreetse isiku suhtes rakendatavad kaitseabinõud. See teave salastatakse täiesti salajasel tasemel 75 aastaks. Salastatus kustub, kui tunnistajakaitse all olnud isiku surmast on möödunud 20 aastat, kuid mitte vähem kui 50 aastat dokumendi salastamisest arvates.

[RT I 2009, 65, 448 – вступ. в силу 01.01.2010]

Riiklikus kriisireguleerimisplaanis erakorralise seisukorra ja sõjaseisukorra ajal tegutsemist käsitleva teabe osas on riigisaladuseks riiklikus kriisireguleerimisplaanis erakorralise seisukorra ja sõjaseisukorra ajal tegutsemist käsitlev teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse täiesti salajasel tasemel 50 aastaks. Salastatus kustub teabe avalikul kasutamisel erakorralise seisukorra või sõjaseisukorra ajal.

Утратил силу

[RT I, 27.09.2016, 5 – вступ. в силу 30.09.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Politsei- ja Piirivalveameti isikukaitse üksuse kaitseoperatsioonide läbiviimist käsitlev teave, sealhulgas meetodeid, taktikat ja vahendeid käsitlev teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 25 aastaks või kuni isikukaitse osutamise vajaduse äralangemiseni või isikukaitse osutamise lõppemiseni.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Politsei- ja Piirivalveameti eriüksuse relvastuse, laskemoona, erivahendite ja varustust käsitleva teabe osas on riigisaladuseks:

relvastuse, laskemoona, erivahendite ja muu varustuse koondandmeid, hoidmist ja jaotust kajastav teave. See teave salastatakse piiratud tasemel 25 aastaks;

teave eriüksuse relvastuse, laskemoona, erivahendite ja muu varustuse tehniliste andmete kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 25 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 6. Subcategories of state secret in area of law enforcement

(1) Regarding information collected by a surveillance agency during surveillance activities and information concerning the methods, tactics and means used for collection of such information, the following is a state secret:

1) information collected in the course of surveillance for the conduct of witness protection. Such information is classified as ‘secret’ for 25 years;

2¹) information collected by a surveillance agency by means of surveillance operations in criminal offences provided in Chapters 8, 15, 16 and 22 of the Penal Code and in criminal offences under the investigative jurisdiction of the Estonian Internal Security Service, in case its disclosure may damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 25 years. Such information is declassified to the extent that it is included in the criminal file or is communicated to the person who was under surveillance, or to the person whose private or family life has been violated by surveillance;

3) information obtained by the surveillance agency from a person involved in secret cooperation in a surveillance operation and collected by an undercover agent.

4) information collected in the course of surveillance activities, which is reflected in the threat assessments and reviews concerning organised crime and other serious crime prepared by the Police and Border Guard Board. Such information is classified as ‘restricted’ for 50 years;

5) information reflecting the methods, tactics and means used in surveillance activities, except information which can be derived from the information collected by surveillance acts, which has been disclosed lawfully. Such information is classified as ‘restricted’ for 25 years;

6) information concerning the remuneration to a person who has been recruited by a surveillance agency for covert cooperation in surveillance activities, compensation and taxes paid on such amounts, and the documents reflecting them. Such information is classified as ‘restricted’ for 25 years;

7) information concerning a person or body simulated by a surveillance agency, which may disclose the connection thereof to the surveillance agency. Such information is classified as ‘restricted’ for 25 years.

(2) With regard to information concerning a person who has been involved in covert cooperation in surveillance activities by a surveillance agency and undercover agents, the information concerning the identity of the person who has been involved in covert cooperation in surveillance activities by a surveillance agency and undercover agents is a state secret. Such information is classified as ‘restricted’ for 75 years. Classification expires when 20 years have passed since the death of such a person but not earlier than 50 years as of the classification of information.

(3) Information concerning a police agent of surveillance agencies is a state secret. Such information is classified as ‘restricted’ for 75 years. The classification of such information expires to the extent that it has been entered into a criminal file. Classification of information not entered in a criminal file expires when 20 years have passed as of the death of the person but not earlier than 50 years as of the classification of the information;

(4) Regarding information concerning the structure, composition of staff and tasks of the structural unit of the Police and Border Guard Board dealing with witness protection, information reflecting the structure and composition of staff of the structural unit of the Police and Border Guard Board dealing with witness protection and the persons occupying the posts in that unit and their duties is a state secret to the extent determined by a directive of the head of the Police and Border Guard Board. Such information is classified as ‘secret’ for 50 years.

(5) Regarding the property at the disposal of a structural unit of the Police and Border Guard Board dealing with witness protection and the breakdown of the budget, the following is a state secret:

1) information concerning the means of transport used by a structural unit of the Police and Border Guard Board dealing with witness protection in case disclosure of such information would endanger the application of witness protection or the safety of the structural unit dealing with witness protection or of a person placed under protection. Such information is classified as ‘confidential’ for 10 years;

2) information concerning the property used by a structural unit of the Police and Border Guard Board dealing with witness protection in case disclosure of such information would endanger the application of witness protection or the safety of the structural unit dealing with witness protection or a person placed under protection. Such information is classified as ‘secret’ for 25 years;

3) the breakdown of budget expenditure and reports on the execution of the budget of a structural unit of the Police and Border Guard Board dealing with witness protection.

Such information is classified as ‘secret’ for 25 years.

(6) Regarding information concerning witness protection measures the following is state secret:

1) information concerning the methods and tactics of application of witness protection measures. Such information is classified as ‘secret’ for 50 years;

2) format of the witness protection agreement established by a regulation on the basis of subsection 6 of § 14 and § 19 of the Witness Protection Act and the procedure for keeping and storing of the protection file. Such information is classified as ‘restricted’ for 25 years.

(7) Regarding the information concerning application of witness protection measures to a particular person, the following is a state secret:

1) information reflecting the application of witness protection measures to a particular person, except information which reflects only the fact of placing such person under witness protection. Such information is classified as ‘top secret’ for 75 years. Classification expires after 20 years have passed since the death of the person placed under witness protection but not earlier than 50 years as of the classification of information;

2) the breakdown of budgetary expenditure and reports on the execution of the budget of a structural unit of the Police and Border Guard Board dealing with witness protection, in case they reflect the protective measures applied with regard to a particular person. Such information is classified as ‘top secret’ for 75 years. Classification expires after 20 years have passed since the death of the person placed under witness protection but not earlier than 50 years as of the classification of the document.

(8) Regarding the information concerning activities during a state of emergency or state of war described in the national crisis management plan, the information concerning acting during a state of emergency and state of war described in the national crisis management plan, except information the disclosure of which does not damage the security of the Republic of Estonia, is a state secret. Such information is classified as ‘top secret’ for 50 years. Classification expires upon the public use of such information during a state of emergency or state of war.

(11) Information dealing with the conduct of defence operations by the personal protection unit of the Police and Border Guard Board, including information dealing with the methods, tactics and means, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 25 years or until the need for the provision of personal protection ceases to exist or the provision of personal protection terminates.

(12) Information concerning the armament, ammunition, special equipment and other equipment of the special unit of the Police and Border Guard Board is a state secret:

1) information reflecting the aggregate data, storage and breakdown of armament, ammunition, special equipment and other equipment. Such information is classified as ‘restricted’ for 25 years;

2) information on the technical data of the armament, ammunition, special equipment and other equipment of the special tactical unit of the Police and Border Guard Board, except for information the disclosure of which would not damage/damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 25 years.

§ 7. Julgeolekuasutuste riigisaladuse alaliigid

Julgeolekuasutuste rahvusvahelist koostööd kajastava teabe osas on riigisaladuseks:

julgeolekuasutuse koostatud teave julgeolekualase välissuhtluse kohta, kui see ei sisalda käesoleva lõike punktides 2–4 nimetatud teavet. See teave salastatakse piiratud tasemel 30 aastaks;

julgeolekuasutuse julgeolekualast koostööd välisriigi või rahvusvahelise organisatsiooniga kajastav teave, kui see ei hõlma käesoleva lõike punktides 3 ja 4 nimetatud teavet. See teave salastatakse konfidentsiaalsel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti. Seda teavet ei salastata, kui see on õiguspäraselt avalikustatud;

julgeolekuasutuse rahvusvahelise koostöö käigus edastatav varjatult kogutud teave ja selle teabe vahetamist kajastav teave. See teave salastatakse salajasel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti;

julgeolekuasutuse poolt koos välisriigi politsei- või julgeolekuasutusega varjatult kogutud teave ja selle kogumist kajastav või selle käigus vahetatav teave. See teave salastatakse täiesti salajasel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti.

Julgeolekuasutuse kasutatava vara ja julgeolekuasutuse eelarve jaotust kajastava teabe osas on riigisaladuseks:

teave julgeolekuasutuse kasutatava vara kohta, kui selle avalikuks tulek ohustaks julgeolekuasutuse ülesande täitmist või julgeolekuasutuse turvalisust. See teave salastatakse konfidentsiaalsel tasemel kuni 25 aastaks või kuni hoone või rajatise valdamise lõppemiseni;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

teave teabe varjatult kogumiseks kasutatavate tehniliste vahendite kohta, kui selle avalikuks tulek ohustaks julgeolekuasutuse ülesande täitmist. See teave salastatakse salajasel tasemel 50 aastaks;

julgeolekuasutuse eelarve kulude liigendus, eelarve täitmise aruandlus, eelarve planeering ja investeeringud. See teave salastatakse salajasel tasemel 50 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Hädaolukorra lahendamisel julgeolekuasutuse tegevust kajastava teabe osas on riigisaladuseks hädaolukorra lahendamisel julgeolekuasutuse tegevust kajastav teave, sealhulgas kasutatavad meetodid ja taktika ning hädaolukorra lahendamisel osalevate ametnike tegevusjuhised. See teave salastatakse konfidentsiaalsel tasemel 20 aastaks. Salastatus kustub teabe avalikul kasutamisel hädaolukorras.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Julgeolekuasutuse ülesannete täitmisel varjatult kogutud teabe ja selle kogumist kajastava teabe osas on riigisaladuseks:

«Julgeolekuasutuste seaduse» alusel varjatult kogutud ja kogutav teave ning töökorraldused selle teabe kogumiseks. See teave salastatakse salajasel tasemel 50 aastaks. Salastatus kustub, kui julgeolekuasutuse ülesannete täitmiseks on julgeolekuasutuse peadirektori otsusel vajalik teabe avalik kasutamine. Käesolevat punkti ei kohaldata elektroonilise side ettevõtja või isikuandmete töötleja seadmes automaatselt talletatavate logide kohta;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

punktis 1 nimetatud teave, kui selle avaldamisega kaasneks oht inimese elule või tervisele või täiesti salajasel tasemel salastatud teabe kaitstusele. See teave salastatakse täiesti salajasel tasemel 50 aastaks;

punktis 1 nimetatud teabe kogumise meetodid ja taktika. See teave salastatakse salajasel tasemel 50 aastaks;

signaalluure meetodeid ja allikaid kajastav teave. See teave salastatakse täiesti salajasel tasemel 50 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

«Julgeolekuasutuste seaduse» alusel teabe varjatud kogumise toimingute loetelusid sisaldav aruandlus, milles ei kajastu täiesti salajasel tasemel salastatav teave. See teave salastatakse salajasel tasemel 25 aastaks;

Vabariigi Valitsuse ja Vabariigi Valitsuse julgeolekukomisjoni poolt julgeolekuasutusele teabe kogumiseks antavad ülesanded. See teave salastatakse salajasel tasemel 25 aastaks;

Kaitsepolitseiameti poolt «Julgeolekuasutuste seaduse» alusel teabe varjatud kogumise käigus laekunud teave toimepandud või ettevalmistatavate kuritegude kohta, mis ei ole Kaitsepolitseiameti uurimisalluvuses, juhul kui selles ei avaldu teabe allikad, kogumise taktika või käesoleva lõike punktides 2–6 nimetatud teave. See teave salastatakse piiratud tasemel 25 aastaks.

Julgeolekuasutuse ülesannete täitmisel analüüsitud ja sünteesitud teabe osas on riigisaladuseks:

julgeolekuasutuse ülesannete täitmisel analüüsitud ja sünteesitud teave, mis kajastab välisriike, välismaiseid tegureid või tegevust. See teave salastatakse piiratud tasemel 50 aastaks;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

julgeolekuasutuse ülesannete täitmisel analüüsitud ja sünteesitud teave, mis kajastab riigisiseseid või välismaiseid ohuallikaid. See teave salastatakse konfidentsiaalsel tasemel 50 aastaks;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

julgeolekuasutuse poolt koostatud ohuhinnangud, välja arvatud käesoleva lõike punktis 3¹ nimetatud ohuhinnangud. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

julgeolekuasutuse poolt koostatud ohuhinnangud julgeolekuasutuse uurimisalluvuses olevate kuritegude kohta. See teave salastatakse piiratud tasemel 25 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

ürituse, objekti või isiku julgestamise eesmärgil julgeolekuasutuse poolt koostatud ohuhinnang. See teave salastatakse piiratud tasemel 15 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

punktides 1–4 nimetatud teave, mille lähteandmed on salastatud nendes punktides sätestatuga võrreldes kõrgemal tasemel või pikemaks tähtajaks. See teave salastatakse lähteandmete kõrgeimast salastatuse tasemest ja pikimast salastamistähtajast lähtudes;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

valitsusasutuse ettepanek või ülesanne julgeolekuasutusele analüüsida või sünteesida punktides 1–3 nimetatud teavet või koostada punktides 3¹ ja 4 nimetatud ohuhinnang, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse ettepanekust või ülesandest lähtudes vastavalt punktides 1–4 määratud tasemel ja tähtajaks.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Lõike 5 alusel ei salastata teavet, mis koostatakse eesmärgiga avalikkuse teavitamise teel ennetada ohtu või riigi huvide kahjustamist või teavitada avalikkust julgeolekuasutuse tegevusest. Samuti ei salastata teabe seda osa, mis kantakse kriminaaltoimikusse.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Julgeolekuasutuse struktuuriüksusi, koosseisu ja nende ülesandeid kajastava teabe osas on riigisaladuseks:

julgeolekuasutuse struktuur, välja arvatud struktuuriüksused, mis avaldatakse vastava julgeolekuasutuse põhimääruses. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

julgeolekuasutuse struktuuriüksuste ja teenistujate ülesanded, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

julgeolekuasutuse teenistujate koondandmed ja üksnes teabe varjatud kogumisega seonduvaid tööülesandeid täitvate teenistujate koosseis. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

Утратил силу

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

julgeolekuasutuse poolt tehnilise julgeoleku kontrolli käigus antud hinnangud ja tehtud analüüsid. See teave salastatakse piiratud tasemel 25 aastaks.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Andmed julgeolekuasutuse poolt salajasele koostööle kaasatud isiku ja salajase koosseisulise julgeolekuasutuse ametniku või töötaja kohta, välja arvatud § 6 lõikes 2 nimetatud teave, on riigisaladus. See teave salastatakse täiesti salajasel tasemel 75 aastaks. Salastatus kustub, kui isiku surmast on möödunud 20 aastat, kuid mitte varem kui 50 aastat teabe salastamisest arvates.

[RT I, 28.06.2017, 40 – вступ. в силу 01.07.2017]

Andmed isiku kohta, kes «Eestit okupeerinud riikide julgeolekuorganite või relvajõudude luure- või vastuluureorganite teenistuses olnud või nendega koostööd teinud isikute arvelevõtmise ja avalikustamise korra seaduse» § 5 lõike 2 punktis 1 sätestatud korras on Kaitsepolitseiametile esitanud isikliku ülestunnistuse julgeoleku- või luureorgani teenistuses olemise või sellega koostöö tegemise kohta, välja arvatud juhul, kui julgeoleku- või luureorgani teenistuses olnud või sellega koostööd teinud isik on eelnimetatud teenistuse või koostööga seonduvalt pannud toime õigusrikkumise, mis Eesti Vabariigis kehtiva õiguse kohaselt on karistatav esimese astme kuriteona, või on toime pannud kuriteo inimsuse vastu või sõjakuriteo ning õigusrikkumise või kuriteo toimepanemine selle isiku poolt on kohtulikult tõendatud jõustunud kohtulahendiga või kui julgeoleku- või luureorgani teenistuses oli või tegi sellega koostööd Vabariigi President või Riigikogu, Vabariigi Valitsuse või Riigikohtu liige, on riigisaladus. See teave salastatakse salajasel tasemel 50 aastaks. Salastatus kustub, kui isiku surmast on möödunud 20 aastat, kuid mitte varem kui 50 aastat teabe salastamisest arvates.

Julgeolekuasutuste tegevuse koordineerimist, nende koostööd Kaitseväega ja Vabariigi Valitsuse julgeolekukomisjoni tööd käsitleva teabe osas on riigisaladuseks:

Riigikantseleis julgeolekuasutuste töö koordineerimisega ja Vabariigi Valitsuse julgeolekukomisjoni töö korraldamisega seotud ametnike või Siseministeeriumis ja Kaitseministeeriumis julgeolekuasutuste töö suunamise ja koordineerimisega seotud ametnike ja töötajate koostatud teave julgeolekualase välissuhtluse kohta, kui see ei sisalda punktis 2 nimetatud teavet. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Riigikantseleis julgeolekuasutuste tööd koordineeriva ja Vabariigi Valitsuse julgeolekukomisjoni tööd korraldava struktuuriüksuse või Siseministeeriumis ja Kaitseministeeriumis julgeolekuasutuste tööd suunava ja koordineeriva struktuuriüksuse julgeolekualast koostööd välisriigi või rahvusvahelise organisatsiooniga kajastav teave. See teave salastatakse konfidentsiaalsel tasemel 50 aastaks, kui ei ole kokku lepitud teisiti. Seda teavet ei salastata, kui see on õiguspäraselt avalikustatud;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave Vabariigi Valitsuse julgeolekukomisjoni ja selle alakomisjoni istungitel käsitletavate teemade kohta, välja arvatud teave, mida Vabariigi Valitsuse julgeolekukomisjoni otsusega ei käsitata riigisaladusena või mis avalikustatakse eesmärgiga ennetada ohtu või riigi huvide kahjustamist. See teave salastatakse piiratud tasemel 25 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Riigikantseleis julgeolekuasutuste tööd koordineeriva ja Vabariigi Valitsuse julgeolekukomisjoni tööd korraldava struktuuriüksuse ja teenistujate või Siseministeeriumis ja Kaitseministeeriumis julgeolekuasutuste tööd suunava ja koordineeriva struktuuriüksuse ja teenistujate ülesanded, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 25 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Riigikantseleis julgeolekuasutuste tööd koordineeriva ja Vabariigi Valitsuse julgeolekukomisjoni tööd korraldava struktuuriüksuse poolt koostatud ohuhinnangud ja riigi julgeolekuteabe hanke ja analüüsi kava. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Riigikantseleis julgeolekuasutuste tööd koordineeriva ja Vabariigi Valitsuse julgeolekukomisjoni tööd korraldava struktuuriüksuse või Siseministeeriumis ja Kaitseministeeriumis julgeolekuasutuste tööd suunava ja koordineeriva struktuuriüksuse poolt julgeolekuteabe alusel analüüsitud ning koostatud teave. See teave salastatakse salajasel tasemel 50 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Siseministeeriumi ja Kaitseministeeriumi koostatud julgeolekuasutuse tegevuse suunamist ja koordineerimist kajastav teave, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse salajasel tasemel 25 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

julgeolekuasutuse teenistuslikku järelevalvet või auditeerimist kajastav teave, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 25 aastaks.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Lõike 9 punktides 3 ja 6–6² nimetatud teave, mille lähteandmed on salastatud nendes punktides sätestatuga võrreldes kõrgemal tasemel või pikemaks tähtajaks, salastatakse lähteandmete kõrgeimast salastatuse tasemest ja pikimast salastamistähtajast lähtudes.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Julgeolekuasutuse poolt teeseldud isikute ja organite ning kasutatavate variandmete kohta käiva teabe osas on riigisaladuseks teave, millest nähtub teeseldud isikute ja organite või kasutatavate variandmete seotus julgeolekuasutusega. See teave salastatakse salajasel tasemel 50 aastaks.

Julgeolekuasutuse dokumendiregistris sisalduv teave on riigisaladus. See teave salastatakse salajasel tasemel 25 aastaks või kõrgemal tasemel ja pikemaks tähtajaks, kui register sisaldab vastava salastatuse taseme ja tähtajaga teavet.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 7. Subcategories of state secret of security authorities

(1) With regard to information related to the international cooperation of security authorities, the following is a state secret:

1) information concerning foreign relations in the area of security, prepared by a security authority, unless it contains information specified in clauses 2–4 of this subsection. Such information is classified as ‘restricted’ for 30 years;

2) information concerning security cooperation between the security authority and a foreign state or international organisation unless it contains information specified in clauses 3 and 4 of this subsection. Such information is classified as ‘confidential’ for 50 years unless otherwise agreed. Such information is not classified in case it has been disclosed lawfully;

3) covertly collected information to be transmitted in the course of international cooperation by the security authority and information reflecting the exchange of such information. Such information is classified as ‘secret’ for 50 years unless otherwise agreed;

4) information collected covertly by the security authority together with a foreign police or security authority and information reflecting the collection of information or information exchanged in the course thereof. Such information is classified as ‘top secret’ for 50 years unless otherwise agreed.

(2) Regarding the information reflecting the property used by the security authority and breakdown of the budget of the security authority, the following is a state secret:

1) information concerning the property used by a security authority in case the disclosure of such information would endanger the compliance with the function or security of the security authority. Such information is classified as ‘confidential’ for up to 25 years or until the termination of the possession of the building or construction works;

2) information concerning the technical means used for the covert collection of information in case disclosure of such information would endanger the performance of the function of the security authority. Such information is classified as ‘secret’ for 50 years;

3) breakdown of budgetary expenditure, budget execution reports, budget planning and investments of the security authority. Such information is classified as ‘secret’ for 50 years.

(3) Regarding information reflecting the operation of a security authority upon resolving an emergency, the state secret is information reflecting the operation of the security authority upon resolving an emergency, including the methods and tactics used, and the code of conduct for officials participating in resolving the emergency. Such information is classified as ‘confidential’ for 20 years. Classification expires upon the public use of the information in an emergency.

(4) With regard to information covertly collected upon the performance of the tasks of a security authority and the information reflecting the collection thereof, the following is a state secret:

1) information which has been and is being covertly collected based on the Security Authorities Act, and the work organisation for collection of such information. Such information is classified as ‘secret’ for 50 years. Classification expires in case, according to a decision of the director general of the security authority, the public use of such information is necessary for the performance of the functions of the security authority. This clause does not apply to the logs automatically saved in the equipment of an electronic communications undertaking or a processor of personal data;

2) information specified in clause 1 in case the disclosure thereof would pose a threat to the life or health of a person or to the protection of information classified as ‘top secret’. Such information is classified as ‘top secret’ for 50 years;

3) methods and tactics of the collection of information specified in clause 1. Such information is classified as ‘secret’ for 50 years;

4) information reflecting the methods and sources of signals intelligence. Such information is classified as ‘top secret’ for 50 years;

5) reports containing the lists of acts of covert data collection based on the Security Authorities Act, which do not reflect information classified as ‘top secret’. Such information is classified as ‘secret’ for 25 years;

6) tasks for the collection of information assigned to the security authority by the Government of the Republic and the Security Committee of the Government of the Republic. Such information is classified as ‘secret’ for 25 years;

7) information that is received by the Estonian Internal Security Service during covert collection of information, based on the Security Authorities Act, concerning committed or prepared crimes which do not fall within the investigative jurisdiction of the Estonian Internal Security Service, provided that such information does not reveal the sources of information, the tactics of collection of information or the information specified in clauses 2–6 of this subsection. Such information is classified as ‘restricted’ for 25 years.

(5) With regard to information analysed and synthesised during performance of the functions of a security authority, the following is a state secret:

1) information analysed and synthesised during the performance of the functions of a security authority which concerns foreign states, foreign factors or activity. Such information is classified as ‘restricted’ for 50 years;

2) information analysed and synthesised during the performance of the functions of a security authority which reflects internal or foreign sources of danger. Such information is classified as ‘confidential’ for 50 years;

3) threat assessments prepared by a security authority, except threat assessments specified in clause 3¹ of this subsection. Such information is classified as ‘secret’ for 50 years;

3¹) threat assessments prepared by a security authority concerning the crimes within the investigative jurisdiction of the security authority. Such information is classified as ‘restricted’ for 25 years;

4) threat assessment prepared by a security authority with the aim to provide security protection to an event, object or a person. Such information is classified as ‘restricted’ for 15 years;

5) information specified in clauses 1–4, the source data of which is classified at a higher level or for a longer period than provided in these clauses. Such information is classified based on the highest level and longest term of classification for the source data;

7) proposal or task of a governmental authority to a security authority to analyse or synthesize information specified in clauses 1–3 or to prepare the threat assessment specified in clauses 3¹ and 4, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified based on the proposal or task at the level and for the term determined in clauses 1–4.

(5¹) On the basis of subsection 5 information, which is prepared with the aim to prevent threat or damage to the interests of the state or inform the public of the activities of the security authority, is not classified. Neither is classified part of the classified information which is entered in the criminal file.

(6) With regard to information reflecting structural units of the security authorities, composition of staff and their tasks, the following is a state secret:

1) the structure of a security authority, except the structural units which are published in the statutes of the corresponding security authority. Such information is classified as ‘secret’ for 50 years;

2) the tasks of structural units and staff of the security authority, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 50 years;

3) the aggregate data concerning the employees of the security authority and the composition of staff performing duties related solely to the covert collection of data. Such information is classified as ‘secret’ for 50 years;

5) assessments given and analyses made during the technical security check by the security authority. Such information is classified as ‘restricted’ for 25 years.

(7) Information concerning a person involved in covert cooperation by the security authority and an undercover official or employee of the security authority, except information specified in subsection 2 of § 6, is a state secret. Such information is classified as ‘top secret’ for 75 years. Classification expires when 20 years have passed since the death of the person but not earlier than 50 years as of the classification of information.

(8) Information concerning a person who has submitted a personal confession concerning service in security or intelligence organisations or cooperation with it to the Estonian Internal Security Service pursuant to the procedure provided in clause 1 of subsection 2 of § 5 of the Procedure for Registration and Disclosure of Persons who Have Served in or Co-operated with Security Organisations or Intelligence or Counterintelligence Organisations of Armed Forces of States which Have Occupied Estonia Act, except in the case the person who has served in security or intelligence organisations or cooperated with them, has committed an offence in relation to such service or cooperation which, according to the law in force in the Republic of Estonia, is punishable as a criminal offence of the first degree or has committed a crime against humanity or a war crime and the committing of an offence or crime by this person has been proved by the court with a judgment which has entry into force, or the person who was in service in the security or intelligence organisations or cooperated with it was the President of the Republic, a member of the Riigikogu, the Government of the Republic or the Supreme Court, is a state secret. Such information is classified as ‘secret’ for 50 years. Classification expires when 20 years have passed since the death of the person but not earlier than 50 years as of the classification of the information.

(9) With regard to information concerning the coordination of the activities of security authorities, their cooperation with the Defence Forces and the work of the Security Committee of the Government of the Republic, the following is a state secret:

1) information reflecting foreign relations in the area of security prepared by the officials of the Government Office conducting the coordination of work of the security authorities and the organisation of work of the Security Committee of the Government of the Republic or by the officials and employees related to organisation and coordination of work of the security authorities in the Ministry of the Interior and the Ministry of Defence unless it contains information specified in clause 2 of this subsection. Such information is classified as ‘restricted’ for 30 years;

2) information reflecting cooperation with a foreign state or international organisation in the area of security of a structural unit of the Government Office conducting the coordination of work of the security authorities and the organisation of work of the Security Committee of the Government of the Republic or a structural unit in the Ministry of the Interior and the Ministry of Defence executing the organisation and coordination of work of the security authorities. Such information is classified as ‘confidential’ for 50 years unless otherwise agreed. Such information is not classified in case it has been made public lawfully;

3) information concerning the topics discussed at the meetings of the Security Committee of the Government of the Republic and its subcommittee, except information which is not deemed a state secret by a decision of the Security Committee of the Government of the Republic or which is disclosed with the aim to prevent threat or damage to the interests of the state. Such information is classified as ‘restricted’ for 25 years;

4) the tasks of the structural unit and staff coordinating the work of security authorities in the Government Office and organising the work of the Security Committee of the Government of the Republic, or of the structural unit and staff guiding and coordinating the work of security authorities in the Ministry of the Interior and the Ministry of Defence, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 25 years;

5) threat assessments and a plan for the procurement and analysis of national security information prepared by a structural unit coordinating the work of security authorities in the Government Office and organising the work of the Security Committee of the Government of the Republic. Such information is classified as ‘secret’ for 50 years;

6) information analysed and prepared based on security information by a structural unit coordinating the work of the security authorities in the Government Office and the organising the work of the Security Committee of the Government of the Republic. Such information is classified as ‘secret’ for 50 years;

6¹) information reflecting the guidance and coordination of activities of a security authority prepared by the Ministry of the Interior and the Ministry of Defence, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘secret’ for 25 years;

6²) information reflecting the supervisory control or audit of a security authority, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 25 years;

(9¹) The information specified in clauses 3 and 6–6² of subsection 9 the source data of which is classified at a higher level or for a longer period compared to the provisions in these clauses. Such information is classified based on the highest level and longest term of classification for source data;

(10) With regard to information concerning the persons and bodies simulated by security authorities and covert data used, the information which demonstrates the connection with the security authority of the bodies simulated and covert data used is a state secret. Such information is classified as ‘secret’ for 50 years.

(11) Information available in the document register of the security authority is a state secret. Such information is classified as ‘secret’ or higher level for 25 years and for a longer term in case the register contains information with the appropriate classification level and term.

§ 8. Infrastruktuuri ja teabe kaitse riigisaladuse alaliigid

Vabariigi Presidendi Kantselei, Riigikantselei, julgeolekuasutuse, Kaitseministeeriumi, Kaitseväe, Kaitseliidu, Kaitseressursside Ameti, Riigi Infosüsteemi Ameti, Eesti Panga, Siseministeeriumi, Politsei- ja Piirivalveameti ja Välisministeeriumi, sealhulgas välisesinduste, ning nende valitsusasutuste hallatavate riigiasutuste valve-, häire-, side- ja infosüsteeme käsitleva teabe osas on riigisaladuseks:

[RT I, 22.11.2016, 7 – вступ. в силу 01.01.2017]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala elektroonilise läbipääsu- või valvesüsteemi koondteave ühe ehitise või maa-ala või selle tervikuna käsitatava osa ulatuses, mis sisaldab andmeid süsteemi moodustavate seadmete, sealhulgas keskseadmete asukoha, tüübi, nendevaheliste ühenduste ja teiste tehniliste näitajate kohta või andmeid valvealade või -tsoonide kohta või süsteemi üldist kirjeldust, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala elektroonilise läbipääsu- või valvesüsteemi toimimist ja efektiivsust kajastavad analüüsid ja hinnangud, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala elektroonilise läbipääsu- või valvesüsteemi koondteave ühe ehitise või maa-ala või selle tervikuna käsitatava osa ulatuses, mis sisaldab andmeid süsteemi kuuluvate lõppseadmete (andurid, kaamerad või muud seadmed) asukoha ja tüübi ning nendest moodustatavate valvealade ja -tsoonide või süsteemi seadistuse kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala elektroonilises läbipääsu- või valvesüsteemis töödeldav teave kogumis, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala automaatse tulekahjusignalisatsioonisüsteemi koondteave ühe ehitise või selle tervikuna käsitatava osa ulatuses, mis sisaldab andmeid süsteemi moodustavate seadmete asukoha, tüübi, nendevaheliste ühenduste ja teiste tehniliste näitajate kohta või süsteemi üldist kirjeldust, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse valduses oleva ehitise või maa-ala füüsiliste julgeolekumeetmete analüüsid ja hinnangud, mis kajastavad julgeolekumeetmete toimimist ja efektiivsust, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave Kaitseväes signaalluureks, õhuseireks, mereseireks, objektide turbeks ja valveks ning riigi sõjaliseks kaitsmiseks ja selle juhtimiseks püsivalt kasutatavate raadiosageduste kohta. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Kaitseministeeriumi, Kaitseväe, Kaitseliidu, Kaitseressursside Ameti ja teiste Kaitseministeeriumi valitsemisalas olevate töötlevate üksuste riigi sõjaliseks kaitsmiseks ja selle juhtimiseks kasutatavate sidevõrkude ja töötlussüsteemide koondteave, sealhulgas iga sidevõrgu ja töötlussüsteemi ülesehituse koondteave ja turvameetmeid käsitlev teave. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Kaitseministeeriumi, Kaitseväe, Kaitseliidu, Kaitseressursside Ameti ja teiste Kaitseministeeriumi valitsemisala töötlevate üksuste asutusesiseseks kasutamiseks mõeldud teabe töötlemiseks kasutatavate töötlussüsteemide, milles ei töödelda salastatud teavet, tehnilisi andmeid ja turvameetmeid kajastav teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel kuni töötlussüsteemi või selle osa kasutamise lõppemiseni, kuid mitte kauemaks kui 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

teave õhuväe õhuseire sidesüsteemis kasutatava krüptoseadme kirjelduse kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

teave õhuväe õhuseire sidesüsteemis kasutatava võtmeta krüptoseadme kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

teave õhuväe õhuseire sidesüsteemis kasutatava võtmega krüptoseadme kohta. See teave salastatakse salajasel tasemel 10 aastaks;

teave õhuväe õhuseire sidesüsteemis kasutatavate sidelinkide skeemide kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

teave õhuseiresüsteemide andmeedastusseadmete parameetrite ja tegevusvõime kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks;

käesoleva lõike sissejuhatavas osas nimetatud asutuse teave kaabelduse kohta ühe ehitise või maa-ala või selle tervikuna käsitatava osa ulatuses, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks või kuni võrgu võõrandamiseni või kasutamise lõppemiseni;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

käesoleva lõike sissejuhatavas osas nimetatud asutuse teave konfidentsiaalsel ja kõrgemal tasemel salastatud teabe töötlussüsteemi kaabelduse kohta ühe ehitise või maa-ala või selle tervikuna käsitatava osa ulatuses. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks või kuni võrgu võõrandamiseni või kasutamise lõppemiseni;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

välispiiride valvamiseks mõeldud seire- ja valvesüsteemide tehniline teave ja tööparameetrid, mis ei ole avalikest allikatest kättesaadav ja mille avalikuks tulek kahjustab sisejulgeoleku tagamist. See teave salastatakse piiratud tasemel 10 aastaks;

[RT I, 27.08.2022, 1 – вступ. в силу 01.01.2023]

välispiiride valvamiseks mõeldud seire- ja valvesüsteemide ülesehituse ja tehniliste parameetrite kohta käiv koondteave, mis sisaldab süsteemide üldist kirjeldust või andmeid süsteemi kuuluvate seadmete täpsete tehniliste näitajate kohta. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks või kasutamise lõppemiseni;

[RT I, 27.08.2022, 1 – вступ. в силу 01.01.2023]

välispiiride valvamiseks mõeldud seire- ja valvesüsteemide katvuspiirkondi kajastavate testide tulemused. See teave salastatakse piiratud tasemel 10 aastaks;

[RT I, 27.08.2022, 1 – вступ. в силу 01.01.2023]

välispiiride valvamiseks mõeldud andmeside detailset tehnilist ülesehitust või turbemeetodeid käsitlev teave kogumis. See teave salastatakse piiratud tasemel 10 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

operatiivraadioside detailset ülesehitust või turbemeetodeid käsitlev teave kogumis, välja arvatud võrgu ülesehituse koondnumbrid. See teave salastatakse piiratud tasemel 20 aastaks;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Riigi Infosüsteemi Ameti ning Justiits- ja Digiministeeriumi koostatud küberturvalisuse riskianalüüsid, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel kuni 20 aastaks;

[RT I, 29.12.2024, 1 – вступ. в силу 01.01.2025]

seire-, järelevalvetoimingute ja küberintsidentide analüüsi käigus kogutud teave põhiseadusliku institutsiooni, valitsusasutuse, selle hallatava riigiasutuse, elutähtsa teenuse osutaja ning Eestis paikneva ja Eesti poolt tagatava julgeolekuga rahvusvahelise organisatsiooni võrgu- ja infosüsteemi, mis ei ole salastatud teabe töötlussüsteem, turvanõrkuste ja rakendatavate turvameetmete kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel kuni võrgu- ja infosüsteemi kasutamise lõppemiseni, kuid mitte kauemaks kui 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

välispiiride valvamiseks mõeldud seire- ja valvesüsteemide juhtimissüsteemi ülesehitust kajastav teave kogumis. See teave salastatakse piiratud tasemel 20 aastaks;

[RT I, 27.08.2022, 1 – вступ. в силу 01.01.2023]

riigi infosüsteemi kuuluvas andmekogus Kaitseväe, jälitusasutuse, julgeolekuasutuse või tunnistajakaitset teostava asutuse poolt salajasele koostööle kaasatud isikuga, salajase koosseisulise julgeolekuasutuse ametniku või töötajaga, variisikuga, politseiagendiga, tunnistajakaitse kohaldamisega seotud isikuga või teeseldud juriidilise isiku, tema struktuuriüksuse, organi või äriühingu filiaaliga seotud füüsilise isikuga seotud variandmete ja konspiratsioonivõtete rakendamist käsitlev teave, välja arvatud teave, mille avalikustamine ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel kuni 50 aastaks.

[RT I, 31.12.2021, 18 – вступ. в силу 03.01.2022]

Riigikaitseseaduse tähenduses riigikaitseobjektide, välja arvatud käesoleva paragrahvi lõikes 1 nimetatud asutuste valduses olevate riigikaitseobjektide ja avaliku korra tagamiseks oluliste riigikaitseobjektide valve- ja häiresüsteeme ning kaitsemeetmeid käsitleva teabe osas on riigisaladuseks:

avaliku võimu organi kasutuses oleva või elutähtsa teenuse osutamisega või sisejulgeoleku tagamisega seotud riigikaitseobjekti riskianalüüsis ja turvaplaanis riigikaitseobjekti elektroonilist läbipääsu- või valvesüsteemi ning riigikaitseobjekti füüsilise kaitse miinimummeetmeid ja lisaturvameetmeid käsitlev koondteave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 10 aastaks;

riigikaitseobjekti, selle täpset paiknemist ning seoseid teiste riigikaitseobjektidega käsitlev teave, mis ohustab kaitsemeetmete rakendamist, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 20 aastaks.

[RT I, 27.09.2016, 5 – вступ. в силу 30.09.2016]

Riigisaladuse ja salastatud välisteabe töötlussüsteeme käsitleva teabe osas on riigisaladuseks:

valdkonna eest vastutava ministri määrusega kehtestatavad krüptomaterjalide ning nende töötlemise ja kaitse nõuded. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

kiirgusturbe tagamise nõuded ja meetmed, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

töötlussüsteemi seadmete ja asukoha paljastava kiirguse mõõtmise metoodika ning mõõtmise tulemuste hindamise kriteeriumid. See teave salastatakse konfidentsiaalsel tasemel 25 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

töötleva üksuse krüptomaterjali registreerimist puudutavad andmed, sealhulgas registreerimiseks kasutatava dokumendiregistri kanded. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Välisluureametis krüptomaterjali registreerimist puudutavad andmed kogumina. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

töötlevale üksusele spetsiaalselt salastatud teabe töötlemiseks loodud tarkvara lähtekood, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

piiratud tasemel salastatud teavet töötleva töötlussüsteemi tehnilisi andmeid või turvameetmeid kajastav teave, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse piiratud tasemel 30 aastaks;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

konfidentsiaalse või kõrgema taseme salastatud teabe töötlussüsteemis teabe töötlemise tingimused ja kasutajate ülesannete jagunemine salastatud teabe töötlemisel. See teave salastatakse piiratud tasemel 30 aastaks;

konfidentsiaalsel tasemel salastatud teavet töötleva töötlussüsteemi tehnilisi andmeid või turvameetmeid kajastav teave. See teave salastatakse konfidentsiaalsel tasemel 30 aastaks. Käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korras võib seda teavet salastada madalamal tasemel;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

salajasel tasemel salastatud teavet töötleva töötlussüsteemi tehnilisi andmeid või turvameetmeid kajastav teave. See teave salastatakse salajasel tasemel 50 aastaks. Käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korras võib seda teavet salastada madalamal tasemel;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

täiesti salajasel tasemel salastatud teavet töötleva töötlussüsteemi tehnilisi andmeid või turvameetmeid kajastav teave. See teave salastatakse täiesti salajasel tasemel 50 aastaks. Käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korras võib seda teavet salastada madalamal tasemel;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

salastatud teavet töötleva töötlussüsteemi haavatavuse analüüsi ja riskianalüüsi tulemusi ning jääkriskide hinnanguid kajastav teave. See teave salastatakse töötlussüsteemis töödeldava teabe kõrgeimal salastatuse tasemel kuni 50 aastaks. Käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korras võib seda teavet salastada madalamal tasemel;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

salastatud teavet töötleva töötlussüsteemi toimimist ja efektiivsust kajastav teave. See teave salastatakse töötlussüsteemis töödeldava teabe kõrgeimal salastatuse tasemel kuni 30 aastaks. Käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korras võib seda teavet salastada madalamal tasemel.

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Lõike 1 punktis 18 ning lõike 2 punktides 6 ja 8–10 nimetatud töötlussüsteemi tehnilisi andmeid ja turvameetmeid kajastav teave on teave, millest nähtuvad:

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

töötlussüsteemi tehniline kirjeldus;

Утратил силу

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

töötlussüsteemi võrguskeem;

tehniline teave töötlussüsteemi teise töötlussüsteemiga ühendamise kohta;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teave töötlussüsteemis rakendatavate turvameetmete kohta;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teave töötlussüsteemis rakendatavate krüptograafiliste turvameetmete kohta;

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

õigusaktis sätestatud elektroonilise teabeturbe nõude täitmata jätmise kompenseerimiseks rakendatav turvameede.

Утратил силу

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Утратил силу

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Утратил силу

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Enne käesoleva määruse § 8 lõike 2 punktides 8–12 nimetatud teabe töötlussüsteemis töödeldava teabe kõrgeimast salastatuse tasemest madalamal tasemel salastamist peab töötlev üksus kooskõlastama käesoleva määruse § 22 lõike 1 punkti 17 alusel kehtestatud korra Välisluureametiga. Korra kehtestamise aluseks olevate nõuete juhendi töötab välja Välisluureamet.

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Relvasüsteemide ja rahvusvaheliselt ühiseks kasutamiseks mõeldud töötlussüsteemide puhul kooskõlastab Välisluureamet käesoleva paragrahvi lõike 2 punktides 8–12 nimetatud teabe salastatuse tasemed igal juhul eraldi.

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Kaitseväe korralduse seaduse § 37 lõike 1 punktides 1, 2 ja 5 ning lõikes 2 nimetatud viisil teavet koguva kaitseväeluure ülesannet täitva Kaitseväe struktuuriüksuse kasutuses olevaid hooneid ja rajatisi käsitleva teabe osas on riigisaladuseks teave struktuuriüksuse erivajadusteks kohandatud hoonete ja ruumide kohta, välja arvatud teave, mille avalikuks tulek ei kahjusta Eesti Vabariigi julgeolekut. See teave salastatakse konfidentsiaalsel tasemel 50 aastaks või hoone või rajatise valduse lõppemiseni.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Kaitseväe ja Kaitseliidu relva- ja lahingumoonaladusid käsitleva teabe osas on riigisaladuseks:

teave relva-, laskemoona- ja lahingumoonalao turvalisuse tagamise erinõuete kohta, välja arvatud valvesüsteemide kohta kehtestatud nõuded. See teave salastatakse piiratud tasemel 10 aastaks või kuni relva-, laskemoona- või lahingumoonalao valduse lõppemiseni;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitseväe ja Kaitseliidu relvade, laskemoona ja lahingumoona ladude andmed kogumis. See teave salastatakse piiratud tasemel 30 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötleva üksuse salastatud teabekandjate evakueerimist käsitleva teabe osas on riigisaladuseks konfidentsiaalsel või kõrgemal tasemel salastatud teavet sisaldavate teabekandjate evakueerimist käsitlev § 33 lõigetes 2 ja 3 sätestatud teave. See teave salastatakse konfidentsiaalsel tasemel 20 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötleva üksuse turvaala valve- ja häiresüsteeme käsitleva teabe osas on riigisaladuseks:

teave, mis sisaldab andmeid turvaala elektroonilise läbipääsu- või valvesüsteemi moodustavate seadmete asukoha, tüübi, nendevaheliste ühenduste ja teiste tehniliste näitajate kohta või andmeid valvealade või -tsoonide kohta või süsteemi üldist kirjeldust. See teave salastatakse konfidentsiaalsel tasemel kuni ala turvaalana kasutamise lõpetamiseni, kuid mitte kauemaks kui 30 aastaks;

turvaala elektroonilise läbipääsu- või valvesüsteemi toimimist ja efektiivsust kajastavad analüüsid ja hinnangud. See teave salastatakse konfidentsiaalsel tasemel kuni ala turvaalana kasutamise lõpetamiseni, kuid mitte kauemaks kui 30 aastaks;

turvaala füüsiliste julgeolekumeetmete analüüsid ja hinnangud, mis kajastavad julgeolekumeetmete toimimist ja efektiivsust. See teave salastatakse konfidentsiaalsel tasemel kuni ala turvaalana kasutamise lõpetamiseni, kuid mitte kauemaks kui 30 aastaks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui töötleva üksuse turvaala elektrooniline läbipääsu- või valvesüsteem on suurema süsteemi osa, salastatakse vaid turvaalale paigaldatud seadmeid kajastav teave.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Eesti Panga sularaha vedu käsitleva teabe osas on riigisaladuseks:

teave Eesti Panga riikidevahelise veo aja ja veetava summa kohta. See teave salastatakse piiratud tasemel kuni veo lõppemiseni;

teave Eesti Panga riikidevahelise veo marsruudi ja julgestamise kohta. See teave salastatakse konfidentsiaalsel tasemel 10 aastaks.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Katkematu side korraldamist käsitleva teabe osas on riigisaladuseks katkematu side korraldamise kord ja nõuded katkematule sidele ning katkematu sidega varustatud objektide ja nende sidevahendite loetelu kogumis. See teave salastatakse piiratud tasemel 25 aastaks.

[RT I, 19.03.2012, 1 – вступ. в силу 22.03.2012]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 8. Subcategories of state secret related to protection of infrastructure and data

(1) With regard to information concerning the security, alarm, communication and information systems of the Office of the President of the Republic, the Government Office, a security authority, the Ministry of Defence, the Defence Forces, the Defence League, the Defence Resources Agency, the State Information Systems Agency, Eesti Pank, the Ministry of the Interior, the Police and Border Guard Board and the Ministry of Foreign Affairs, including foreign representations and missions, and the state authorities administered by such governmental authorities, the following is a state secret:

1) aggregate information concerning the electronic access or security system of a building or area in the possession of the authority specified in the introductory part of this subsection to the extent of one building or area or part thereof considered to be an integral whole, which contains data on the location, type, connections between them and other technical indicators of the equipment which constitute the system, including the central processing equipment, or data concerning the security areas or zones or a general description of the system, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘confidential’ for 30 years;

2) analyses and assessments concerning the operation and efficiency of the electronic access or surveillance system of a building or area in the possession of an authority specified in the introductory part of this subsection, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘confidential’ for 30 years;

4) aggregate information concerning the electronic access or surveillance system of a building or area in the possession of an authority specified in the introductory part of this subsection to the extent of one building or area or part thereof considered to be an integral whole, which contains data concerning the location and type of the terminal equipment (sensors, cameras or other devices) and concerning the setting of the security areas and zones or system created thereby, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

7) the set of information processed by the electronic access or security system of a building or area in the possession of an authority specified in the introductory part of this subsection, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

12) aggregate information concerning the automatic fire alarm systems of a building or area in the possession of an authority specified in the introductory part of this subsection to the extent of one building or area or part thereof considered to be an integral whole, which contains data concerning the location, type, the connection between them and other technical indicators of the equipment which constitute the system, or a general description of the system, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

14) the analyses and assessments concerning the physical security measures of a building or area in the possession of an authority specified in the introductory part of this subsection, which reflect the functioning and efficiency of the security measures, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘confidential’ for 30 years;

15) information concerning radio frequencies permanently used for signals intelligence, air surveillance, marine surveillance, security and guarding of objects, and military defence of the state and command thereof in the Defence Forces. Such information is classified as ‘confidential’ for 30 years;

(16) aggregate information on the communications networks and processing systems used for military defence of the state and for its command of the Ministry of Defence, the Defence Forces, the Defence League, the Defence Resources Agency and other processing entities within the area of government of the Ministry of Defence, including aggregate information on the architecture of each communications network and processing system and information on security measures. Such information is classified as ‘confidential’ for 30 years;

18) information reflecting the technical data and security measures of the processing systems used for the processing of information intended for official use only by the Ministry of Defence, the Defence Forces, the Defence League, the Defence Resources Agency and other processing entities within the area of government of the Ministry of Defence, which do not process classified information, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ until the end of the use of the processing system or part thereof, but for no longer than 30 years;

20) information concerning the description of the cryptographic device used in the Air Force Airborne Surveillance Communications System of the air forces. Such information is classified as ‘confidential’ for 10 years;

21) information concerning the description of the keyless cryptographic device used in the airborne surveillance communications system of the air forces. Such information is classified as ‘confidential’ for 10 years;

22) information concerning the description of a cryptograhic device with a key used in the airborne surveillance communications system of the air forces. Such information is classified as ‘secret’ for 10 years;

23) information concerning the communication links schemes in the airborne surveillance communications system of the air forces. Such information is classified as ‘confidential’ for 10 years;

24) information concerning the parameters and operational capacity of the data transmission equipment used in the airborne surveillance systems. Such information is classified as ‘confidential’ for 10 years;

25) information of an authority specified in the introductory part of this subsection concerning the cabling of the networks to the extent of one building or area or part thereof considered to be an integral whole, except information the disclosure of which does not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years or until the network is transferred or its use is terminated;

25¹) information of the authority specified in the introductory part of this subsection concerning the cabling of the processing entity of information classified at the ‘confidential’ and higher level of classification to the extent of one building or area or part thereof considered to be an integral whole. Such information is classified as ‘confidential’ for 30 years or until the network is transferred or its use is terminated;

26) information concerning the methods and means used by the Estonian Foreign Intelligence Service for organising and control of special telecommunications. Such information is classified as ‘confidential’ for 30 years.

(27) technical information and operational parameters of surveillance and security systems, intended for the surveillance of external borders, which are not available from public sources and the disclosure of which would damage the safeguarding of internal security. Such information is classified as ‘restricted’ for 10 years;

]

(28) aggregate information on the structure and technical parameters of monitoring and surveillance systems intended for the surveillance of external borders, which contains a general description of the systems or data on the precise technical characteristics of the equipment included in of the system. Such information is classified as ‘confidential’ for 30 years or until the end of its use;

29) the results of the tests reflecting the coverage areas of the monitoring and surveillance systems intended for the surveillance of external borders. Such information is classified as ‘restricted’ for 10 years;

30) a set of data concerning the detailed technical structure or security methods of data communication intended for surveillance of external borders. Such information is classified as ‘restricted’ for 10 years;

31) a set of data concerning the detailed structure or security methods of the operational radio communication, except for the aggregate figures of the structure of the network. Such information is classified as ‘restricted’ for 20 years;

32) Cyber security risk analyses prepared by the Information Systems Authority and the Ministry of Economic Affairs and Communications, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 20 years;

32¹) information collected during the monitoring, surveillance and cyber incident analysis concerning the security vulnerabilities and security measures implemented by a constitutional institution, a government authority, a state authority administered by the government authority, a critical service provider, and the network and information system that is not a classified information processing system of an international organisation located in Estonia and whose security is ensured by Estonia, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ until the termination of the use of the network and information system, but not for longer than 30 years;

(33) information in the set on the architecture of the monitoring and surveillance systems for the surveillance of external borders. Such information is classified as ‘restricted’ for 20 years;

34) information contained in the database of the state information system on the application of covert information and covert measures with regard to a natural person involved in secret cooperation by the Defence Forces, a surveillance agency, a security authority or a witness protection authority, an undercover staff official or employee of a security authority, an undercover agent, a police agent, a person relating to the application of witness protection or a natural person related to a simulated legal person, its structural entity, body or subsidiary of the company, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for up to 50 years.

(1¹) For the purposes of the National Defence Act with regard to information concerning the national defence objects, except information concerning the surveillance and alarm systems and protective measures for national defence objects in the possession of the authorities specified in subsection 1 of this section and for national defence objects essential for ensuring public order, the following is state secret:

1) aggregate data concerning the electronic access or surveillance systems of a national defence object and minimum measures of physical protection and additional security measures of a national defence object in the risk assessment and security plan of a national defence object in the possession of a public authority or related to the provision of a vital service or ensuring internal security, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 10 years;

2) information concerning a national defence object, its exact location and relations with other national defence objects, which would endanger the implementation of protective measures, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 20 years.

(2) With regard to information concerning the processing systems of state secrets and foreign classified information, the following is a state secret:

1) security requirements established by the minister in charge of the policy sector for the processing and protection cryptographic material. Such information is classified as ‘restricted’ for 30 years;

2) requirements and measures to ensure radiation security, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

3) the methodology for the measurement of the detectable radiation of the equipment and location of the processing system and the criteria for the evaluation of the measurement results. Such information is classified as ‘confidential’ for 25 years;

3¹) data concerning the registration of cryptographic material of the processing entity, including the entries in the document register used for registration. Such information is classified as ‘restricted’ for 30 years;

4) the data in the set at the Estonian Foreign Intelligence Service concerning the registration of cryptographic material. Such information is classified as ‘confidential’ for 30 years;

5) the source code of a software specially designed for the processing entity for processing classified information, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

6) information reflecting the technical data or security measures of the processing system processing classified information at the ‘restricted’ level, except information the disclosure of which would not damage the security of the Republic of Estonia. Such information is classified as ‘restricted’ for 30 years;

7) the conditions for processing information in the information processing system for information classified at the ‘confidential’ or higher level and the division of tasks between users in the processing of classified information. Such information is classified as ‘restricted’ for 30 years;

8) information reflecting the technical specifications or security measures of a processing system processing classified information at a ‘confidential’ level. Such information is

classified as ‘confidential’ for 30 years. In accordance with the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation, such information may be classified at a lower level;

9) information reflecting the technical data or security measures of the processing system processing classified information at the secret level. This information is classified as ‘secret’ for 50 years. In accordance with the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation, such information may be classified at a lower level;

10) information reflecting the technical data or security measures of a processing system processing classified information at the ‘top secret’ level. Such information is classified as ‘top secret’ for 50 years. In accordance with the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation, such information may be classified at a lower level;

11) information reflecting the results of the vulnerability analysis and risk analysis and residual risk assessments of the processing system processing classified information. Such information is classified at the highest classification level of the information processed in the processing system for up to 50 years. In accordance with the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation, such information may be classified at a lower level;

12) information reflecting the operation and efficiency of the processing system processing classified information. Such information is classified at the highest classification level of the information processed in the processing system for up to 30 years. In accordance with the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation, such information may be classified at a lower level.

(3) The information reflecting the technical data and security measures of the processing system specified in clause 18 of subsection 1 and clauses 6 and 8–10 of subsection 2 mean information which sets out:

2) the technical specification of the CIS;

3) network scheme of the processing system;

4) technical information concerning interconnection of the processing system with another processing system;

4¹) information on the security measures applicable in the processing system;

5) information on the cryptographic security measures applicable in the processing system;

6) the security measure applied to compensate for non-compliance with the electronic information security requirement provided in the legislation.

(3¹) Prior to classification of the information specified in clauses 8–12 of subsection 2 of § 8 of this Regulation at the level lower than the highest classification level, the processing entity is required to coordinate the procedure established based on clause 17 of subsection 1 of § 22 of this Regulation with the Foreign Intelligence Service. The guidelines for the requirements based on which the procedures are established are developed by the Foreign Intelligence Service.

(3²) In the case of weapon systems and processing systems for international joint use, the Foreign Intelligence Service coordinates the classification levels of the information specified in clauses 8–12 of subsection 2 of this section in each case separately.

(4) With regard to information concerning the buildings and construction works in use by the structural unit of the Defence Forces, which executes military intelligence, the information concerning buildings and premises adjusted for special needs of the structural unit, except information the disclosure of which would not damage the security of the Republic of Estonia, is state secret. Such information is classified as ‘confidential’ for 50 years or until the possession of the building or construction works terminates.

(5) With regard to information concerning the weapons and munitions warehouses of the Defence Forces and the National Defence League, the following is a state secret:

1) information on the specific requirements for the security of the weapons, ammunition and munition warehouses, except those relating to surveillance systems. Such information is classified as ‘restricted’ for 10 years or until the termination of the possession of the weapons, munition or ammunition warehouse;

2) data on weapons, ammunition and munition warehouses of the Defence Forces and the Defence League in the set. Such information is classified as ‘restricted’ for 30 years.

(6) With regard to the information on the evacuation of classified media of the processing entity, the information on the evacuation of media classified as ‘confidential’ or higher level provided in subsections 2 and 3 of § 33 is state secret. Such information is classified as ‘confidential’ for 20 years.

(7) Regarding information on the surveillance and alarm systems of the security area of the processing entity the following is state secret:

1) information containing data on the location and type of the devices, interconnections between them and other technical characteristics of the devices constituting the electronic access or surveillance system of the security area, or data on security areas or zones, or a general description of the system. Such information is classified as ‘confidential’ until the termination of the use of the area as a security area, but not for longer than 30 years;

2) analyses and assessments reflecting the operation and efficiency of the electronic access or surveillance system of the security area. Such information is classified as ‘confidential’ until the termination of the use of the security area.

3) the analyses and assessments of physical security measures of the security area, which reflect the operation and efficiency of security measures. Such information is classified as ‘confidential’ until the termination of using the area as a security area but not for longer than 30 years.

(7¹) In case the electronic access or surveillance system of the security area of the processing entity is a part of a larger system, only information reflecting the equipment installed in the security area is classified.

(8) With regard to information concerning cash transportation by Eesti Pank, the following is a state secret:

1) information concerning the time of the cross-border cash transportation by Eesti Pank and the amount of cash transported. Such information is classified as ‘restricted’ until the termination of transportation.

2) information concerning the route and provision of security protection to the cross-border cash transportation by Eesti Pank. Such information is classified as ‘confidential’ for 10 years.

(9) With regard to information concerning organisation of uninterrupted communication, information in the set concerning the procedure for organisation of uninterrupted communication and the requirements for uninterrupted information and the list of objects supplied with uninterrupted communication and their communication means is state secret. Such information is classified as ‘restricted’ for 25 years.

3. peatükk RIIGISALADUSE SALASTATUSE KUSTUTAMINE, SALASTAMISALUSE, -TASEME JA -TÄHTAJA MUUTMINE › 1. jagu Riigisaladuse salastatuse ennetähtaegne kustutamine

§ 9. Salastatuse ennetähtaegse kustutamise taotluse esitamine

Asutus või põhiseaduslik institutsioon, kellel puudub pädevus kustutada enda loodud riigisaladuse salastatust enne tähtaja möödumist, esitab «Riigisaladuse ja salastatud välisteabe seaduse» § 13 lõikes 4 sätestatud juhul taotluse riigisaladuse salastatuse ennetähtaegseks kustutamiseks Vabariigi Valitsusele ministri kaudu, kelle valitsemisalasse ta kuulub. Kui asutus või põhiseaduslik institutsioon ei asu ühegi ministeeriumi valitsemisalas, esitab ta taotluse Vabariigi Valitsusele Siseministeeriumi kaudu.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Taotluses märgitakse salastatuse ennetähtaegse kustutamise vajaduse põhjendused, millisele töötlevale üksusele on see teave edastatud ja kas teave oleks pärast kustutamist asutusesiseseks kasutamiseks mõeldud teave. Taotlusele lisatakse selle kohta esitatud vastuväited. «Riigisaladuse ja salastatud välisteabe seaduse» § 13 lõikes 2 nimetatud teabe korral lisatakse taotlusele ka füüsilise isiku kirjalik nõusolek.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Ministril on õigus suunata taotlus Vabariigi Valitsuse julgeolekukomisjonile arvamuse andmiseks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 9. Submission of application for premature declassification

(1) An authority or constitutional institution that has no competence to declassify a state secret created thereby before the expiry of the term, submits, in the case provided in subsection 4 of § 13 of the State Secrets and Classified Information of Foreign States Act, an application for the premature declassification of the state secret to the Government of the Republic through the minister into whose area of government it belongs. In case the authority or constitutional institution does not belong to the area of government of any ministry, it submits the application to the Government of the Republic through the Minister of the Interior.

(2) The application sets forth the reasons for the need for premature classification, the processing entity to whom such information has been forwarded, and specifies whether, after declassification, such information becomes information intended for official use only. The objections submitted thereto are appended to the application. In the case of information specified in subsection 2 of § 13 of the State Secrets and Classified Information of Foreign States Act, the written consent of the natural person is also appended to the application.

(3) A minister has the right to send the application to the Security Committee of the Government of the Republic for obtaining their opinion.

§ 10. Taotluse kohta vastuväidete esitamine

Paragrahvi 9 lõikes 1 nimetatud asutus või põhiseaduslik institutsioon peab enne salastatuse kustutamise taotlemist teavitama taotluse esitamise kavatsusest kõiki asutusi ja põhiseaduslikke institutsioone, kellele seda riigisaladust sisaldav teabekandja on edastatud, ja andma neile vastuväidete esitamiseks vähemalt ühekuulise tähtaja. Samuti teavitatakse vajaduse korral asutust ja põhiseaduslikku institutsiooni, kelle ülesandeid see teave võib puudutada.

Salastatuse ennetähtaegse kustutamise kavatsuse teates märgitakse salastatuse ennetähtaegse kustutamise vajaduse põhjendused ja kas teave oleks pärast salastatuse kustutamist asutusesiseseks kasutamiseks mõeldud teave.

Teate saanud asutus või põhiseaduslik institutsioon esitab riigisaladuse salastatuse ennetähtaegsele kustutamisele vastuväited hiljemalt käesoleva paragrahvi lõike 1 alusel antud tähtaja jooksul.

Minister kaalub taotluse Vabariigi Valitsusele esitamisel taotlusele esitatud vastuväiteid.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 10. Submission of objections to application

(1) Before application for declassification, the agency or constitutional institution specified in subsection 1 of § 9 informs all the authorities and constitutional institutions to whom a medium containing a state secret has been forwarded of the intention to submit such an application and grants them a term of at least one month for submission of objections. The authorities and constitutional institutions, whose tasks such information may concern, are also notified of, where necessary.

(2) The notice on the intention to prematurely declassify information sets forth the reasons for the need for premature declassification and specifies whether such information would be, after declassification, information intended for official use only.

(3) An authority or constitutional institution which receives such notice submits its objections to the premature declassification of a state secret the latest within the term granted on the basis of subsection 1 of this section.

(4) Upon submission of the application to the Government of the Republic, a minister considers the objections submitted to the application.

§ 11. Kustutamiseks pädeva asutuse poolt kustutamise kavatsusest teavitamine

Asutus või põhiseaduslik institutsioon, kes on pädev kustutama enda loodud riigisaladuse salastatust enne tähtaja möödumist, peab kustutamise kavatsusest teavitama kõiki asutusi ja põhiseaduslikke institutsioone, kellele seda riigisaladust sisaldav teabekandja on edastatud, ja andma neile vastamiseks vähemalt ühekuulise tähtaja. Samuti teavitatakse vajaduse korral asutust ja põhiseaduslikku institutsiooni, kelle ülesandeid see teave võib puudutada.

Kustutamise kavatsuse teates märgitakse salastatuse ennetähtaegse kustutamise põhjendused, kavandatav kustutamise kuupäev ja selgitus, kas teave oleks edaspidi asutusesiseseks kasutamiseks mõeldud teave.

Teate saanud asutus või põhiseaduslik institutsioon esitab salastatuse ennetähtaegse kustutamise kohta vastuväited käesoleva paragrahvi lõike 1 alusel antud tähtaja jooksul.

Lõikes 1 nimetatud asutuse või põhiseadusliku institutsiooni juht kaalub salastatuse ennetähtaegse kustutamise otsustamisel asutuste ja põhiseaduslike institutsioonide vastuväiteid.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 11. Notification of intention to declassify by authority competent to declassify

(1) An authority or constitutional institution that is competent to declassify a state secret created thereby before the expiry of the term informs all the authorities and constitutional institutions to whom a medium containing a state secret has been transmitted of the intention to submit such application and grants them a term of at least one month for submission of objections. The authority and constitutional institution whose tasks such information may concern is also given notice, where necessary.

(2) A notice on the intention to declassify sets forth the reasons for premature declassification, the planned date of declassification and an explanation whether, hereinafter, such information would become information intended for official use only.

(3) An authority or constitutional institution that receives such a notice submits their objections to premature declassification within the term granted based on subsection 1 of this section.

(4) Upon deciding on premature declassification, the head of the authority or constitutional institution specified in subsection 1 considers the objections submitted by authorities and constitutional institutions.

§ 12. «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutuse ja põhiseadusliku institutsiooni teavitamine salastatuse ennetähtaegsest kustutamisest

Kui §-des 10 ja 11 nimetatud teate saanud asutus või põhiseaduslik institutsioon on kõnealuse riigisaladuse edastanud «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutusele või põhiseaduslikule institutsioonile, teavitab ta seda asutust või põhiseaduslikku institutsiooni riigisaladuse ennetähtaegse kustutamise kavatsuse teate saamisest. Sel viisil teavitatud asutusel ja põhiseaduslikul institutsioonil on õigus esitada oma vastuväited samas korras, salastatuse ennetähtaegse kustutamise taotluse esitamist või ennetähtaegset kustutamist kavatseva asutuse või põhiseadusliku institutsiooni antud tähtaja jooksul.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 12. Notification of authorities and constitutional institutions specified in subsection 3 of § 35 of State Secrets and Classified Information of Foreign States Act of premature declassification

In case an authority or constitutional institution that has received a notice specified in §§ 10 and 11 has forwarded such a state secret to the authority or constitutional institution specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act, they notify that authority or constitutional institution of having received the notice on the intention to prematurely classify a state secret. The authority or constitutional institution notified in this manner has the right to submit their objections in accordance with the same procedure before submission of the application for premature declassification or within the term granted by the authority or constitutional institution intending to prematurely declassify information.

§ 13. Ennetähtaegsest kustutamisest teavitamine

Kui asutus või põhiseaduslik institutsioon on kustutanud enda loodud riigisaladuse salastatuse enne tähtaja möödumist, teavitab ta sellest viivitamata kõiki töötlevaid üksusi, kes seda riigisaladust sisaldavat teabekandjat valdavad.

Kui Vabariigi Valitsus kustutab riigisaladuse salastatuse enne tähtaja möödumist ministri taotluse või ministri edastatud taotluse alusel, teavitab minister salastatuse kustutamisest viivitamata kõiki töötlevaid üksusi, kellele seda riigisaladust sisaldav teabekandja on edastatud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Asutus või põhiseaduslik institutsioon, kes on edastanud salastatud teabekandja, mille salastatus on kustutatud, «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutusele või põhiseaduslikule institutsioonile, teavitab salastatuse kustutamisest viivitamata ka seda asutust või põhiseaduslikku institutsiooni.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 13. Notification of premature declassification

(1) In case an authority or constitutional institution declassifies a state secret created thereby before the expiry of the term, they immediately inform all the processing entities that possesses the medium containing that state secret.

(2) In case the Government of the Republic declassifies a state secret before the expiry of the term based on an application submitted or transmitted by a minister, the minister immediately informs of the declassification all the processing entities to whom the medium containing such a state secret has been forwarded.

(3) An authority or constitutional institution that has forwarded a classified medium that has been declassified to an authority or constitutional institution specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act, also immediately informs such an authority or constitutional institution of the declassification.

3. peatükk RIIGISALADUSE SALASTATUSE KUSTUTAMINE, SALASTAMISALUSE, -TASEME JA -TÄHTAJA MUUTMINE › 2. jagu Riigisaladuse salastamistähtaja pikendamine

§ 14. Salastamistähtaja pikendamise taotlus

Asutus või põhiseaduslik institutsioon, kellel puudub pädevus pikendada enda loodud riigisaladuse salastamistähtaega, esitab taotluse salastamistähtaja pikendamiseks Vabariigi Valitsusele ministri kaudu, kelle valitsemisalasse ta kuulub. Kui asutus või põhiseaduslik institutsioon ei asu ühegi ministeeriumi valitsemisalas, esitab ta taotluse Vabariigi Valitsusele Siseministeeriumi kaudu.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Riigisaladuseks oleva teabe salastamistähtaja pikendamise taotlus esitatakse Vabariigi Valitsusele võimaluse korral vähemalt kolm kuud enne salastamistähtaja lõppu.

Taotluses märgitakse salastamistähtaja pikendamise vajaduse põhjendused ja millisele töötlevale üksusele on see teave edastatud. Taotlusele lisatakse selle kohta esitatud vastuväited.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Ministril on õigus suunata taotlus Vabariigi Valitsuse julgeolekukomisjonile arvamuse andmiseks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 14. Application for extension of term of classification

(1) An authority or constitutional institution that has no competence to extend the term of classification of a state secret created thereby submits an application for the extension of the term of classification to the Government of the Republic through the minister into whose area of government they belong. In case the authority or constitutional institution does not belong to the area of government of any ministry, they submit the application to the Government of the Republic through the Minister of the Interior.

(2) An application for extension of the term of classification of information classified as state secret is submitted to the Government of the Republic, where possible, at least three months prior to the expiry of the term of classification.

(3) The application sets forth the reasons for the need to extend the term of classification and specifies the processing entities to which such information has been forwarded. Any objections submitted to the application are appended to the application.

(4) A minister has the right to refer the application to the Security Committee of the Government of Republic for obtaining their opinion.

§ 15. Salastamistähtaja pikendamise kohta vastuväidete esitamine

Paragrahvi 14 lõikes 1 nimetatud asutus või põhiseaduslik institutsioon peab enne salastamistähtaja pikendamise taotlemist teavitama taotluse esitamise kavatsusest kõiki asutusi ja põhiseaduslikke institutsioone, kellele seda riigisaladust sisaldav teabekandja on edastatud, ja andma neile vastamiseks vähemalt ühekuulise tähtaja.

Pikendamise kavatsuse teates märgitakse salastamistähtaja pikendamise põhjendused.

Teate saanud asutus või põhiseaduslik institutsioon esitab riigisaladuse salastamistähtaja pikendamisele vastuväited käesoleva paragrahvi lõike 1 alusel antud tähtaja jooksul.

Minister kaalub taotluse Vabariigi Valitsusele esitamisel taotlusele esitatud vastuväiteid.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 15. Submission of objections to extension of term of classification

(1) Before application for extension of the term for classification, the authority or constitutional institution specified in subsection 1 of § 14 is required to inform all the authorities and constitutional institutions to whom media containing the state secret has been transmitted of the intention to submit such an application and grant them a term of at least one month for responding.

(2) A notice on the intention to extend the term for classification sets forth the reasons for extension of the term for classification.

(3) An authority or constitutional institution which receives such notice submits their objections to the extension of the term of classification within the term granted on the basis of subsection 1 of this section.

(4) Upon submission of the application to the Government of the Republic, the minister considers the objections submitted to the application.

§ 16. Salastamistähtaja pikendamisest teavitamine

Kui asutus või põhiseaduslik institutsioon on pikendanud enda loodud riigisaladuse salastamistähtaega, teavitab ta sellest viivitamata kõiki töötlevaid üksusi, kes seda riigisaladust sisaldavat teabekandjat valdavad.

Kui Vabariigi Valitsus on pikendanud riigisaladuse salastamistähtaega ministri taotluse või ministri poolt edastatud taotluse alusel, teavitab minister salastatuse pikendamisest viivitamata kõiki töötlevaid üksusi, kellele seda riigisaladust sisaldav teabekandja on edastatud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Asutus või põhiseaduslik institutsioon, kes on edastanud salastatud teabekandja, mille salastamistähtaega on pikendatud, «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutusele või põhiseaduslikule institutsioonile, teavitab salastatuse pikendamisest viivitamata ka seda asutust või põhiseaduslikku institutsiooni.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 16. Notification of extension of term of classification

(1) In case an authority or constitutional institution has extended the term of classification of a state secret created thereby, it immediately informs thereof all the entities in possession of a medium containing such a state secret.

(2) In case the Government of the Republic has extended the term of classification of a state secret based on an application submitted or transmitted by a minister, the minister immediately informs of the extension of the term of classification all the processing entities to whom a medium containing such a state secret has been forwarded.

(3) An authority or constitutional institution that has transmitted a classified medium whose term of classification has been extended to an authority or constitutional institution specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act, also immediately informs such an authority or constitutional institution of the extension of classification.

3. peatükk RIIGISALADUSE SALASTATUSE KUSTUTAMINE, SALASTAMISALUSE, -TASEME JA -TÄHTAJA MUUTMINE › 3. jagu Salastamisandmete parandamine

§ 17. Salastamisandmete parandamise taotluse esitamine

Asutus või põhiseaduslik institutsioon, kelle töötajal või teenistujal puudub pädevus salastamisandmete parandamiseks, esitab «Riigisaladuse ja salastatud välisteabe seaduse» § 15 lõikes 1 sätestatud juhul taotluse salastamisandmete parandamiseks vastavalt Vabariigi Valitsusele või Siseministeeriumile selle ministri kaudu, kelle valitsemisalasse ta kuulub. Töötlemisloaga isik esitab taotluse riigisaladuse töötlemise loa saamist toetanud asutuse kaudu.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Taotluses märgitakse salastamisandmete parandamise põhjendused ja selgitus, kas teave oleks edaspidi juurdepääsupiiranguta avalik või asutusesiseseks kasutamiseks mõeldud teave või millisel alusel või millise tähtajaga salastatud teave ning millistele töötlevatele üksustele on see teave edastatud. Taotlusele lisatakse selle kohta esitatud vastuväited.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Ministril on õigus suunata taotlus Vabariigi Valitsuse julgeolekukomisjonile arvamuse andmiseks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 17. Submission of application for correction of classification data

(1) An authority or constitutional institution, whose employee or public servant lacks competence to correct classification data, submits, in the case provided in subsection 1 of § 15 of the State Secrets and Classified Information of Foreign States Act, an application for the correction of classification data respectively to the Government of the Republic or the Minister of the Interior through the minister into whose area of government it belongs. A person holding a Facility Security Clearance submits the application through the authority which supported the grant of Facility Security Clearance for the processing of state secrets to such a person.

(2) The application sets forth the reasons for correction of classification data and provides an explanation whether such data would thereafter become public information without any restrictions to access, or information intended for official use only or classified information, specifying the basis and term for classification, and specifies the processing entities to which such data has been transmitted. Any objections submitted thereto are appended to the application.

(3) A minister has the right to refer the application to the Security Committee of the Government of Republic for an opinion.

§ 18. Salastamisandmete parandamise taotluse esitamise kavatsusest teavitamine

Enne salastamisandmete parandamise taotluse esitamist peab taotluse esitamise kavatsusest teavitama kõiki asutusi ja põhiseaduslikke institutsioone, kellele seda riigisaladust sisaldav teabekandja on edastatud, ja andma neile vastamiseks vähemalt ühekuulise tähtaja.

Salastamisandmete parandamise teates märgitakse salastamisandmete parandamise põhjendused ja selgitus, kas teave oleks edaspidi juurdepääsupiiranguta avalik või asutusesiseseks kasutamiseks mõeldud teave või millisel alusel või millise tähtajaga salastatud teave.

Teate saanud asutus või põhiseaduslik institutsioon esitab riigisaladuse salastamisandmete parandamisele vastuväited hiljemalt käesoleva paragrahvi lõike 1 alusel antud tähtaja jooksul.

Salastamisandmete parandamine otsustatakse taotluse ja sellele esitatud vastuväidete alusel.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 18. Notification of intention to submit application for correction of classification data

(1) Before submission of an application for the correction of classification data, notice must be given to all the authorities and constitutional institutions to whom media containing the corresponding state secret has been forwarded, and a term of one month must be granted to respond to such authorities and institutions.

(2) A notice on correction of classification data sets forth the reasons for correction of the classification data and an explanation whether such data would thereafter become public information without any restrictions to access, or information intended for official use only or classified information, specifying the basis and term for classification.

(3) An authority or constitutional institution that has received such notice submits their objections to the correction of the classification data of a state secret at the latest within the term granted on the basis of subsection 1 of this section.

(4) Correction of classification data is decided based on the application and the objections submitted thereto.

§ 20. «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutuse ja põhiseadusliku institutsiooni teavitamine salastamisandmete parandamise kavatsusest

Kui teate saanud asutus või põhiseaduslik institutsioon on riigisaladuse edastanud «Riigisaladuse ja salastatud välisteabe seaduse» § 35 lõikes 3 nimetatud asutusele või institutsioonile, teavitab ta seda asutust või põhiseaduslikku institutsiooni riigisaladuse salastamisandmete parandamise kavatsuse teate saamisest. Sel viisil teavitatud asutusel või põhiseaduslikul institutsioonil on õigus esitada oma vastuväited samas korras parandamise kavatsuse teate saanud asutuste ja põhiseaduslike institutsioonidega, salastamisandmete parandamisele vastuväidete esitamiseks antud tähtaja jooksul.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 20. Notification of authority and constitutional institution specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act of intention to correct classification data

In case an authority or constitutional institution that has received a notice specified in §§ 10 and 11 has transmitted a state secret to the authority or institution specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act, notifies such authority or constitutional institution of having received a notice on the intention to correct the classification data of a state secret. An authority or constitutional institution notified in such a manner has the right to submit their objections in accordance with the same procedure as the authorities and constitutional institutions that have received the notice on the intention to correct classification data, within the term granted for submission of objections to the correction of classification data.

§ 21. Salastamisandmete parandamisest teavitamine

Kui töötlev üksus parandab salastamisandmeid, teavitab ta sellest viivitamata kõiki töötlevaid üksusi, kellele seda riigisaladust sisaldav teabekandja on edastatud.

Kui salastamisandmete parandamise on otsustanud Vabariigi Valitsus taotluse alusel, teavitab taotluse esitanud ministeerium sellest kõiki töötlevaid üksusi, kellele seda riigisaladust sisaldav teabekandja on edastatud.

Kui salastamisandmeid parandatakse väärteo- või kohtuotsusega, teavitab Kaitsepolitseiamet kõiki töötlevaid üksusi, kellele seda riigisaladust sisaldav teabekandja on edastatud.

Töötlev üksus, kes on edastanud teise töötleva üksuse koostatud salastatud teabekandja, mille salastamisandmed on parandatud, „Riigisaladuse ja salastatud välisteabe seaduse“ § 35 lõikes 3 nimetatud töötlevale üksusele, teavitab salastamisandmete muutmisest viivitamata seda töötlevat üksust.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 21. Notification of correction of classification data

(1) In case a processing entity corrects classification data, they immediately inform thereof all the processing entities to whom media containing the corresponding state secret has been transmitted.

(2) In case correction of classification data has been decided by the Government of the Republic based on an application, the ministry that submitted the application informs thereof all the processing entities to whom media containing the corresponding state secret has been transmitted.

(3) In case classification data is corrected by a resolution in a misdemeanour matter or a court judgment, the Estonian Internal Security Service informs thereof all the processing entities to whom media containing the corresponding state secret has been transmitted.

4) A processing entity that has transmitted a classified medium prepared by another processing entity, the classified data of which have been corrected, to a processing entity specified in subsection 3 of § 35 of the State Secrets and Classified Information of Foreign States Act immediately notifies that processing entity of the amendment of the classification data.

4. peatükk SALASTATUD TEABE KAITSE KORRALDAMISE NÕUDED

§ 22. Töötleva üksuse salastatud teabe kaitse juhendile esitatavad nõuded

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötleva üksuse salastatud teabe kaitse juhendis reguleeritakse järgmisi küsimusi, arvestades töötleva üksuse eripära:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

väljastpoolt saabuvate ja väljapoole saadetavate salastatud teabekandjate vastuvõtmise ja edastamise kord;

salastatud teabekandjate registreerimise kord;

seifi võtme ja ligipääsukoodi hoiustamise kord;

juurdepääsuloa ja juurdepääsusertifikaadi käitlemise kord;

salastamisandmete parandamise kord;

salastatud koosolekute pidamise kord;

turvaala asukoht;

turvaala valve, turvaalale pääsemise, sellel liikumise ja sealt lahkumise kord;

salastatud teabe kaitse plaan ohuolukorras;

teavitamine isikust, kes püüab mis tahes viisil saavutada ebaseaduslikku juurdepääsu salastatud teabele, ning «Riigisaladuse ja salastatud välisteabe seaduse» või selle alusel antud õigusakti nõuete rikkumisest;

loend kõikide töötlevas üksuses kehtivate selliste kordade, juhendite ja muude eeskirjade kohta, mis reguleerivad riigisaladuse töötlemist;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

salastatud teabekandja hävitamise meetod ja kord;

administratiivala ulatus;

relva ning tehnilise vahendi ja muu eseme, mida saab kasutada tehnilise vahendina teabe kogumiseks, turvaalale viimise kord;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

sissepääsuloa või sissepääsu tagava vahendi kaotamise, kaotamiskahtluse või muu valduse kaotamisest teavitamise kord;

selle isiku määramine, kellele tuleb anda hoiule konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja säilitamiseks kasutatava seifi luku varuvõti ja luku kood;

selle riigisaladuseks oleva teabe salastatuse taseme määramise kord, mida võib käesoleva määruse kohaselt salastada mitmel tasemel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Lisaks lõikes 1 nimetatutele võib salastatud teabe kaitse juhendis sätestada näiteks:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

töötleva üksuse piires salastatud teabekandjate vastuvõtmise ja edastamise korra (turvaala piires, administratiivala kaudu);

salastatud teabekandjate edastamise täpsema korra;

salastatud teabekandjate reprodutseerimise korra;

kohapealse mehitatud valve kontrollkäikude korra;

turvaalale iseseisva sissepääsuõigusega isikute sissepääsuloa erisused võrreldes samas töötlevas üksuses töötavate isikutega;

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

külalise turvaalale lubamise erisused võrreldes samas töötlevas üksuses töötavate isikutega.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabe kaitse juhendi osa, mis peab olema salastatud, kehtestatakse juhendi lisana või eraldi dokumendina.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 22. Requirements for guidelines on protection of classified data of processing entity

(1) The guidelines on the protection of classified data of a processing entity regulate the following issues, taking account of the specific character of the processing entity:

1) procedure for receiving and transmitting classified media arriving from outside and to be sent outside;

2) procedure for registration of classified media;

3) procedure for storage of the key and access code to a safe;

4) procedure for handling a Personnel Security Clearance and Personnel Security Clearance Certificate to classified information;

5) procedure for correction of classification data;

6) procedure for holding classified meetings;

7) location of the security area;

8) guarding of the security area, procedure for entry into, moving within and leaving the security area;

9) an emergency action plan for protection of classified information;

10) notification of a person who has attempted, in any manner, to gain unlawful access to classified information, and notification of violation of the requirements of the State Secrets and Classified Information of Foreign States Act or legislation issued on the basis thereof;

11) list of all such procedures, guidelines and other rules in force regulating the processing of state secrets in the processing entity;

12) method of and procedure for destruction of classified media;

13) scope of the administrative area;

14) procedure for bringing into the security area a weapon and a technical device or another object that can be used as technical means for collection of data;

15) procedure for notification of the loss, suspicion of loss of entry permits or means ensuring entry or of the loss of other possession;

16) appointment of a person with whom a spare key to the lock and lock codes for the safe used to store media classified at the ‘confidential’ and higher level of classification must be deposited for safekeeping.

17) the procedure for determining the classification level of information classified as a state secret which may be classified at more than one level in accordance with this Regulation.

(2) In addition to the provisions specified in subsection 1, the guidelines on the protection of classified information may provide, for example:

1) procedure for the receipt and transmission of classified media within the processing entity (within the limits of the security area, through the administrative area);

2) a specific procedure for transmitting classified media;

3) procedure for reproduction of classified media;

4) procedure for inspection rounds by the local manned guard;

5) specifics of the entry permits for persons with the right of independent entry to the security area compared to the persons who work at the same processing entity;

6) specifics of allowing a visitor to enter the security area compared to the persons who work at the same processing entity;

(3) The part of the guidelines on the protection of classified information, which must be classified, is established as an annex to the guidelines or as a separate document.

§ 23. Töötleva üksuse riigisaladuse kaitset korraldava isiku või struktuuriüksuse ja infoturbejuhi tegevusele esitatavad nõuded

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Töötleva üksuse riigisaladuse kaitset korraldav isik või struktuuriüksus peab:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

korraldama salastatud teabe kaitset ning «Riigisaladuse ja salastatud välisteabe seaduse» ja selle alusel antud aktide nõuetest kinnipidamist;

nõustama töötajaid salastatud teabe töötlemisel;

korraldama juurdepääsuõigust omavate isikute koolitust salastatud teabe kaitse küsimustes, sealhulgas elektroonilise teabeturbe alal;

korraldama turvaala valvurite tööd ja teostama järelevalvet nende tegevuse üle, kui seda ülesannet ei ole antud teisele ametiisikule;

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

pidama arvestust töötajate riigisaladusele juurdepääsu lubade ja juurdepääsusertifikaatide üle ning tagama, et riigi julgeoleku volitatud esindajal on ajakohane info „Riigisaladuse ja salastatud välisteabe seaduse“ § 20 lõike 5 alusel määratud ametikohtade kohta;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

pidama arvestust salastatud teabekandjate üle ning kontrollima nende olemasolu ja terviklikkust vastavalt §-le 23¹;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

pidama seifide kasutajate nimekirja;

edastama iga 90 päeva järel vastavalt Kaitsepolitseiametile, Kaitseväele või Välisluureametile info juurdepääsuluba mitteomavate isikute ametisse nimetamisest ametikohale, millel on ette nähtud piiratud tasemel riigisaladusele juurdepääsu õigus, samuti sellisel ametikohal oleva isiku ametikohalt vabastamisest ning teenistusvälistele isikutele piiratud taseme riigisaladusele juurdepääsu lubamise otsustamisest;

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

korraldama elektroonilise teabeturbe nõuete täitmist ja andma Välisluureametile sellekohast teavet viimase nõudmisel;

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

osalema süsteemi turbejuhendi ja kasutusjuhendi väljatöötamises ning tagama nende tutvustamise ja kättesaadavuse;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

määrama kindlaks isikud, kes omavad töötlussüsteemile või selle osale juurdepääsu õigust, ning juurdepääsuõiguse sisu ja ulatuse, kui seda ei ole määranud töötleva üksuse juht;

tagama teabele juurdepääsu andvate füüsiliste ja elektrooniliste vahendite väljastamise ning selliste vahendite perioodilise vahetamise ja nende üle arvestuse pidamise;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

omama ülevaadet töötlussüsteemide hooldamise ja remontimise ning nende konfiguratsiooni muutmise dokumentatsioonist;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

selgitama välja sündmuse või protsessi mittetoimumise või töötlussüsteemi volitustevastase kasutamise asjaolud;

teavitama viivitamatult Kaitsepolitseiametit ja vastavalt Kaitseväge, Välisluureametit või riigi julgeoleku volitatud esindajat, kui talle on teatavaks saanud «Riigisaladuse ja salastatud välisteabe seaduse» ning selle alusel antud õigusaktidest tulenevate nõuete rikkumine või teabe teatavaks saamine vastava taseme juurdepääsuõigust mitteomavale isikule;

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

teavitama viivitamata käesoleva määruse § 103 lõikes 2 sätestatud erandi kasutamisest ja seda kasutanud isikust kirjalikult Kaitsepolitseiametit ning salastatud välisteabe edastamise korral riigi julgeoleku volitatud esindajat, välja arvatud riigisaladuse ja salastatud välisteabe seaduse § 52 lõikes 3 sätestatud juhul;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

korraldama nende teavituste säilitamise ja hävitamise, mis on esitatud sellistesse välisriikidesse reisimise kohta, mille kohta kehtib teatamiskohustus;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

võtma seletusi isikutelt, kes on rikkunud «Riigisaladuse ja salastatud välisteabe seaduse» või selle alusel antud õigusakti nõudeid.

Töötlussüsteemi eest vastutava töötleva üksuse infoturbejuht peab osalema töötlussüsteemi:

turvariskide hindamisel;

oluliste muudatuste planeerimises;

turbejuhendi ja kasutusjuhendi väljatöötamises.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Töötleva üksuse riigisaladuse kaitset korraldaval isikul või struktuuriüksuse asjaomastel töötajatel või ametnikel peab olema töötleva üksuse töödeldava teabe kõrgeimale salastatuse tasemele vastav juurdepääsuõigus.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemi eest vastutava töötleva üksuse infoturbejuhil peab olema töötlussüsteemis töödeldava teabe kõrgeimale salastatuse tasemele vastav juurdepääsuõigus.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 23. Requirements for activities of person or structural entity organising protection of state secret at processing entity and chief information security officer (järg)

(1) The person or structural entity of the processing entity organising the protection of state secret is required to:

1) organise the protection of state secrets and compliance with the requirements of the State Secrets and Classified Information of Foreign States Act and legislation issued on the basis thereof;

2) advise employees on the processing of classified information;

3) organise the training of persons with the right of access on issues of the protection of classified information, including in the area of electronic information security;

4) organise the work of the guards of the security area and supervise their activities unless such duty is assigned to another official;

6) keep records of the national Personnel Security Clearance and Personnel Security Clearance Certificates of the employees and ensure that the Estonian National Security Authority has up-to-date information on the posts assigned in accordance with subsection 5 of § 20 of the State Secrets and Classified Information of Foreign States Act;

7) keep records of classified media and verify their existence and integrity in accordance with § 23¹;

8) keep a list of persons who use safes;

9) communicate every 90 days information to the Estonian Internal Security Service, the Defence Forces or the Estonian Foreign Intelligence Service respectively concerning the appointment of persons who do not hold Personnel Security Clearance to posts where the right of access to state secrets classified as ’restricted’ is required, as well as information on the release from the post of a person in such a post and on the decisions to approve the access to state secrets classified as ‘restricted’ to persons outside the service;

10) organise compliance with the requirements of electronic information security and communicate corresponding information to the Estonian Foreign Intelligence Service at their request;

12) participate in the development of the security guide and user guide for the system and ensure that they are made available and accessible;

13) determine the persons who have the right of access to the processing entity or a part thereof, and the content and extent of the right of access unless it has been determined by the head of the processing entity;

14) ensure the issue of physical and electronic means enabling access to information and the periodic exchanging and keeping records of such means;

15) have an overview of the records on the maintenance and repair of the processing systems and of any modifications of their configuration;

17) ascertain the circumstances of non-occurrence of an event or process or of the unauthorised use of the processing system;

18) immediately inform the Estonian Internal Security Service and correspondingly, the Defence Forces, the Estonian Foreign Intelligence Service or the Estonian National Security Authority of becoming aware of a violation of the requirements arising from the State Secrets and Classified Information of Foreign States Act or legislation issued on the basis thereof or of the disclosure of classified information to a person who does not have right of access to information of the corresponding level of classification;

18¹) notify immediately in writing the Estonian Internal Security Service and, in the case of communicating foreign classified information, the Estonian National Security Authority of the use of exemption provided in subsection 2 of § 103 of this Regulation and of the person who has used it except in the cases provided in subsection 3 of § 52 of the State Secrets and Classified Information of Foreign States Act;

18²) organise the storage and destruction of such notifications which are submitted concerning travelling to such countries for which notification obligation applies;

19) take explanations from persons who have violated the requirements of the State Secrets and Classified Information of Foreign States Act or legislation issued on the basis thereof.

(1¹) The chief information security officer of the processing entity in charge of the processing system must participate in the following of the processing system:

1) security risk assessment;

2) the planning of significant changes;

3) the development of security guides and user guides.

(2) The person organising the protection of state secrets of the processing entity or the relevant employees or officials of the structural unit must have the right of access to the information at the highest classification level processed by the processing entity.

(3) The chief information security officer of the processing entity in charge of the processing system must have the right of access to information at the highest classification level processed in the processing system.

§ 23¹. Teabekandjate kontrollimine

Töötlev üksus kontrollib tema valduses olevaid salajasel ja täiesti salajasel tasemel salastatud teavet sisaldavaid registreeritud teabekandjaid järgmiselt:

füüsilise teabekandja olemasolu ja terviklikkust kontrollitakse vähemalt kord aastas vahetult;

töötlussüsteemiga püsivalt ühendamata salvestuskandja olemasolu kontrollitakse vähemalt kord aastas vahetult;

töötlussüsteemiga püsivalt ühendatud salvestuskandja olemasolu kontrollitakse vähemalt kord aastas töötlussüsteemi tarkvara abil, sobivate vahendite puudumise korral vahetult;

faili olemasolu kontrollitakse vähemalt kord aastas töötlussüsteemi tarkvara abil või pisteliselt vahetult.

Arhiivihoidlas olevate salajasel ja täiesti salajasel tasemel salastatud teavet sisaldavate registreeritud teabekandjate olemasolu ja terviklikkust kontrollitakse lõikes 1 nimetatud viisil vähemalt kord viie aasta jooksul.

Teabekandjaid kontrollinud füüsiline isik vormistab kontrolli tulemused kirjalikku taasesitamist võimaldavas vormis ja esitab need töötleva üksuse riigisaladuse kaitset korraldavale isikule.

Töötlussüsteemi tarkvara abil tehtud kontrolli tulemused võib salvestada logifailidena.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 23¹. Verification of media

(1) A processing entity verifies registered media in their possession containing ‘secret’ and ‘top secret’ classified information as follows:

1) the existence and integrity of the physical medium is verified directly at least once a year;

2) the existence and integrity of the storage medium, which is not permanently connected to the processing system, is verified directly at least once a year;

3) the existence of the storage medium permanently connected to the processing system is verified at least once a year by means of the software of the processing system, or in the absence of suitable means directly;

4) the existence of a file is checked at least once a year by means of the software of the processing system, or at random directly.

(2) The existence and integrity of the recorded media containing information classified as ‘secret’ and ‘top secret’ located in the archive repository is verified in the manner specified in subsection 1 at least once every five years.

(3) The natural person who has verified the media records the results of the verification in a form that can be reproduced in writing and submits them to the person organising the protection of state secrets in the processing entity.

(4) The results of the verifications carried out by means of the software of the processing system may be recorded in the form of log files.

[

§ 23². Mitmel tasemel salastatava teabe salastatuse taseme määramine

Kui töötleva üksuse salastatud teabe kaitse juhendis ei ole reguleeritud selle riigisaladuseks oleva teabe salastatuse taseme määramise korda, mida võib käesoleva määruse kohaselt salastada mitmel tasemel, tuleb teave salastada teabe salastamise aluses sätestatud kõrgeimal salastatuse tasemel.

[RT I, 24.09.2024, 3 – вступ. в силу 01.10.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 23². Determination of the classification level of information subject to classification at multiple levels

Unless the guidelines for the protection of classified information of the processing entity regulates the procedure for determining the classification level of the information classified as a state secret, which may be classified at multiple levels in accordance with this Regulation handled by the processing entity, the information must be classified at the highest classification level provided in the grounds for classification of information.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 1. jaotis Turvaala üldnõuded

§ 24. Turvaala üldnõuded

Turvaalal peab olema määratletud ja kaitstud välispiir, millel on võimalik kontrollida kõiki sisse- ja väljapääse, ning sisse- ja väljapääsukontrolli süsteem, mis võimaldab turvaalale iseseisvalt siseneda ainult nõutava tasemega juurdepääsuõigusega isikul.

Ala turvaalana kasutamine peab olema eelnevalt kooskõlastatud vastavalt Kaitsepolitseiameti, Kaitseväe või Välisluureametiga.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Kaitsepolitseiamet, Kaitsevägi või Välisluureamet võivad teha käesolevas määruses sätestatud turvaalale esitatavates nõuetes konkreetse hoone või töötleva üksuse suhtes erandeid, kui nõuete rakendamine ei ole tehniliselt või seadusest tulenevatel põhjustel võimalik või kui turvaala nõuetekohasuse võib tagada muude meetmete abil.

[RT I, 19.08.2014, 17 – вступ. в силу 22.08.2014]

Turvaala üldisi nõudeid kohaldatakse ajutisele ja liikuvale turvaalale niivõrd, kuivõrd käesolevas määruses ei ole sätestatud teisiti.

Turvaalale esitatavad nõuded täpsustatakse juhendis, mille töötab välja Kaitsepolitseiamet koostöös Kaitseväe ja Välisluureametiga.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Ala turvaalana kasutamise lõpetamisel tuleb sellest teavitada kooskõlastanud asutust 30 päeva jooksul kasutamise lõpetamisest arvates.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 24. General requirements for security area

(1) A security area must have a defined and protected external border, at which it is possible to control all the entrances and exits, and an entry and exit control system that allows only a person with the required level of access rights to enter the security area independently.

(2) The use of an area as a security area must be priorily coordinated with the Estonian Internal Security Service, the Defence Forces or the Estonian Foreign Intelligence Service respectively-

(3) The Estonian Internal Security Service, the Defence Forces or the Estonian Foreign Intelligence Service may grant exemptions from the requirements for security areas provided in this Regulation with regard to a specific building or processing entity in case the application of the requirements is not technically possible or it is impossible due to reasons arising from law, or in case the compliance with the requirements for the security area may be guaranteed by other means.

(4) The general requirements for the security area are applied to the temporary and mobile security areas in so far as it is not provided otherwise in this Regulation.

(4¹) The requirements for a security area are specified in the guidelines developed by the Estonian Internal Security Service in cooperation with the Defence Forces and the Foreign Intelligence Service.

(5) Upon termination of the use of an area as a security area, the authority which granted their approval for such a use is informed thereof within 30 days as of the termination of the use.

§ 25. Turvaala asukoht

Töötleva üksuse turvaala peab asuma tema otseses valduses olevates ruumides.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Enne turvaala rajamise planeerimist tuleb konsulteerida kooskõlastamiseks pädeva asutuse esindajatega, et määrata turvaala parim asukoht hoones.

Võimaluse korral ei rajata turvaala hoone esimesele ega viimasele korrusele.

Võimaluse korral tuleb turvaala asukoht hoones valida selliselt, et akende olemasolul avaneksid need riigisaladust töötleva asutuse valduses olevale territooriumile.

Riigisaladust ja salastatud teabekandjaid töötlevad isikud ja struktuuriüksused tuleb võimaluse korral paigutada asutuses lähestikku, näiteks ühte ja samasse ruumi või hoone ühte tiiba.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 25. Location of security area

(1) A security area of the processing entity must be located in the premises which are in the direct possession of the processing entity.

(2) Before planning the establishment of a security area, the representatives of the authority competent to grant approval must be consulted in order to determine the best possible location for the security area in the building,

(3) Where possible, a security area is not be established on the first or last floor of a building.

(4) Where possible, the location of a security area in a building is chosen so that in case there are windows they would face the territory in the possession of the authority processing state secrets.

(5) Persons and structural entities which process state secrets and classified media must be located, where possible, in a close proximity to each other, for example, in one and the same room or one and the same wing of a building in the authority.

§ 26. Liikuv ja ajutine turvaala

Erandkorras võib turvaala rajada ka liikuvatele platvormidele (edaspidi liikuv turvaala) või aladele, mis tavaliselt ei ole kasutuses turvaalana (edaspidi ajutine turvaala). Liikuvaks ja ajutiseks turvaalaks võib olla näiteks sõiduk, haagis, laev, punker, konteiner, soojak, telk, ülesande täitmiseks sobiv olemasolev ehitis. Võimaluse korral tuleb ajutise turvaalana kasutada püsiehitist.

[RT I 2008, 55, 312 – вступ. в силу 01.01.2009]

Sellise turvaala kasutusele võtmine tuleb eelnevalt kooskõlastada vastavalt Kaitsepolitseiameti, Kaitseväe või Välisluureametiga. Liikuva või ajutise turvaala kooskõlastamist taotleval asutusel tuleb kooskõlastuse saamiseks esitada kooskõlastavale asutusele kirjalik taotlus vähemalt 30 päeva enne sellise turvaala kasutusele võtmist.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Julgeolekuasutus võib võtta liikuva või ajutise turvaala kasutusele oma juhi või tema volitatud isiku otsusel ilma lõikes 2 sätestatud teise julgeolekuasutuse kooskõlastuseta. Liikuva või ajutise turvaala kasutuselevõtmisel teavitab julgeolekuasutus teist julgeolekuasutust kirjalikult esimesel võimalusel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kaitsevägi võib võtta lisaõppekogunemise korraldamise otsuse järel lisaõppekogunemise ajaks liikuva või ajutise turvaala kasutusele Kaitseväe juhataja või tema volitatud ülema otsusel, teavitades sellest kirjalikult esimesel võimalusel Kaitseväes riigisaladuse kaitset korraldavat struktuuriüksust.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kiireloomulistel asjaoludel võib lõikes 2 nimetatud tähtaega lühendada kooskõlastava asutuse nõusolekul.

Liikuva või ajutise turvaala, millel töödeldakse salastatud välisteavet, kasutusele võtmise korral teavitab lõikes 2 nimetatud juhul kooskõlastuse andnud asutus ning lõigetes 2¹ ja 2² nimetatud juhul turvaala kasutusele võtnud asutus riigi julgeoleku volitatud esindajat kirjalikult esimesel võimalusel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Liikuvale ja ajutisele turvaalale kohaldatakse võimalusel kõiki turvaala nõudeid, võimaluse puudumisel tagatakse salastatud teabe turvalisus muude meetmetega.

Eriolukorra, erakorralise seisukorra, kõrgendatud kaitsevalmiduse, sõjaseisukorra, mobilisatsiooni ja demobilisatsiooni ajal võib liikuva või ajutise turvaala luua iga riigisaladust või salastatud välisteavet valdava asutuse juhi suulise korralduse alusel. Suuliselt antud korraldus tuleb esimesel võimalusel ka kirjalikult jäädvustada. Asutused, kelle tegevus eeldab nimetatud olukordades liikuva või ajutise turvaala loomist, peavad kajastama sellekohase info asutuse ja teiste tasandite, näiteks maakonna ja ministeeriumi kriisiplaanides ning teavitama sellest kooskõlastavat asutust.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Liikuval ja ajutisel turvaalal töödeldakse vaid konkreetse ülesande täitmiseks vajalikke salastatud teabekandjaid. Kui töötlemisvajadus on lõppenud, viiakse salastatud teabekandjad viivitamata alalisele turvaalale.

Liikuva või ajutise turvaala koha valikul tuleb eelkõige arvestada ülesande tõhusat ja turvalist täitmist.

Asutuse juht peab määrama isiku, kes vastutab liikuval või ajutisel turvaalal salastatud teabekandjate kaitseks rakendatavate julgeolekumeetmete eest (edaspidi vastutav isik).

Kui turvaala kasutamisel ilmneb lahknevusi eelnevalt kooskõlastamisele esitatud andmetest, siis tuleb vastutaval isikul sellest kirjalikult teavitada kooskõlastavat asutust hiljemalt 30 päeva pärast muudatuse toimumist.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 26. Mobile and temporary security area

(1) As an exception, a security area may also be established on moving platforms (hereinafter mobile security area) or areas which are not usually used as a security area (hereinafter temporary security area). A vehicle, trailer, ship, bunker, container, site accommodation, tent, or other existing construction works suitable for such function may be used as mobile or temporary security areas. Where possible, a permanent structure must be used as a temporary security area.

(2) The introduction of such a security area must be priorily coordinated with the Estonian Internal Security Service, the Defence Forces or the Estonian Foreign Intelligence Service respectively. An authority applying for the coordination of a mobile or temporary security area is required to submit a written request for such coordination to the coordinating authority at least 30 days before the introduction of such a security area.

(2¹) A security authority may take into use a mobile or temporary security area by the decision of its head or a person authorised thereby without the coordination of another security authority specified in subsection 2. The security authority notifies the other security authority in writing at the earliest opportunity of the taking into use of a mobile or temporary security area.

(2²) Following a decision to organise an additional reservist training, the Defence Forces may take into use a mobile or temporary security area for the duration of the additional reservist training by the decision of the Commander of the Defence Forces or a commander authorised thereby, informing in writing the structural unit in the Defence Forces organising protection of state secret at the earliest opportunity.

(3) In urgent circumstances, the time limit specified in subsection (2) may be shortened with the consent of the coordinating authority.

(3¹) In the event of the taking into use of a mobile or temporary security area, in which the foreign classified information is processed, in the case specified in subsection 2 the coordinating authority and in the case specified in subsections 2¹ and 2² the authority which has taken into use the security area informs the Estonian National Security Authority in writing at the earliest opportunity.

(4) Where possible, all the requirements for security areas are applied to mobile and temporary security areas and, where not possible, the security of classified information is guaranteed by other means.

(5) During an emergency situation, a state of emergency, increased defence readiness, state of war, mobilisation and demobilisation the mobile and temporary security areas may be established based on an oral order by the head of the authority in possession of a state secret or foreign classified information. An order given orally is recorded also in writing at the first opportunity. Agencies whose activities presume, under such circumstances, the establishment of a mobile or temporary security area must provide information to this effect in the crisis management plans of the agencies themselves, as well as in the plans of other levels, such as counties and ministries, and inform the coordinating authority thereof.

(6) Only the classified media needed for the performance of a particular task is processed within a mobile or temporary security area. After termination of the need for processing, the classified media is moved to a permanent security area immediately.

(7) Upon choosing a location for a mobile or temporary security area, above all, the efficient and safe performance of the task must be given priority.

(8) The head of an authority must appoint a person who is responsible for the security measures to be applied for the protection of classified media within a mobile or temporary security area (hereinafter responsible person).

(9) In case discrepancies from the data submitted for coordination become evident upon using the security area, the responsible person must notify the coordinating authority thereof in writing at the latest within thirty days after such modification took place.

§ 27. Turvaala sein, lagi ja põrand

Turvaala sein, lagi ja põrand peavad olema valmistatud betoonist, terasest või kivist nii, et detaile, millest sein, lagi või põrand koosneb, ei oleks võimalik väljastpoolt lihtsalt eemaldada.

Kahe turvaala vaheline sein või turvaala sisesein võivad olla kergkonstruktsiooniga. Turvaala välissein, lagi või põrand võib olla kergkonstruktsiooniga, kui hoones on pidev mehitatud valve või kui neid on tugevdatud füüsiliste tõkete lisamisega või tehniliste valveseadmetega.

Turvaala helipidavus peab olema selline, et seal toimuv ei kostaks ümbritsevatesse ruumidesse.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 27. Walls, ceiling and floor of security area

(1) The walls, ceiling and floor of a security area must be made of concrete, steel or stone so that the details of which the walls, ceiling or floor consist of could not be easily removed from outside.

(2) A wall between two security areas or an internal wall within a security area may be of a light construction. The exterior walls, ceiling or floor of a security area may be of a light construction in case a permanent manned guard is present in the building or in case they have been strengthened by adding physical barriers or technical surveillance equipment.

(3) A security area must be soundproofed to the extent where sounds originating from such an area would not be heard in the neighbouring premises.

§ 28. Turvaala uks

Turvaala välispiiril asuv uks (edaspidi turvaala uks) peab olema kooskõlastava asutuse hinnangul piisavalt turvaline, et valvepersonal jõuaks sissetungikatsele reageerida enne, kui sissetungija on ületanud füüsilised tõkked.

Turvaala ukse hingedepoolsel küljel peavad olema turvatapid, mis ukse sulgemisel sulguvad lengi sisse. Turvaala uksel peab olema automaatne sulgur, mis tagab ukse iseenesliku sulgumise määratud aja jooksul, ja andur, mis annab märguande, kui uks on olnud avatud üle määratud aja.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Kui nõuetekohast turvaala ust ei ole võimalik paigaldada, tuleb turvaala ust valvata täiendavate valve- ja häiresüsteemiseadmetega.

Turvaala uks peab olema varustatud vähemalt kahe lukuga, millest vähemalt üks peab olema automaatselt lukustuv ja vähemalt üks mehaaniline turvalukk. Turvaluku keel peab olema kaitstud.

Turvaala mehaanilised ukselukud ei tohi olla avatavad sama võtmega, millega saab avada hoones asuvaid teisi mehaanilisi ukselukke. Kui seda nõuet ei ole võimalik järgida, tuleb võtmeid hoida samadel tingimustel seifivõtmetega.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 28. Door to security area

(1) The door at the external border of a security area (hereinafter door to security area) must be, in the opinion of the coordinating authority, sufficiently secure to allow the security guards to react to attempted intrusion before the intruder has crossed the physical barriers.

(2) The hinge side of the security door must be provided with security latches which close into the frame upon closing the door. The door to the security area must be equipped with an automatic closing device that ensures that the door closes automatically within a predetermined time, and a sensor which gives a signal in case the door has been open for longer than assigned.

(3) In case a proper door to the security area cannot be installed, the door to the security area must be guarded with additional surveillance and alarm system equipment.

(4) The door to the security area must be fitted with at least two locks, at least one of which must lock automatically, and with at least one mechanical security lock. The tumbler of the security lock must be protected.

(5) Mechanical locks of the security area cannot be openable with the same key with which other mechanical locks in the building can be opened. In case this requirement cannot be met, the keys must be stored under the same conditions as the keys to a safe.

§ 29. Turvaala aken

Kergesti ligipääsetavas kohas, näiteks katusel, rõdul ja hoonelaiendusel asuv turvaala aken tuleb varustada sissemurdmist takistavate turvaelementidega. Vajaduse korral tuleb kasutada akna turvalisuse suurendamiseks muid füüsilisi tõkkeid või valve- ja häiresüsteemiseadmeid.

Turvaala aken tuleb katta kardina või toonkilega, et väljastpoolt ei oleks võimalik jälgida turvaalal toimuvat.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 29. Window of security area

(1) The window of a security area located at an easily accessible place, such as a roof, terrace or on the extension of the building, must be fitted with anti-burglar security elements. Other physical barriers or security or alarm system equipment must be used to increase the safety of a window, where necessary.

(2) The windows of a security area must be covered with a curtain or toned film so that it would not be possible to observe from the outside what is going on inside the security area

§ 30. Turvaala muu avaus

Turvaalal asuv muu avaus peab olema kaitstud füüsiliste tõkete või valve- ja häiresüsteemiseadmetega, et välistada turvaalale tehniliste seadmete ebaseaduslik paigaldamine või turvaalal hoitaval salastatud teabekandjal sisalduva teabe muul viisil ohustamine.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 30. Other opening of security area

Other opening located in a security area must be protected with physical barriers or security and alarm system equipment to prevent the unlawful installation of technical equipment in the security area or other danger to the information contained in the classified media stored within the security area.

§ 31. Avatud hoiuala

Avatud hoiuala välissein, lagi ega põrand ei tohi olla kergkonstruktsiooniga.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 31. Open storage area

The external walls, ceiling or floor of an open storage area cannot be of a light construction.

§ 32. Liikuva ja ajutise turvaala konstruktsiooniline kaitse

Liikuval ja ajutisel turvaalal peab olema füüsilise tõkkega selgelt määratud ja kaitstud välispiire, milles on võimalik kontrollida kõiki sisse- ja väljapääse. Kooskõlastava asutuse nõudel peab muutma turvaala asukohta, tugevdama turvaala konstruktsiooni ja kasutama lisapiirdeid.

Liikuva ja ajutise turvaala konstruktsioon peab tagama, et väljastpoolt oleks välistatud juurdepääs salastatud teabele või selle ohustamine.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 32. Structural protection of mobile and temporary security area

(1) A mobile or temporary security area must have an external boundary clearly defined and protected by a physical barrier which allows control over all entries and exits. At the demand of the coordinating authority, the location of the security area must be changed, the structure of the security area strengthened, and additional barriers used.

(2) The structure of a mobile or temporary security area must guarantee that access or danger to classified information from outside of the security area would be precluded.

§ 33. Evakuatsiooniplaan

Turvaala kohta peab olema koostatud ohuolukorras tegutsemiseks salastatud teabekandjate evakuatsiooniplaan.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Evakuatsiooniplaanis peavad olema kajastatud erinevad võimalikud ohuolukorrad, millal tuleb salastatud teabekandjad evakueerida või hävitada.

Lõike 2 alusel määratletud iga ohuolukorra kohta tuleb ette näha, kuidas toimub evakuatsioon või hävitamine, kes seda korraldavad, milliseid vahendeid selleks kasutatakse, kuhu evakueeritakse salastatud teabekandjad.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 33. Evacuation plan

(1) A plan for evacuation of classified media in the case of emergency situation must be prepared with regard to a security area.

(2) The evacuation plan must set out all the possible emergencies in the case of which classified media must be evacuated or destroyed.

(3) For each emergency situation defined on the basis of subsection 2, it must be prescribed how the evacuation or destruction is carried out, who organises it, what means are used for this purpose, where classified information is evacuated.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 2. jaotis Turvaala valve nõuded

§ 34. Turvaala valve üldnõuded

Turvaala valvamiseks peab olema valve- ja häiresüsteem (edaspidi valveseadmestik), läbipääsusüsteem ja mehitatud valve.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Turvaala valveseadmestik ja läbipääsusüsteem koos füüsilise kaitse meetmetega peavad tagama, et mehitatud valve jõuab reageerida sissetungikatsele enne, kui sissetungija on ületanud füüsilised tõkked.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Turvaala või selle osa peab olema valve all, kui sellel ei viibita.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 34. General requirements for guarding of security area

(1) A surveillance and alarm system (hereinafter surveillance equipment), an access system and a manned guarding must be provided for guarding the security area.

(2) The surveillance equipment and the access system of the security area, together with the physical protection measures, must ensure that the manned guard would be able to respond to an intrusion attempt before the intruder has crossed the physical barriers.

(3) The security area or part thereof must be under surveillance when it is not occupied.

§ 35. Valveseadmestiku nõuded

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Valveseadmestik peab:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

andma häire kohe mehitatud valvele ja töötleva üksuse juhi määratud isikule, kui toimub sissetung või selle katse või kui on tekkinud valveseadmestiku rike;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

võimaldama turvaala valvet eraldi sisse ja välja lülitada;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

automaatselt tuvastama valveseadmestiku rikked;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

võimaldama koostoimes läbipääsusüsteemiga kindlaks teha isiku turvaalale ning võimaluse korral ka turvaala osasse sisenemise ja sealt väljumise;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

võimaldama elektrooniliselt tuvastada turvaala valve sisse- ja väljalülitamise, häire aja ning koostoimes läbipääsusüsteemiga isiku turvaalale ning võimaluse korral selle osasse sisenemise ja sealt väljumise. Nimetatud toimingu andmeid säilitatakse vähemalt üks aasta.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Riigisaladuse kaitseks kasutatava valveseadmestiku reservtoide peab tagama valveseadmestiku toimimise põhielektrisüsteemi tõrke korral turvaala mehitatud valve alla võtmiseni.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Valveseadmestiku keskseade ja selle juhtseade peavad asuma turvaalal. Administratiivalal võib asuda vaid selline juhtseade, mis võimaldab turvaala valvet juhtida või seadistada üksnes valveseadmestiku eriõigustega kasutajal või turvaala valvet üksnes sisse ja välja lülitada.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 35. Requirements for surveillance equipment

(1) The surveillance equipment must:

(1) immediately alert the manned guard and the person designated by the head of the processing entity in case an intrusion or attempted intrusion occurs or in case of a failure of the surveillance equipment has occurred;

3) enable to switch on and off separately the surveillance of the security area;

(4) automatically detect faults in the surveillance equipment;

5) in interaction with the access system, enable the identification of entry into and exit from the security area by a person and, where possible, also a part of the security area;

6) enable electronically identify the switching on and off of the security system, surveillance of the security area, activation and deactivation of the security of the security area, the alarm time and, in interaction with the access system, the entry into and exit from the security area of a person and, where possible, to the part thereof. The data of the specified act are kept for at least one year.

(3) The backup power supply of the surveillance equipment used for the protection of state secrets ensures the operation of the surveillance equipment in the event of a failure of the main electrical system until the security area is taken under manned guarding.

(4) The central unit of the surveillance equipment and its control unit must be located in the security area. Only such a control equipment may be located in the administrative area, which allows only the user with special rights to control or configure the surveillance of the security area, or only to switch the surveillance of security area on and off.

§ 36. Liikuva ja ajutise turvaala mehitatud valve

Liikuvat või ajutist turvaala peavad kaitsma liikuvad või püsipositsioonidel relvastatud valvurid, kes jälgivad kogu kaitstavat ala. Turvaala valvamiseks võib kasutada nii valvemeeskonna valvureid kui ka turvaalal ööpäevaringselt töötavaid instrueeritud isikuid.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui liikuva või ajutise turvaala pidevat mehitatust ei suudeta tagada, siis tuleb liikuvale või ajutisele turvaalale paigaldada häiresüsteem, mis edastab häire valvemeeskonnale või instrueeritud turvaala töötajatele, kes peavad jõudma turvaalale kooskõlastava asutusega kooskõlastatud reageerimisaja jooksul. Reageerimisaeg ei tohi olla pikem ajast, mis kulub sissetungijal füüsiliste tõkete ületamiseks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 36. Manned guarding of mobile and temporary security areas

(1) A mobile or temporary security area must be protected by mobile or stationary armed guards, who monitor the entire protected area. The surveillance of the security area may be carried out by guards of the guarding team as well as by instructed persons working 24 hours a day in the security area.

(2) In case the continuous staffing of a mobile or temporary security area cannot be ensured, an alarm system must be installed in the mobile or temporary security area, which transmits the alarm signal to the guarding team or instructed security area personnel, who must arrive at the security area within the response time agreed with the coordinating authority. The response time may not exceed the time that it takes the intruder to overcome the physical barriers.

§ 38. Kohapealse mehitatud valve õigus juurdepääsuks riigisaladusele

Turvaalal ringkäiku tegeval kohapealsel mehitatud valvel peab olema vähemalt selle taseme riigisaladusele juurdepääsu luba, mis tasemel salastatud teavet kontrollitaval turvaalal töödeldakse.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 38. Right of on-site manned guard to access state secrets

On-site manned guard patrolling the security area must have the national Personnel Security Clearance at least at the level at which classified information is being processed within the security area under surveillance.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 3. jaotis Isikute viibimine ja töötamine turvaalal

§ 39. Isikute viibimine turvaalal

Isikute turvaalal viibimise korraldus peab arvestama isiku riigisaladusele juurdepääsu õigust, teadmisvajadust ning tegema kindlaks isiku turvaalale sisenemise ja sealt väljumise.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 39. Presence of persons in security area

The procedure for presence of persons in a security area must take account of the right of access and need-to-know of a person and must identify the entry into and exit from the security area by persons.

§ 40. Iseseisva sissepääsuõigusega isiku pääs turvaalale

Turvaalale iseseisva sissepääsuõigusega isikule antakse sissepääsuluba, millele kantakse loa number. Sissepääsuluba ei pea andma, kui turvaala koosneb ühest või kahest ruumist.

Töötlev üksus peab pidama arvestust turvaalale pääsevate isikute sissepääsuõiguse, sissepääsu tagavate vahendite ja sissepääsulubade üle.

Turvaalal töötav isik kannab sissepääsuluba nähtaval kohal, et oleks võimalik tuvastada tema isik. Sissepääsuloa nähtaval kohal kandmise nõue ei kehti julgeolekuasutuste puhul. Väljaspool turvaala ja administratiivala ei tohi sissepääsuluba nähtaval kohal kanda.

Turvaala sisse- ja väljapääsukorraldus peab tagama iseseisva sissepääsuõigusega isikute tuvastamise sisenemisel ja väljumisel.

Sissepääsuloa või sissepääsu tagava eseme kaotamise, kaotamiskahtluse või muu valduse kaotuse korral tuleb sellest viivitamata teavitada töötlevas üksuses määratud isikut, kes võtab meetmed sissepääsuloa või sissepääsu tagava eseme kasutamise takistamiseks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 40. Access of persons with independent right of access to security area

(1) A person who has an independent right of access to a security area is issued an entry permit in which the number of the permit is entered. An entry permit need not be issued in case the security area consists of only one or two rooms.

(2) A processing entity must keep record of the right of access, means of access and entry permits of persons with the right of access to the security area.

(3) The person working in the security area must wear the entry permit in a visible place so as to enable identification of the person. The requirement to carry the permit in a visible place does not apply to security authorities. Outside the security area and the administrative area, the permit must not be carried in a visible place.

(4) The procedure for entry into and exit from a security area must ensure the identification of persons with an independent right of access upon entry and exit.

(5) In the case of loss, suspected loss of an entry permit or an object ensuring entry or loss of other possession, notice thereof must be immediately given to the duly appointed person in the processing entity, who take measures for preventing the use of the entry permit or an object ensuring entry.

§ 41. Külalise viibimine turvaalal

Turvaalale võib lubada külalise töötleva üksuse salastatud teabe kaitse juhendis sätestatud korras.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Külalisele antakse numbriga külastusluba, millele on märgitud sõna «KÜLALINE» ja mis võimaldab tuvastada loa saanud isiku. Külaline peab kandma külastusluba nähtaval kohal.

Külastusluba ei pea väljastama:

kui turvaala koosneb ühest või kahest ruumist;

riiklikult olulise välisvisiidi või kõrgete külaliste Eesti visiidi delegatsiooni liikmele.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Külastusloa andmine ja selle tagastamine, külalise saabumise ja lahkumise aeg, külalise ees- ja perekonnanimi tuleb registreerida. Külaline tuleb identifitseerida kehtiva isikut tõendava dokumendi alusel. Riiklikult olulise välisvisiidi või kõrgete külaliste Eesti visiidi delegatsiooni liikme võib identifitseerida muul viisil.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Külaline võib turvaalal liikuda üksnes koos vastuvõtjaga või temale määratud saatjaga. Külalist on keelatud jätta turvaalale üksinda, välja arvatud juhul, kui külalisel on õigus juurde pääseda selle taseme riigisaladusele, mida turvaalal töödeldakse, ning arvestades teadmisvajaduse põhimõtet.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 41. Presence of visitors in security area

(1) A visitor may be admitted to the security area in accordance with the procedure provided in the guidelines on the protection of the classified information of the processing entity.

(2) A visitor is issued a numbered visitor's permit, which has the word KÜLALINE [visitor] on it, and enables the identification of the person who has been granted the permit. A visitor must carry the visitor's permit in a visible place.

(3) A visitor’s permit need not be issued:

1) in case the security area consists of one or two rooms;

2) to a member of a delegation of a foreign visit of national importance or of high-ranking guests visiting Estonia.

(4) The issue and return of the visitor’s permit, the time of arrival and departure of the guest, the given name and surname of the guest must be recorded. The guest must be identified based on a valid identity document. A member of a delegation of a foreign visit of national importance or of high-ranking guests visiting Estonia may be identified in another manner.

(5) A visitor may move within the security area only together with the host or with the person assigned to escort the visitor. It is prohibited to leave the visitor alone in the security area unless the visitor has the right of access to the corresponding level of classification of state secrets which are processed in the security area, taking account of the need-to-know principle.

§ 42. Liikuval ja ajutisel turvaalal töötamise nõuded

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Ajutise turvaala eest vastutav isik peab turvaala kolimise korral hüljatud turvaala üle vaatama ja veenduma, et alale ei ole jäänud salastatud teabekandjaid.

Kui töö ajutisel turvaalal on lõppenud, tuleb salastatud teabekandjad toimetada asutuse alalisele turvaalale andmete võrdlemiseks ja eesmärgi täitnud materjali hävitamiseks.

Ajutise turvaala olemasolevaid füüsilise julgeoleku meetmeid tuleb vajaduse korral tugevdada ka pärast seda, kui turvaala kasutamine on kooskõlastatud.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 42. Requirements for working in mobile and temporary security areas

(1) In case of relocating the temporary security area the person responsible for the temporary security area must inspect the abandoned security area and make sure that there are no classified media left in the area.

(2) When the work in the temporary security area has been completed, the classified media must be delivered to the permanent security area of the authority for comparison of data and destruction of the material that have served their purpose.

(3) The physical security measures in place in the temporary security area must be strengthened, where necessary, also after the use of the security area has been coordinated.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 4. jaotis Salastatud teavet käsitleva koosoleku pidamise nõuded

§ 43. Koosoleku pidamise üldnõuded

Salastatud teavet käsitleva nõupidamise, koosoleku, konverentsi või muu kohtumise (edaspidi koosolek) korraldamiseks peavad olema täidetud järgmised nõuded:

salastatud teavet käsitleva koosoleku korraldaja ja tehnilise vahendi abil osalejad peavad tagama, et koosolekule on juurdepääs ainult isikutel, kellel on käsitletava taseme salastatud teabele juurdepääsu õigus ning teadmisvajadus;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

koosolekuruumis toimuvat ei või olla võimalik väljastpoolt näha ega kuulda.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 43. General requirements for conduct of meetings

In order to organise a consultation, meeting, conference or other gathering (hereinafter a meeting) dealing with classified information the following requirements must be complied with:

1) the organizer of a meeting dealing with classified information and the participants through the technical means must ensure that only the persons who have a right of access to the classified information at the level to be discussed and a need-to-know have access to the meeting;

2) what takes place within the meeting room cannot be heard or seen from outside.

§ 44. Koosoleku pidamine turvaalal ja administratiivalal

Koosoleku pidamiseks kasutatavad ruumid peavad asuma turvaalal.

Piiratud taseme riigisaladust käsitleva koosoleku läbiviimiseks kasutatavad ruumid võivad asuda ka administratiivalal ja neile ei pea kohaldama käesolevas jaos järgnevalt sätestatud nõudeid.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 44. Holding meetings within security area and administrative area

(1) The premises used for holding meetings must be located within the security area.

(2) Rooms which are used for the conduct of a meeting on state secrets classified as ‘restricted’ may also be located in an administrative area and the requirements provided in this subchapter need not be applied to the rooms.

§ 45. Koosolekuruumide kontrollimine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Perioodiliselt tuleb kontrollida, et koosolekuruumis ei oleks ebaseaduslikult teabe kogumise seadmeid.

Koosolekuruumis ei tohi koosoleku pidamise ajal olla ühtegi eelnevalt kontrollimata eset ega tehnilist vahendit, mida saab kasutada teabe ebaseaduslikuks kogumiseks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 45. Periodic checking of meeting rooms

(1) There must be periodic checking to ensure that there are no illegal information gathering devices in the meeting room.

(2) During the holding of a meeting, there must not be any previously unchecked item or technical device in the meeting room that can be used to illegally collect information.

]

§ 46. Koosoleku salvestamine ja koosolekul märkmete tegemine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Koosoleku salvestamine ja koosolekul märkmete tegemine on lubatud üksnes koosoleku korraldaja nõusolekul.

Iga koosolekul osaleja koosolekul tehtud salvestusi ja märkmeid sisaldavaid teabekandjaid töödeldakse vastavalt nendes sisalduva teabe salastatuse tasemele.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 46. Recording of meeting and taking notes at meeting

(1) Recording of a meeting and taking notes at a meeting is permitted only with the consent of the organiser of the meeting.

(2) The recordings made and the media containing the notes of each participant in the meeting are processed in accordance with the level of classification of the information contained therein.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 5. jaotis Administratiivala üldnõuded

§ 46¹. Administratiivala üldnõuded

Administratiivalal peab olema selgelt määratletud välispiir, millel on võimalik kontrollida kõiki sisse- ja väljapääse, ning sisse- ja väljapääsukontrolli süsteem, mis võimaldab tuvastada kõik sisenenud isikud ja sõidukid.

Administratiivalale esitatavad nõuded täpsustatakse juhendis, mille töötab välja Kaitsepolitseiamet koostöös Kaitseväe ja Välisluureametiga.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 46¹. General requirements for administrative area

(1) An administrative area must have a clearly defined external border at which all entrances and exits can be controlled, and an entry and exit control system that allows the identification of all the persons and vehicles that have entered.

(2) The requirements for the administrative area are specified in the guidelines that are drawn up by the Estonian Internal Security Service in cooperation with the Estonian Defence Forces and the Estonian Foreign Intelligence Service.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 1. jagu Turvaala ja administratiivala › 6. jaotis Salastatud teabe töötlemine turvaalal ja administratiivalal

§ 46². Salastatud teabe töötlemine turvaalal ja administratiivalal

Töötlev üksus töötleb oma valduses olevat salastatud teavet üldjuhul oma turvaalal.

Salastatud teabe töötlemine teise töötleva üksuse turvaalal on lubatud üksnes Kaitsepolitseiameti, Kaitseväe või Välisluureameti nõusolekul. Nimetatud nõusoleku andmisel piirdutakse nende turvaala nõuete hindamisega, mille täitmise tuvastamine oli turvaalal salastatud teabe töötlemise lubatavaks pidamise eelduseks.

Ilma lõikes 2 sätestatud kooskõlastava asutuse nõusolekuta võib salastatud teavet töödelda:

selle töötleva üksuse turvaalal, kelle ametnikul või töötajal on konkreetse töödeldava teabe suhtes teadmisvajadus, tingimusel, et see ametnik või töötaja viibib vahetult teabe töötlemise juures;

julgeolekuasutuse turvaalal;

välisesinduse turvaalal;

Kaitseministeeriumi ja selle valitsemisala valitsusasutuse turvaalal.

Töötlev üksus võib piiratud tasemel salastatud teavet töödelda ka oma valduses oleval administratiivalal või teise töötleva üksuse nõusolekul ka tema administratiivalal.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 46². Processing of classified information in security and administrative areas

(1) The processing entity processes classified information in their possession, in general, within their security area.

(2) The processing of classified information in the security area of another processing entity is permitted only with the consent of the Estonian Internal Security Service, the Defence Forces or the Foreign Intelligence Service. Upon granting the specified consent only such requirements for the security area are assessed, the compliance with which was a prerequisite for considering the processing of classified information in the security area permissible.

(3) Classified information may be processed without the consent of the coordinating authority provided in subsection 2:

1) within the security area of the processing entity whose official or employee has a need-to-know in respect of the particular information to be processed, provided that the official or employee is directly present at the processing of the information;

2) within the security area of the security authority;

3) within the security area of a diplomatic mission or consular post;

4) within the security area of the Ministry of Defence and the government authority in the area of government thereof.

(4) A processing entity may also process restricted classified information in the administrative area in their possession or, with the consent of another processing entity, in the premises of another processing entity.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 2. jagu Salastatud teabe arvestus

§ 46³. Salastatud teabe kogumi salastatuse tase

Kui salastatud teabe või teabekandjate kogum koosneb salastatuse eri tasemega osadest, loetakse teabe kogumi, seda kogumit kandva teabekandja ning teabekandjate kogumi salastatuse tasemeks nende osade kõrgeim salastatuse tase.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 46³. Classification level of set of classified information

Where a set of classified information or media consists of parts with different levels of classification, the highest level of classification of those parts is considered to be the level of classification of the set of information, the medium carrying it and the media in the set.

§ 47¹. Salastatud teavet sisaldav salvestuskandja

Salastatud teavet sisaldava salvestuskandjana käsitatakse ja töödeldakse kuni hävitamiseni salvestuskandjat:

millele on salvestatud salastatud teavet, sõltumata sellest, kas teave on hiljem kustutatud, välja arvatud juhul, kui Kaitsepolitseiamet või Välisluureamet on intsidendi käsitlemise ajal määranud teisiti;

mis on töötlussüsteemi osa, sõltumata sellest, kas salvestuskandja on töötlussüsteemi tehnilise lahenduse järgi ette nähtud salastatud teabe salvestamiseks, välja arvatud juhul, kui Välisluureamet on töötlussüsteemi akrediteerimisel määranud teisiti.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 47¹. Storage medium containing classified information

A storage medium that is considered to be and processed as the storage medium containing classified information until its destruction is a storage medium:

1) on which classified information has been recorded, regardless of whether the information is subsequently erased, unless otherwise specified by the Internal Security Service or the Foreign Intelligence Service at the time of the handling of an incident;

2) which is part of a processing system, regardless of whether the storage medium is designed by the technical design of the processing system to store classified information, unless otherwise specified by the Foreign Intelligence Service upon accreditation of the processing system.

§ 48. Teabekandja originaal

Teabekandja originaaliks loetakse töötleva üksuse loodud teabekandja esimest registreeritud eksemplari. Teabekandja muid eksemplare ning teisest töötlevast üksusest saabunud teabekandjaid käsitatakse ja töödeldakse koopiatena.

Töötleva üksuse valduses oleva füüsilise teabekandja originaali edastamise korral teisele töötlevale üksusele tehakse sellele lisamärge „Originaal“. Sellise märkega teabekandjat käsitatakse originaalina ja töödeldakse vastavalt.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 48. Original medium

(1) The first registered copy of the medium created by the processing entity is considered to be the original medium. Other copies of the medium and media received from another processing entity are handled and processed as copies.

(2) Where the original of a physical medium in the possession of a processing entity is transmitted to another processing entity, it is additionally marked 'Originaal'[original]. A medium so marked is treated as an original and processed accordingly.

§ 49. Salastatud teabekandjate register

Töötlev üksus peab salastatud teabekandjate registreerimiseks sisse seadma salastatud teabekandjate registri (edaspidi ka register).

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Olenevalt salastatud teabekandjate hulgast võib sisse seada eraldi registrid täiesti salajase, salajase, konfidentsiaalse ja piiratud taseme salastatud teabekandjate registreerimiseks.

Piiratud tasemel salastatud teabekandjaid võib töötleva üksuse juhi otsusega registreerida ka üldises dokumendiregistris, kui on tagatud, et salastatud teave ei saa seetõttu teatavaks kõrvalistele isikutele.

Register võib jaguneda põhiregistriks ning allregistriteks. Allregistri sisseseadmise otsustab töötleva üksuse juht.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 49. Register of classified media

(1) A processing entity is required to establish a register of classified media (hereinafter also the register) for the purpose of registration of classified media.

(2) Separate registers may be established for the registration of ‘top secret’, ‘secret’, ‘confidential’ and ‘restricted’ classified information depending on the number of classified media.

(3) Media classified as ‘restricted’ may also be registered in the general register of documents by the decision of the head of the processing entity, provided that it is ensured that the classified information cannot thereby become known to unauthorised persons.

(4) The register may be divided into the main register and sub-registers. The establishment of a sub-register is decided by the head of the processing entity.

§ 50. Nõuded registrile

Registrit peetakse elektrooniliselt või vajaduse korral paberil.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Registrikanne ise ei tohi võimaluse korral sisaldada salastatud teavet.

Töötlev üksus peab tagama registriandmete alalise säilimise.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 50. Requirements for register

(1) The register is kept electronically or, where appropriate, on paper.

(2) The register entry itself must not, where possible, contain classified information.

(3) The processing entity must ensure the permanent preservation of the register data.

§ 51. Registrisse kantav teave

Teabekandja kohta märgitakse registrisse järgmine teave selle olemasolu korral:

teabekandja identifitseerimiseks vajalikud andmed: registreerimiskuupäev ja -number, selle loonud töötleva üksuse nimi ning dokumendi puhul ka pealkiri ning dokumendi koostanud ja allkirjastanud või sisu kinnitanud isiku nimi. Koopiale ei pea andma uut registreerimisnumbrit, kui märgitakse koopia järjekorranumber;

teabekandja edastanud töötleva üksuse nimi, registreerimiskuupäev ja -number, kui teabekandja on saabunud teisest töötlevast üksusest;

teabekandja liik;

teabekandja salastamisalus, salastatuse tase ja salastamistähtaeg, nende muudatus ja muudatuse tegemise alus;

füüsilise teabekandja puhul selle eksemplaride arv ja numbrid. Eksemplaride arvu ja numbreid ei pea registrisse kandma konfidentsiaalsel ja madalamal tasemel salastatud teabekandja puhul;

füüsilise teabekandja puhul selle osade ja dokumendi lehtede arv. Kui dokument on vormistatud lehe mõlemale poolele, registreeritakse registris selle dokumendi lehtede arv, märkides juurde, et dokument on vormistatud lehe mõlemale poolele;

füüsilise teabekandja puhul koopiate arv. Koopiate arvu ei pea registrisse kandma konfidentsiaalsel ja madalamal tasemel salastatud teabekandja puhul;

selle töötleva üksuse nimi, kellele teabekandja edastati, ja edastamise aeg, füüsilise teabekandja puhul üleandmis-vastuvõtmisakti number;

märge selle kohta, kui teisele töötlevale üksusele on antud nõusolek edastada teabekandjal sisalduvat salastatud teavet kolmandale töötlevale üksusele;

märge teabekandja hävitamise kohta, sealhulgas hävitamise akti registreerimiskuupäev ja -number;

selle isiku nimi, kellele on antud juurdepääs salajasel või kõrgemal tasemel salastatud teabekandjal olevale teabele, ning juurdepääsu andmise viis ja aeg;

teabekandjale määratud lisaturvameetmed, kui need rakenduvad registrit pidavale töötlevale üksusele, ja teabekandja suhtes teadmisvajadust omava selle isiku nimi või ametikoht, kes on seotud registrit pidava töötleva üksusega;

elektroonilise dokumendi puhul teave, mis võimaldab kontrollida dokumendi terviklikkust.

Salvestuskandja kohta märgitakse registrisse järgmine teave selle olemasolu korral:

salvestuskandja identifitseerimiseks vajalikud andmed: registreerimiskuupäev ja -number, salvestuskandja unikaalset tuvastamist võimaldavad andmed;

salvestuskandja edastanud töötleva üksuse nimi, registreerimiskuupäev ja -number juhul, kui salvestuskandja on saabunud teisest töötlevast üksusest;

salvestuskandja liik;

salvestuskandjal sisalduva teabe kõrgeim salastatuse tase;

selle töötleva üksuse nimi, kellele salvestuskandja edastati, ning edastamise aeg ja üleandmis-vastuvõtmisakti number;

märge selle kohta, kui teisele töötlevale üksusele on antud luba edastada salvestuskandjal sisalduvat salastatud teavet kolmandale töötlevale üksusele;

märge salvestuskandja hävitamise kohta, sealhulgas hävitamise akti registreerimiskuupäev ja -number;

selle isiku nimi, kellele salajasel või kõrgemal tasemel salastatud salvestuskandja üle anti, ja üleandmise aeg;

salvestuskandjale määratud lisaturvameetmed, kui need rakenduvad registrit pidavale töötlevale üksusele, ja salvestuskandja suhtes teadmisvajadust omava selle isiku nimi või ametikoht, kes on seotud registrit pidava töötleva üksusega.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 51. Data entered in register

(1) The following data is entered in the register with regard to classified media:

1) data necessary for the identification of a medium: registration date and number, the name of the processing entity that has created it, and for a document also its title and the name of the person who prepared and signed the document or confirmed the content. Each copy need not be given a new registration number in case the consecutive number of the copy is specified;

2) the name of the processing entity that has transmitted the medium, registration date and number in case the medium has arrived from another processing entity;

3) the type of a medium;

4) the basis for classification of a medium, level of and term for classification, their modification and the basis for modification;

5) in the case of a physical medium, the quantity of copies and copy numbers of the document. The quantity of copies and copy numbers need not be entered in the register for media classified at the ‘confidential’ and lower level;

6) in the case of physical medium the quantity of the parts and pages of the document. In case a document has been prepared on both sides of a page, the quantity of pages of such a document is registered in the register of classified media, with a note that the document has been prepared on both sides of a page;

7) in the case of a physical medium the quantity of copies. The quantity of copies need not be entered in the register for media classified at the ‘confidential’ or lower level of classification;

8) the name of the processing entity to whom the medium has been forwarded and the time of transmission; in the case of a physical medium the number of the instrument of delivery and acceptance;

9) a note in case the other processing entity has been given consent to transmit classified information contained in the medium to a third processing entity;

10) a note concerning the destruction of the medium, including the registration date and number of the instrument of destruction;

11) the name of the person who has been granted access to information on a medium classified as ‘secret’ or higher level, and the method and time of granting access;

12) additional security measures assigned to the medium, in case they are applied to the processing entity keeping the register, and the name or post of the person who has a need-to-know regarding the medium, who is related to the processing entity keeping the register;

13) in the case of an electronic document, information that allows checking the integrity of the document.

(2) The following information about the storage medium, where available, is entered in the register:

1) data necessary for identification of the storage medium: registration date and number, data enabling unique identification of the storage medium;

2) the name, registration date and number of the processing entity that forwarded the storage medium, in case the storage medium has arrived from another processing entity;

3) type of storage medium;

4) the highest level of classification of the information contained in the storage medium;

5) the name of the processing entity to which the storage medium was transferred, as well as the time of transfer and the number of the instrument of delivery and acceptance;

6) a note on whether another processing entity has been granted permission to transmit the classified information contained in the storage medium to the third processing entity;

7) a note on the destruction of the storage medium, including the registration date and number of the report of destruction;

8) the name of the person to whom the storage medium classified at a ‘secret’ or higher level was handed over, and the time of the transfer;

9) additional security measures assigned to the storage medium, in case they are applied to the processing entity keeping the register, and the name or post of the person who has a need-to-know with regard to the storage medium and who is related to the processing entity keeping the register.

§ 52. Salastatud teabekandjate registreerimine

Salastatud teabekandja registreeritakse hiljemalt selle valmimisele või saabumisele järgneval tööpäeval. Salastatud teabekandja loetakse valminuks üldjuhul selle allkirjastamisel või elektroonilisel kinnitamisel. Salvestuskandja registreeritakse hiljemalt selle kasutusele võtmisel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandja registreeritakse üldjuhul üks kord. Põhiregistris registreeritud salastatud teabekandjat ei pea registreerima sama töötleva üksuse allregistris.

Kui salastatud dokumentide kogum sisaldab ka salastamata teabekandjaid, võib kogumisse kuuluvad salastamata teabekandjad registreerida salastatud teabekandjate registris. Kui kogum koosneb eraldi kasutatavatest salastatud dokumentidest, võib iga kogumi osaks oleva dokumendi registreerida eraldi.

Kui teabekandja sisaldab nii riigisaladust kui ka salastatud välisteavet, registreeritakse teabekandja vastava taseme riigisaladuse registreerimiseks sisse seatud registris.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Registreerima ei pea:

töötlussüsteemis töödeldavat elektroonilist sõnumit, kui teabe töötlemine on töötlussüsteemi tarkvara abil fikseeritud;

töötlussüsteemis töödeldavat salajasel või kõrgemal tasemel salastatud teabekandjast tehtud koopiat, kui teabe töötlemine on töötlussüsteemi tarkvara abil fikseeritud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 52. Registration of classified media

(1) A classified medium is registered at the latest on the working day following its completion or arrival. A classified medium is generally considered completed when it is signed or electronically confirmed. The storage medium is registered at the latest when it is taken into use.

(2) A classified medium is generally registered once. A classified medium registered in the main register does not need to be registered in the sub-register of the same processing entity.

(3) In case the set of classified documents also contains unclassified media, the unclassified media included in the set may be registered in the register of classified media. In case the set consists of separately used classified documents, each document that is part of the set may be registered separately.

(4) In case the medium contains both state secrets and foreign classified information, the medium is registered in the register established for the registration of state secrets of the corresponding level.

(5) It is not necessary to register:

1) an electronic message processed in the processing system, in case the information processing is fixed using the software of the processing system;

2) a copy made of a medium classified at the ‘secret’ or higher level processed in the processing system, in case the processing of the information is fixed using the software of the processing system.

§ 53. Registripidaja ja registrikande tegija

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Registri ja sellesse kantud teabe haldamist korraldaval isikul (edaspidi registripidaja) peab olema registreeritavate teabekandjate kõrgeimale salastatuse tasemele juurdepääsu õigus.

Registripidajad ja muud registrikannete tegemise õigusega isikud ning nende isikute õiguste ulatuse määrab töötleva üksuse juht või tema volitatud isik.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 53. Registrar and maker of register entry

(1) The person organizing the management of the register and information entered in it (hereinafter the registrar) must have the right of access to the highest classification level of the media registered.

(2) Registrars and other persons with the right to make register entries and the extent of the rights of these persons is determined by the head of the processing entity or a person authorized thereby.

§ 53¹. Salastatud teabekandja üleandmine töötleva üksuse siseselt

Füüsilise teabekandja teisele sama töötleva üksusega teenistus- või lepingulises suhtes olevale füüsilisele isikule üleandmine tuleb fikseerida kirjalikult teabekandjast eraldi või elektroonilise kinnitusega dokumendihaldussüsteemis.

Üleandmise kohta märgitakse:

teabekandja registreerimiskuupäev ja -number, kõrgeim salastatuse tase ning üleantavate ühikute arv;

üleandmise kuupäev ja kellaaeg;

vastuvõtja nimi ja allkiri või elektrooniline kinnitus;

üleandja nimi ja allkiri või elektrooniline kinnitus.

Andmeid salastatud teabekandja üleandmise kohta säilitatakse turvaalal või dokumendihaldussüsteemis vähemalt kümme aastat. Füüsilise teabekandja, millel on fikseeritud andmed salastatud teabekandja üleandmise kohta, võib hävitada pärast viie aasta möödumist, kui see on digiteeritud.

Käesolevat paragrahvi ei pea kohaldama konfidentsiaalsel tasemel salastatud teabekandja registreerimata koopia ja piiratud tasemel salastatud teabekandja üleandmisel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 53¹. Transfer of classified medium within processing entity

(1) The transfer of a physical medium to another natural person in the service or contractual relationship with the same processing entity must be fixed in writing separately from the medium or with electronic confirmation in the document management system.

(2) The following is noted on the transfer:

1) the registration date and number of the medium, the highest level of classification and the number of entities to be transferred;

2) date and time of transfer;

3) name and signature or electronic confirmation of the recipient;

4) name and signature of the transferor or electronic confirmation.

(3) Data on the transfer of a classified medium are stored in the security area or in the document management system for at least ten years. A physical medium on which the data on the transfer of a classified medium is recorded may be destroyed after five years in case it has been digitized.

(4) This section does not have to be applied upon the transfer of an unregistered copy of a medium classified as ‘confidential’ and medium classified as ‘restricted’.

§ 54. Salastatud teabega tutvumise kinnitus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salajasel ja kõrgemal tasemel salastatud teabekandjas sisalduva teabega tutvumise kohta annab isik allkirja tutvumislehele või elektroonilise kinnituse.

Töötlussüsteemis ei ole eraldi tutvumise kinnitus vajalik, kui elektrooniliselt tagatakse tutvuja isiku ja tutvumisaja tuvastatavus.

Kui allkirja või elektroonilise kinnituse andmine ei ole teabekandjas sisalduva teabega tutvumise ajal võimalik, fikseeritakse tutvuja isik ja tutvumisaeg muul viisil ning võetakse allkiri või kinnitus esimesel võimalusel. Kui tutvuja on välisriigi kodanik ning tema isik ja tutvumisaeg on fikseeritud muul viisil, ei pea allkirja või kinnitust võtma.

Tutvumislehti ja muid andmeid teabega tutvumise kohta säilitatakse vähemalt 75 aastat, kuid mitte vähem, kui säilitatakse teabekandjat, milles sisalduva teabega tutvuti.

Füüsilisel teabekandjal oleva tutvumislehe võib hävitada pärast viie aasta möödumist, kui see on digiteeritud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 54. Confirmation of access to classified information

(1) A person gives a signature to the access sheet or provides an electronic confirmation on the access to the information contained in a medium classified at the ‘secret’ and higher level of classification.

(2) In the processing system, a separate confirmation of access is not necessary in case the identification of the person and the time of access is ensured electronically.

(3) In case it is not possible to provide a signature or electronic confirmation during the access to the information contained in the medium, the identity of the examiner and the time of access are fixed in another manner, and the signature or confirmation is taken at the first opportunity. In case the visitor is a citizen of a foreign state and their identity, and the time of the access are fixed in another manner, signature or confirmation is not required.

(4) Access sheets and other data on the access to information are stored for at least 75 years, but not less than the medium which contained the information examined.

(5) An access sheet on a physical medium may be destroyed after five years have passed in case it has been digitized.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 3. jagu Salastatud teabe märgistamine › 1. jaotis Märgistamise üldnõuded

§ 54¹. Salastatud teabe, teabekandja ja teabekandjate kogumi märgistamise üldpõhimõtted

Salastatud teave ja teabekandja märgistatakse selle tüüpi ja omadusi arvestades parimal võimalikul moel, mis ei kahjusta teabe ega teabekandja terviklikkust, eesmärgiga, et:

selle valdajal oleks võimalik üheselt aru saada, et tegemist on salastatud teabega;

selle mis tahes viisil töötlejal oleks võimalik saada teada selle salastatuse tase, salastamisalus, salastamistähtaeg ning registreerimiskuupäev ja -number, samuti lisaturvameetmed ja teabekandja suhtes teadmisvajadust omavad isikud, kui need on määratud.

Salastatud teabekandjate kogum märgistatakse lisaks lõikes 1 sätestatule viisil, mis võimaldab üheselt aru saada, et tegemist on teabekandjate kogumiga.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 54¹. General principles of marking of classified information, medium and set of media

(1) Classified information and medium are marked, taking into account its type and characteristics, in the best possible way which does not damage the integrity of the information or the medium, with the aim that:

1) its holder would be able to clearly understand that it is classified information;

2) its processor in any way would be able to find out its classification level, basis for classification, classification term and registration date and number, as well as additional security measures and persons with a need-to-know with regard to the medium, in case they are designated.

(2) In addition to the provisions of subsection 1, the set of classified media are marked in a manner that makes it possible to clearly understand that it is a set of media.

§ 55. Riigisaladust sisaldava salastatud teabekandja märgistamine

Riigisaladust sisaldavale salastatud teabekandjale tehakse järgmine märgistus:

salastatuse taseme märge;

salastamisaluse märge;

salastamistähtaja märge.

Salastatuse taseme märkeks on teabekandja kõrgeimale salastatuse tasemele vastav tekst „täiesti salajane“, „salajane“, „konfidentsiaalne“ või „piiratud“. Salastatuse taseme märge tehakse trükituna sõrendatud paksus kirjas vähemalt 16-punktiste suurtähtedega või samadele nõuetele vastavat punast värvi teksti kandva templijäljendi või kleepsuga.

Salastamisaluse märkeks on tekst „Riigisaladus … alusel“, mille lünka kantakse viide käesolevale määrusele ning selle asjaomasele paragrahvile, lõikele ja punktile. Kui salastatud teabekandja on salastatud mitmel õiguslikul alusel, kantakse lünka kõik alused.

Registreeritud teabekandjale või selle juurde kantakse lisaks lõikes 1 nimetatud märgistusele registreerimiskuupäev ja -number.

Kui lõigetes 2–4 sätestatud nõuetele vastavat märgistust ei ole võimalik teabekandja tüübi, materjali, suuruse või muu omaduse tõttu teabekandjale teha, võib rakendada ühte või mitut järgmistest eranditest, tingimusel et märgistus on hõlpsasti nähtav ja loetav ning § 54¹ lõikes 1 nimetatud eesmärk on täidetud:

teha märgistuse muul viisil või tihedamas, õhemas, väiksemas, väiketähtedega või teist värvi kirjas;

teha ainult salastatuse taseme märkest ning registreerimiskuupäevast ja -numbrist koosneva märgistuse;

teha märgistuse teabekandja asemel selle ümbrisele, pakendile või teabekandja külge kinnitatud sildile.

Kui lõigetes 2–4 sätestatud nõuetele vastava märgistuse tegemine ohustab teabekandjale kantud riigisaladuse salastatust, võib jätta teabekandja märgistamata tingimusel, et § 54¹ lõikes 1 nimetatud eesmärk on muul viisil täidetud.

Riigisaladust sisaldava teabekandja edastamisel välisriigile, rahvusvahelisele organisatsioonile või rahvusvahelise kokkuleppega loodud institutsioonile tehakse teabekandjale välislepingu nõuetele vastav salastatuse taseme märge ning esilehele inglise keeles märge „Classified as State Secret of the Republic of Estonia“.

Salastatud teabekandja nõuetekohase märgistamise eest vastutab teabekandja koostaja.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 55. Marking of classified media containing state secret

(1) The classified medium containing a state secret is marked as follows:

1) marking of the level of classification;

2) marking of the basis of classification;

3) marking of the classification term.

(2) The marking of the level of classification is the text corresponding to the highest classification level of ‘top secret’, ‘secret’, ‘confidential’ or ‘restricted’. The marking of the level of classification is made in a double-spaced bold printed type with at least 16-point capital letters or with a stamp or sticker bearing red text in compliance with the same requirements.

(3) The marking of the basis of classification is the text "State secret on the basis of...", in the blank of which is entered a reference to this Regulation and its relevant section, subsection and clause. In case the classified medium is classified on several legal grounds, all grounds are entered in the blank.

(4) In addition to the marking specified in subsection 1, the registration date and number are entered on or next to the registered medium.

(5) In case it is not possible to mark the medium due to the type, material, size or other characteristics of the medium in compliance with the requirements provided in subsections 2-4, one or more of the following exceptions may be applied, provided that the marking is easily visible and readable and the purpose specified in § 54¹ is met:

1) make the marking in a different manner or in denser, thinner, smaller, lowercase letters or in a font of a different colour;

2) make the marking consisting only of the marking of the level of classification and the registration date and number;

3) make the marking, instead of the medium, on its cover, packaging or on a label attached to the medium.

(6) In case the making of the marking in compliance with requirements provided in subsections 2–4 threatens the classification of a state secret entered on a medium, the medium may be left unmarked provided that the purpose specified in subsection 1 of § 54¹ is achieved in another manner.

(7) Upon transmitting a medium containing a state secret to a foreign state, an international organization or an institution established by a international agreement, the marking is made on the medium in compliance with the level of classification in accordance with the requirements of the international agreement, and the marking „Classified as State Secret of the Republic of Estonia" is made on the front page in English.

(8) The compiler of the medium is responsible for the proper marking of the classified medium.

§ 58. Lisamärgistus turvameetmete ja teadmisvajadusega isikute kohta

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandjale võib märgistuse juurde või muule selgelt nähtavale kohale teha lisamärke lisaturvameetmete või teabekandja suhtes teadmisvajadust omava isiku nime või ametikoha kohta.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 58. Additional marking concerning security measures and persons with need-to-know

An additional marking may be made on the classified medium next to the marking or in another clearly visible place about additional security measures or the name or post of a person who has a need-to-know regarding the medium.

§ 59. Pakendatud teabekandja ja teabekandjate kogumi lisamärgistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui säilitamiseks pakendatud salastatud teabekandjat säilitatakse pakendis, ümbrises või muul viisil nii, et märgistus on varjatud, tehakse pakendile või ümbrisele hõlpsasti nähtav ja selgelt loetav lisamärgistus.

Vedamiseks pakendatud salastatud teabekandja märgistamisele kohaldatakse § 88.

Kui salastatud teabekandjad moodustavad kogumi, tehakse kogumi ümbrisele hõlpsasti nähtav ja selgelt loetav ning kogumi kõrgeimale salastatuse tasemele vastav lisamärgistus.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 59. Additional marking of packaged medium and set of media

(1) In case the classified medium packaged for storage is stored in a package, case or in another manner in such a way that the marking is hidden, an easily visible and clearly legible additional marking is made on the package or case.

(2) Section 88 applies to the marking of classified medium packaged for transport.

(3) In case the classified media make up a set, an easily visible and clearly readable additional marking corresponding to the highest classification level of the set is made on the cover of the set.

§ 60. Märgistuse muutmine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatuse kustumise korral tehakse lisamärgistus või muudetakse märgistust viisil, mis võimaldab valdajal aru saada, et enam ei ole tegemist salastatud teabekandjaga.

Kui teabekandja võimaldab, märgitakse salastatuse ennetähtaegsel kustutamisel teabekandjale või selle juurde tekst „Salastatus kustutatud … alusel“, mille lünka kantakse kustutamise otsuse teinud organi nimi ning otsuse rekvisiidid ja jõustumise aeg.

Kui teabekandja võimaldab, märgitakse salastamistähtaja pikendamisel teabekandjale või selle juurde tekst „Salastamistähtaeg pikendatud … alusel“, mille lünka kantakse pikendamise otsuse teinud organi nimi ja otsuse rekvisiidid, ning märgitakse uus salastamistähtaeg.

Kui teabekandja võimaldab, tehakse salastamisandmete parandamisel lisamärgistus või muudetakse valet märgistust ja märgitakse teabekandjale või selle juurde tekst „Salastatus parandatud …“, mille lünka kantakse salastamisandmete parandamise otsuse teinud organi või ametniku nimi ja ametniku allkiri ning otsuse rekvisiidid.

Teabekandja märgistust muudetakse ja selle kohta tehakse kanne registrisse esimesel võimalusel.

Arhiivihoidlas oleva teabekandja märgistust muudetakse selle töötlemise korral, välja arvatud vahetult selle hoidmisega ja säilitamisega seotud toimingute korral.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 60. Amendment of marking

(1) In the case of declassification, additional marking is made or the marking is amended in a manner that enables the holder to understand that it is no longer a classified medium.

(2) In case the medium allows, upon premature declassification the text "Salastatus kustutatud … alusel” [classification deleted on the basis of...] is marked on the medium or next to it, in the blank of which the name of the body that made the declassification decision and the details of the decision, and the date of entry into force are entered.

(3) In case the medium allows, upon extending the classification period, the text " Salastatus pikendatud … alusel” [classification period extended on the basis of...] is marked on the medium or next to it, in which the name of the body that made the extension decision and the details of the decision are entered, and the new classification period is indicated.

(4) In case the medium allows, additional marking is made upon correcting the classification data or incorrect marking is changed and the text " Salastatus parandatud … ” [classification corrected...] is marked on the medium or next to it, in the blank of which the name and signature of the body or official who made the decision to correct the classification data and the details of the decision are entered.

(5) The marking of the medium is amended and an entry about it is made in the register at the earliest opportunity.

(6) The marking of the medium in the archival repository is changed in case of its processing, except for acts directly related to its storage and preservation.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 3. jagu Salastatud teabe märgistamine › 2. jaotis Dokumendi märgistamine

§ 62. Lehekülgede nummerdamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Paberdokumendi iga leht nummerdatakse ja igale lehele märgitakse lehtede koguarv. Kui dokument on vormistatud lehe mõlemale poolele, tuleb nummerdada ja märkida vastavalt leheküljed.

Elektroonilise dokumendi iga lehekülg nummerdatakse alates esimesest ja igale leheküljele märgitakse lehekülgede koguarv.

Kui paberdokument ei võimalda lehekülgi nummerdada, peavad selle juures olema muud teabe terviklikkuse kontrollimist võimaldavad andmed. Kui elektrooniline dokument või selle teabekandja ei võimalda lehekülgi nummerdada, peavad võimaluse korral selle juures olema muud teabe terviklikkuse kontrollimist võimaldavad andmed.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 62. Numbering of pages

(1) Each page of a paper document is numbered and the total number of pages is marked on each page. Where a document is printed on both sides of a page, the pages must be numbered and marked accordingly.

(2) Each page of an electronic document is numbered beginning with the first page and the total number of pages is marked on each page.

(3) Where a paper document does not allow numbering pages, it must have other data that allow checking the integrity of the information. Where the electronic document or its medium does not allow numbering pages, it must, where possible, have other data that allow checking the integrity of the information.

§ 63. Dokumendi märgistamine

Kui paberdokument või elektrooniline dokument ja selle teabekandja võimaldavad, märgistatakse salastatud dokument järgmiselt:

riigisaladust sisaldaval dokumendil tehakse salastamisaluse ja salastamistähtaja märge esilehe päise paremasse nurka, registreerimiskuupäev ja -number selgelt nähtavale kohale ning salastatuse taseme märge iga lehekülje päise ja jaluse keskele;

salastatud välisteavet sisaldaval dokumendil tehakse § 118¹ lõikes 1 sätestatud märgistus esimesele leheküljele ning sama paragrahvi lõikes 3 sätestatud lisamärge esilehe päise paremasse nurka.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 63. Marking of document

In case a paper document or an electronic document and its medium allow, the classified document is marked as follows:

1) on a document containing a state secret, the basis of classification and the term of classification are marked in the right corner of the header of the front page, the registration date and number in a clearly visible place, and the level of classification is marked in the middle of the header and footer of each page;

2) on a document containing foreign classified information the marking provided in subsection 1 of § 118¹ is made on the first page and the additional marking provided in subsection 3 of the same section in the right corner of the header of the first page.

§ 64. Dokumendi lisa, koopia ja väljavõtte märgistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Dokumendi lisa, mis on kasutatav põhidokumendita, märgistatakse nagu eraldi dokument.

Paberdokumendi koopiale tehakse lisamärge „Koopia“.

Dokumendi väljavõttele tehakse lisamärge „Väljavõte“ ja viide originaaldokumendile.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 64. Marking of annex, copy and extract of document

(1) An annex to a document that is used without the main document is marked as a separate document.

(2) The copy of the paper document is marked with the additional mark "Koopia"[copy].

(3) An additional marking "Väljavõte” [extract] and a reference to the original document is made to the extract of the document.

§ 65. Tekstiosade ja illustratsioonide kaupa märgistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui dokumendi tekstiosadel või illustratsioonidel on erinev juurdepääsupiirangu tase või erinevad salastatud välisteabe avaldajad, võib dokumendi märgistada tekstiosade või illustratsioonide kaupa.

Lõikes 1 nimetatud märgistus tehakse sulgudes suurtähtedega asjaomase lõigu algusesse või illustratsiooni ette või peale ning vajaduse korral ka lõigu lõppu või illustratsiooni järele või alla.

Tekstiosa või illustratsiooni juurdepääsupiirangu taseme märke võib esitada sulgudes lühendina, kasutades riigisaladuse puhul märkeid „P“, „K“, „S“ või „TS“.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 65. Marking by text sections and illustrations

(1) In case text sections or illustrations of a document have different levels of access restriction or different originators of foreign classified information, the document may be marked by text sections or illustrations.

(2) The marking specified in subsection 1 is made in parentheses in capital letters at the beginning of the relevant paragraph or before or after the illustration and, where necessary, also at the end of the paragraph or after or below the illustration.

(3) Markings of the access restriction level of a text section or an illustration may be presented in parentheses as an abbreviation, using the marks "P", "K", "S" or "TS"[restricted, confidential, secret, top secret], in the case of a state secret.

§ 67. Dokumentide kogumi märgistamine

Salastatud dokumentidest moodustatud kogum märgistatakse kogumis sisalduva kõrgeima taseme riigisaladuse märkega.

Toimikuks liidetud või muul viisil kaante vahele kogutud paberdokumentide kogumi kõrgeima salastatuse taseme märge tehakse selle esi- ja tagakaane päisesse ja jalusesse.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Muudel juhtudel tehakse kogumi kõrgeima salastatuse taseme märge selle esimeseks dokumendiks oleva dokumendi esimese lehekülje päisesse ja jalusesse.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui kogumi esimene lehekülg ei sisalda riigisaladust, tehakse dokumendi päise paremasse nurka lisamärge „Märgistatud riigisaladusena kui kogumi esileht“.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 67. Marking of set of documents

(1) A set composed of classified documents is marked with the marking indicating the highest classification level of state secret.

(2) In case a set of paper documents has been joined together in a file or is stored between covers in another manner, the marking of the highest classification level is made in the header and footer of its front and back cover of the file.

(3) In other cases, the marking of the highest classification level is made in the header and footer of the first page of the first document in the set.

(4) In case the front page of a set does not contain a state secret, an additional notation "Märgistatud riigisaladusena kui kogumi esileht" [marked as a state secret as the front page of a set] is made in the right corner of the header of a document.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 3. jagu Salastatud teabe märgistamine › 4. jaotis Faili ja elektroonilise sõnumi märgistamine

§ 70. Faili märgistamine

Kui fail seda võimaldab, märgitakse salastatud teavet sisaldava faili salastatuse tase suurtähtedega faili nime algusesse ning failide kogumi kõrgeim salastatuse tase kogumi nime algusesse. Kui faili või failide kogumi nime alguses on kuupäevamärge, võib salastatuse taseme märkida pärast kuupäevamärget. Märke võib vajaduse korral esitada sulgudes või visuaalselt muul viisil eristuvalt lühendina, kasutades riigisaladuse puhul märkeid „P“, „K“, „S“ või „TS“.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 70. Marking of file

In case the file allows it, the classification level of the file containing classified information is marked in capital letters at the beginning of the file name, and the highest classification level of the set of files is marked at the beginning of the name of the set. In case the name of the file or set of files has a date stamp at the beginning, the classification level may be indicated after the date stamp. Where appropriate, the marking may be given in brackets or as an abbreviation otherwise visually distinguishable, using the characters 'P', 'K', 'S' or 'TS' for state secrets.

§ 71. Elektroonilise sõnumi märgistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Elektroonilise sõnumi salastatuse taseme märge tehakse suurtähtedega sõnumi sisuosa algusesse ning vajaduse korral ka sõnumi pealkirja või teemarea algusesse ja sõnumi sisuosa lõppu. Sõnumi pealkirja või teemarea algusesse tehtava märke võib vajaduse korral esitada sulgudes või visuaalselt muul viisil eristuvalt lühendina, kasutades riigisaladuse puhul märkeid „P“, „K“, „S“ või „TS“.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 71. Marking of electronic messages

The marking of the classification level of an electronic message is made in capital letters at the beginning of the body of the message and, where necessary, also at the beginning of the title or subject line of the message and at the end of the body of the message. The marking at the beginning of the title or subject line of the message may, where necessary, be given in brackets or as an abbreviation otherwise visually distinguishable, using the characters 'P', 'K', 'S' or 'TS' for state secrets.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 4. jagu Salastatud teabekandja säilitamine › 1. jaotis Säilitamistingimustele ja -vahenditele esitatavad nõuded

§ 72. Seif

Konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandjaid säilitatakse murdmiskindlas koodlukuga seifis. Seifi kasutuselevõtmine tuleb eelnevalt kooskõlastada vastavalt Kaitsepolitseiameti, Kaitseväe või Välisluureametiga, välja arvatud juhul, kui seifi murdmiskindlus vastab vähemalt standardi EVS-EN 1143-1 1. klassi nõuetele.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Piiratud tasemel salastatud teabekandjat säilitatakse seifis, lukustatud kapis või sahtlis, mis on kaitstud kõrvaliste isikute juurdepääsu eest.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Seif, milles säilitatakse konfidentsiaalsel või kõrgemal tasemel salastatud teabekandjat, peab paiknema turvaalal.

Kui seifi kasutab mitu isikut, tuleb seif jagada füüsiliselt osadeks lähtuvalt teadmisvajaduse põhimõttest. Seifil peavad niisugusel juhul olema eraldi lukustatavad osad.

Kooskõlastava asutuse loal võib salastatud teabekandjaid säilitada avatud hoiualal. Luba andes võib määrata avatud hoiualal säilitamise lisatingimusi, sealhulgas teabe kõrgeima salastatuse taseme, säilitamise viisi ja lisakaitsemeetmed.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 72. Safe

(1) Media classified at the ‘confidential’ and higher level is stored in a break-proof safe with a code lock. The deployment of the safe is subject to prior approval by the Internal Security Service, the Defence Forces or the Foreign Intelligence Service accordingly, unless the break resistance of the safe meets at least the requirements of the standard EVS-EN 1143-1 Class 1.

(2) The medium classified as ‘restricted’ is stored in a safe, locked cabinet or drawer, which is protected from access by unauthorised persons.

(3) A safe in which a medium classified at the ‘confidential’ or higher level is stored must be located in the security area.

(4) In case a safe is used by several persons, the safe must be physically divided into parts on a basis of a need-to-know principle. In such a case, the safe must have separately lockable parts.

(5) With the authorisation of the coordinating authority, the classified media may be stored in a public storage area. Upon granting such authorisation, additional conditions for storage in an open storage area may be specified, including the highest classification level of information, method of storage and additional protective measures.

§ 73. Salastatud teabekandjate säilitamine nende kasutamise ajal

Salastatud teabekandjad peavad pärast nende väljavõtmist seifist või muust säilituskohast olema pideva järelevalve all. Kui salastatud dokumente parajasti ei kasutata, tuleb neid hoida tühi lehekülg ülespoole või kinnikaetult.

Ruumist lahkumisel peab salastatud teabekandja lukustama vastavalt salastatuse tasemele seifi, kappi või sahtlisse.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 73. Storage of classified media during their use

(1) Following removal from a safe or other place of storage, classified media must be under continuous surveillance. In case the classified documents are not being used at any given moment, they must be kept the blank page facing upwards or pinned.

(2) Upon leaving the room, the classified medium must be locked away in a safe, cabinet or drawer according to the level of classification.

§ 74. Erandid üldistest säilitustingimustest

Kui salastatud teabekandjate säilitamise nõudeid ei ole töötlevas üksuses võimalik täita, tuleb salastatud teabekandjad anda ajutisele hoiule riigiasutusele, kus salastatud teabekandjate säilitamise nõuded on täidetud.

Kooskõlastav asutus võib lubada liikuval ja ajutisel turvaalal kasutada § 72 lõikes 1 sätestatust madalama murdvarguskindluse klassiga seife.

Kooskõlastav asutus võib lubada erandjuhul kasutada salastatud teabekandjate säilitamiseks ka muid võimalusi, näiteks säilitamine pakendatuna vastuvõtva baasi või staabi turvaalal, lukustatavas metallkastis, nahktaskus või mujal.

Salajasel või konfidentsiaalsel tasemel salastatud teabekandjat võib asutuse juhi loal erandjuhtudel lühiajaliselt, näiteks sobiva suurusega seifi hankimiseni, säilitada metallist dokumendikapis või sahtlis, kui hoidmispaik asub turvaalal ja on varustatud vähemalt ühe sulgemisrauaga või kolmeosalise võtmekombinatsiooniga lukuga.

Töötlussüsteemi osaks olevat salvestuskandjat võib säilitada olenevalt salastatuse tasemest turvaalal või administratiivalal asuva arvuti sees ilma salvestuskandjat seifi või kappi lukustamata, kui Välisluureamet on andnud töötlussüsteemi akrediteerimisel selleks nõusoleku.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 74. Exceptions to general storage conditions

(1) In case it is not possible to meet the requirements for the storage of classified media in the processing entity, the classified media must be deposited temporarily with state authority where the requirements for storing classified media are met.

(2) The coordinating authority may authorise the use in mobile and temporary security areas of safes with a lower burglary resistance class than that provided in subsection 1 of § 72.

(3) In exceptional cases, the coordinating authority may authorise the use of other means of storage for storing classified media, such as storage in a packaged form within the security area of the receiving base or headquarters, in a locked metal box, leather pouch or elsewhere.

(4) In exceptional cases, media classified as ‘secret’ or ‘confidential’ may, with the authorisation of the head of the authority, be stored in a metal filing cabinet or in a drawer for a short period, for example, until a safe of appropriate size is obtained, provided that the storage place is located in the security area and is equipped with a lock with at least one locking bolt or a lock with three-part key combination. one locking bolt or a lock with a three-part key combination.

(5) A storage medium forming part of a processing system may be stored in a computer located in the security area or administrative area, depending on the classification level, without locking the medium in a safe or cabinet, provided that the Foreign Intelligence Service has given their authorisation thereto upon accreditation of the processing system.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 4. jagu Salastatud teabekandja säilitamine › 2. jaotis Säilituspaiga võtmete ja lukukoodide kaitse

§ 75. Seifi lukukood

Seifi lukukoodi tohib teada ainult selle seifi kasutaja.

Lukukood ei tohi koosneda numbrite või tähtede reast, mida on kerge ära arvata, näiteks tähtpäevade kuupäevad, telefoninumbrid, aritmeetilised jadad.

Lukukoode peab muutma:

kasutaja vahetumisel;

pärast avamist kasutaja juuresolekuta;

kui on põhjust arvata, et kood on saanud teatavaks kõrvalisele isikule;

12 kuu möödumisel viimasest muutmisest.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 75. Lock code of safe

(1) Only the user of a safe is allowed to know the lock code of the safe.

(2) The lock code may not consist of a series of numbers or characters that can be easily guessed, such as dates of important anniversaries, telephone numbers, arithmetic sequences.

(3) Lock codes must be changed:

1) upon change of the user;

2) after opening without the presence of the user;

3) in case there is reason to believe that the code has become known to an unauthorized person;

4) after 12 months have passed from the last changing.

§ 76. Seifi võti ja lukk

Tööajal võib seifi võti asuda seifi kasutaja käes.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandjate hoiustamiseks kasutataval seifil on lisaks koodlukule ka võti ning seifi kasutaja lahkub turvaalalt või seda ümbritsevalt administratiivalalt avalikku ruumi, tuleb seifi võti lukustada võtmete kappi.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Seifi lukud tuleb vahetada, kui on põhjust arvata, et seifi võti on sattunud kõrvalise isiku kätte.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 76. Keys and locks to safes

(1) The key to the safe may be in the hands of the user of the safe during working hours.

(2) In case the safe used for the storage of media classified at the ‘confidential’ and higher level has a key in addition to a code lock, and the user of the safe leaves the security area or the administrative area surrounding it into a public space, the key to the safe must be locked into the key cabinet.

(3) The locks to the safe must be changed in case there is reason to believe that the key to the safe has fallen into the hands of an unauthorised person.

§ 77. Võtmete kapp

Võtmete kapp peab olema metallist, lukustatav ja asuma pideva valve all.

Kui võtmete kappi kasutab mitu isikut, peab olema tagatud, et kasutaja saab võtta ainult talle vajaliku võtme.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 77. Key cabinet

(1) A key cabinet must be made of metal, be lockable and be under continuous surveillance.

(2) I case a key cabinet is used by several persons, it must be guaranteed that each user gets only the key that they need.

§ 78. Seifi varuvõtme ja lukukoodi hoidmine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Seifi varuvõti ja lukukood antakse pitseeritud ümbrikus salastatud teabe kaitse juhendis määratud isikule, kes hoiab neid eraldi seifis. Ümbrikule märgitakse lukukoodi muutmise kuupäev. Erandkorras võib kooskõlastava asutuse eelneval loal hoida varuvõtmeid ja lukukoode muul turvalisel viisil.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Seifi võtit ja lukukoodi võib hoida panga seifis.

Muud seifiluku koodi ülestähendused on keelatud.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 78. Storage of spare keys and lock codes to safe

(1) The spare key and lock code of the safe are given in a sealed envelope to the person specified in the instructions for the protection of classified information who keeps them in a separate safe. The date of changing the lock code is marked on the envelope. In exceptional cases, spare keys and lock codes may be kept in another secure manner with the prior authorization by the coordinating authority.

(2) The key and lock code to the safe may be kept in a bank safe.

(3) Other notes of the code to the safe lock are prohibited.

§ 79. Piiratud tasemel salastatud teabekandja säilitamiseks kasutatava seifi, kapi või sahtli võti või lukukood

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Piiratud tasemel salastatud teabekandja säilitamiseks kasutatava seifi, kapi või sahtli võtit või lukukoodi tuleb hoida nii, et see on kaitstud kõrvaliste isikute kätte sattumise eest.

Piiratud tasemel salastatud teabekandja säilitamiseks kasutatava seifi lukukoodi muutmisel lähtutakse § 75 lõike 3 punktidest 1–3.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 79. Key or lock code to safe, cabinet or drawer used to store medium classified as ‘restricted’

(1) The key or lock code to a safe, cabinet or drawer used for the storage of a medium classified as ‘restricted’ must be kept in such a manner that it is protected from falling into the hands of unauthorised persons.

(2) The changing of the lock code to a safe used for the storage of a medium classified as ‘restricted’ is made based on clauses 1–3 of subsection 3 of § 75.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 5. jagu Salastatud teabekandja reprodutseerimine ja sellest väljavõtte tegemine

§ 80. Reprodutseerimise põhimõtted

Töötlev üksus peab välistama salastatud teabekandja kontrollimatu reprodutseerimise ja sellest väljavõtte tegemise.

Täiesti salajasel tasemel salastatud teabekandja reprodutseerimine ja sellest väljavõtte tegemine teabekandja koostanud töötleva üksuse kirjaliku nõusolekuta on keelatud. Lubatud on nõusolekuta reprodutseerida salastatud teavet töötleva üksuse töötlussüsteemis kasutamiseks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salajasel ja täiesti salajasel tasemel teabekandjat võib reprodutseerida ja sellest väljavõtte teha registripidaja või töötleva üksuse juhi või tema volitatud isiku määratud muu isik.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Reprodutseerimise käigus reprodutseerimisvahendis jäädvustunud teavet tuleb kaitsta ebaseadusliku juurdepääsu eest.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 80. Principles of reproduction

(1) The processing entity must exclude the uncontrolled reproduction of a classified medium and the making of an extract therefrom.

(2) It is prohibited to reproduce a medium classified as ‘top secret’ and to make an extract therefrom without the written consent of the processing entity that prepared the medium. It is permitted to reproduce, without consent, classified information for use in the processing system of the processing entity.

(3) A medium classified as ‘secret’ and ‘top secret’ may be reproduced and an extract made from it by the registrar or by the head of the processing entity or another person appointed by the person authorised thereby.

(4) The information recorded in the means of reproduction during reproduction, must be protected against illegal access.

§ 81. Reprodutseerimisseade

Konfidentsiaalsel, salajasel ja täiesti salajasel tasemel salastatud teabekandja reprodutseerimise seade peab asuma turvaalal ning töötlev üksus peab tagama, et nendele reprodutseerimisseadmetele ei pääse juurde kõrvalised isikud. Salastatud teabekandja reprodutseerimiseks ja väljavõtte tegemiseks tuleb kasutada ainult selleks ettenähtud reprodutseerimisseadmeid.

Piiratud tasemel salastatud teabekandja reprodutseerimine ja sellest väljavõtte tegemine on lubatud administratiivalal selleks ettenähtud reprodutseerimisseadmega.

Reprodutseerimisseadmele tuleb teha selgelt loetav märgistus reprodutseerida lubatud teabe kõrgeima salastatuse taseme kohta.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 81. Reproduction equipment

(1) Equipment for the reproduction of a medium classified at the ‘confidential’, ‘secret’ and ‘top secret’ level must be located in the security area and the processing entity must ensure that such reproduction equipment is not accessible to unauthorised persons. Only such reproduction equipment that is intended for that purpose must be used for the reproduction of classified medium and making extracts therefrom.

(2) Reproduction of a medium classified as ‘restricted’ and making extracts therefrom is permitted in an administrative area with a reproduction equipment that is intended for that purpose.

(3) The reproduction equipment must bear a clearly legible marking regarding the highest classification level of information allowed to be reproduced.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 6. jagu Salastatud teabekandja hävitamine

§ 82. Salastatud teabekandja hävitamise põhimõtted

Konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja hävitamise seade peab asuma turvaalal. Turvaala kooskõlastava asutuse loal võib salastatud teabekandja hävitamise seade asuda administratiivalal.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Salastatud teabekandja evakuatsiooni korral võib selle hävitada väljaspool turvaala või administratiivala viisil, mis kaitseb sellel sisalduvat teavet avalikuks tuleku ning juurdepääsuõiguseta ja teadmisvajaduseta isiku juurdepääsu eest.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kasutuskõlbmatuks muutunud salastatud teabekandja tuleb hävitada esimesel võimalusel, välja arvatud siis, kui seda on vaja säilitada eriotstarbeks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 82. Principles for destruction of classified media

(1) The equipment for the destruction of a medium classified at the ‘confidential’ and higher level must be located in the security area. With the authorisation of the authority coordinating the security area, the equipment for destruction of a classified medium may be located in an administrative area.

(1¹) In the event of evacuation, the classified medium may be destroyed outside the security area or administrative area in a manner that protects the information contained therein from disclosure and from access by a person who has no right of access and no need-to-know.

(2) A classified medium which has become unusable must be destroyed at the earliest opportunity, unless it is necessary to preserve it for a special purpose.

§ 83. Salastatud teabekandja hävitamine

Salajasel ja kõrgemal tasemel salastatud paberkandja hävitamiseks kasutatav paberipurustaja peab paberi purustama tükkideks, mis ei tohi olla suuremad kui 5 mm².

Konfidentsiaalsel ja madalamal tasemel salastatud paberkandja hävitamiseks kasutatav paberipurustaja peab paberi purustama tükkideks, mis ei tohi olla suuremad kui 10 mm².

Kui lõigetes 1 ja 2 nimetatud teabekandja purustamisel tekkinud jäätmed hävitatakse viisil, mis teeb võimatuks teabekandja taastamise, võib hävitamiseks kasutada paberipurustajat, mis purustab paberi tükkideks, mis ei tohi olla suuremad kui 30 mm².

Salvestuskandja hävitamiseks kasutatav seade peab salvestuskandja purustama tükkideks, mis ei tohi olla suuremad kui:

kõvaketta puhul – 10 mm²;

optilise andmekandja puhul – 5 mm²;

pooljuhtketta puhul – 4 mm².

Lõigetes 1–4 nimetamata seadmeid ja meetodeid võib salastatud teabekandja hävitamiseks kasutada vastavalt Kaitsepolitseiameti, Kaitseväe või Välisluureameti nõusolekul. Selleks nõusolekut andes võib määrata erandliku seadme või meetodi kasutamisele lisatingimusi, sealhulgas teabekandja liigi, sellel sisalduva teabe salastatuse taseme ja mahu ning hävitamise põhjustava ohuolukorra.

Fail hävitatakse kustutamise teel.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 83. Destruction of classified medium

(1) A paper shredder used for the destruction of a paper medium classified at the ‘secret’ and higher level must shred the paper into pieces that cannot be larger than 5 mm2.

(2) A paper shredder used for the destruction of a paper medium classified at the ‘confidential’ and lower level must shred the paper into pieces that cannot be larger than 10 mm2.

(3) Where the waste resulting from the shredding of a medium specified in subsections 1 and 2 is destroyed in such a manner that makes it impossible to restore the medium, a paper shredder which shreds the paper into pieces that cannot be larger 30 mm2 may be used for the destruction.

(4) A device used for the destruction of a storage medium must shred the storage medium into pieces that cannot be larger than:

1) in the case of a hard disk - 10 mm2;

2) in the case of an optical medium - 5 mm2;

3) in the case of a solid-state drive - 4 mm2.

(5) Equipment and methods not specified in subsections 1–4 may be used for the destruction of a classified medium with the consent of the Internal Security Service, the Defence Forces or the Foreign Intelligence Service respectively. Upon granting such consent, additional conditions may be imposed on the use of the exempted equipment or method, including the type of the medium, the classification level and volume of information contained therein, and the threat situation causing the destruction.

(6) A file is destroyed by deletion.

§ 84. Salastatud teabekandja hävitamine töötlemisluba omava isiku poolt

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

A-kategooria töötlemisluba omav isik, kelle valduses on salastatud teave, edastab hävitamisele kuuluva konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja hävitamiseks selle teabekandja koostanud töötlevale üksusele või Kaitsepolitseiametile.

Kaitsepolitseiameti kirjalikul loal võib A-kategooria töötlemisluba omav isik hävitada lõikes 1 nimetatud salastatud teabekandja ka iseseisvalt, järgides käesolevas määruses kehtestatud nõudeid.

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

Эстонский текст этой нормы изменился после переведённой редакции (01.01.2025): перевод не соответствует действующему тексту.

§ 84. Destruction of classified medium by legal persons

(1) Legal persons in private law who hold classified information transmit a medium classified at the ‘confidential’ and higher level, which is subject to destruction, including the original, copy and extract of the medium, for the destruction to the authority which prepared the classified medium or supported the application for the processing authorization of a state secret.

(2) With the written consent of the Internal Security Service, a legal person may also destroy the classified medium specified in subsection 1 on their own, in compliance with the requirements established in this Regulation.

§ 85. Salastatud teabekandjat hävitavad füüsilised isikud

Konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja, välja arvatud konfidentsiaalsel tasemel salastatud teabekandja registreerimata koopia hävitamises peab osalema vähemalt kaks isikut, kes allkirjastavad salastatud teabekandja hävitamise akti või annavad elektroonilise kinnituse dokumendihaldussüsteemis.

Hävitamises osalevatel isikutel peab olema asjakohasel tasemel salastatud teabele juurdepääsu õigus.

Faili mustandi või faili registreerimata koopia võib hävitada isik iseseisvalt.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 85. Natural persons destroying classified media

(1) The destruction of a medium classified at the ‘confidential’ and higher level, other than an unregistered copy of a medium classified as ‘confidential’, must involve at least two persons who sign the report of destruction of the classified medium or provide electronic confirmation in the document management system.

(2) The persons participating in the destruction must have the right of access to classified information at the appropriate level.

(3) A draft file or an unregistered copy of a file may be destroyed by a person independently.

§ 86. Salastatud teabekandja hävitamise akt

Salastatud teabekandja hävitamisel koostatakse salastatud teabekandja hävitamise akt.

Salastatud teabekandja hävitamise aktis peavad olema märgitud:

teabekandja registreerimiskuupäev ja -number, eksemplari number ja hävitatavate ühikute arv ning vajaduse korral eksemplaride arv;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

teabekandja hävitanud isikute andmed;

hävitamismeetod;

hävitamise õiguslik alus.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandja hävitamise akte säilitatakse turvaalal või dokumendihaldussüsteemis vähemalt kümme aastat. Füüsilisel teabekandjal oleva hävitamise akti võib hävitada pärast viie aasta möödumist, kui see on digiteeritud.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandja hävitamise akti koostamata võib hävitada:

konfidentsiaalsel ja madalamal tasemel salastatud teabekandja registreerimata koopia;

faili mustandi või faili registreerimata koopia, kui nende hävitamise toiming on töötlussüsteemisiseselt tõendatav.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 86. Report concerning destruction of classified media

(1) Upon destruction of a classified medium, a report of destruction of the classified medium is drawn up.

(2) The reports of destruction of classified media must include:

1) the registration date and number of the medium, the copy number and the number of units to be destroyed and, where necessary, the number of copies;

2) data of the persons who destroyed the medium;

3) method of destruction;

4) legal basis for destruction.

(3) The reports of the destruction of classified media are stored in a security area or in a document management system for at least ten years. The report of destruction of a physical medium may be destroyed after five years have passed in case it has been digitized.

(4) The following may be destroyed without drawing up a report of destruction of a classified medium:

1) an unregistered copy of a medium classified at a ‘confidential’ and lower level;

2) a draft of a file or an unregistered copy of the file, in case the report of destroying them is provable within the processing system.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 7. jagu Salastatud teabekandja vedamine › 1. jaotis Salastatud teabekandja vedamise üldnõuded

§ 87¹. Salastatud teabekandja vedamise üldnõuete kohaldamine

Käesolevas jaos sätestatud nõudeid ei kohaldata avalikus ruumis töötlemiseks ette nähtud töötlussüsteemiks või selle osaks olevale kaasaskantavale töötlusseadmele ja selles olevale salvestuskandjale, mida veetakse avalikus ruumis ilma üleandmise eesmärgita.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 87¹. Application of general requirements for transporting classified medium

The requirements provided in this division are not applied to a portable processing device which is a processing system, or a part thereof intended for processing in the public space and the storage medium in it, which is transported in a public space without the purpose of transfer.

§ 88. Salastatud teabekandja vedamiseks pakendamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandjat veetakse läbipaistmatus topeltpakendis.

Salastatud teabekandja peab olema pakendatud turvaliselt viisil, mis võimaldab tagantjärele tuvastada pakendi avamise. Vajaduse korral peab rakendama lisameetmeid pakendi sisu kaitsmiseks kõrvaliste isikute juurdepääsu eest.

Välispakendile märgitakse:

vastuvõtva töötleva üksuse nimi;

pakendis sisalduva teabekandja registreerimiskuupäev ja -number;

vajaduse korral vastuvõtva töötleva üksuse aadress.

Sisepakendile märgitakse:

adressaadiks vastuvõtva töötleva üksuse salastatud teabekandjate register;

pakendis sisalduva teabekandja salastatuse tase, registreerimiskuupäev ja -number ning ühikute arv;

märge „Leidmisel teavitada kohe Kaitsepolitseiametit“.

Kui teabekandjat veetakse avalikus ruumis ilma üleandmise eesmärgita, tuues selle pärast töötlemise vajaduse lõppemist tagasi töötleva üksuse administratiivalale või turvaalale, märgitakse sellise teabekandja nii välis- kui ka sisepakendile vähemalt töötleva üksuse nimi ning sisepakendile lisaks teabekandja salastatuse tase ja lõike 4 punktis 3 sätestatud märge.

Piiratud tasemel salastatud teabekandja vedamiseks võib välispakendina kasutada kotti, kohvrit või muud samalaadset eset, mis on lukustatud või plommitud või suletud muul viisil, mis takistab kõrvalistel isikutel selle avamist. Sellist välispakendit ei pea märgistama.

Töötlev üksus võib Kaitsepolitseiameti nõusolekul teha käesolevas paragrahvis sätestatud salastatud teabekandja pakendamise nõuetes erandeid tingimusel, et teabekandja turvalisus tagatakse muude meetmetega.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 88. Packaging of classified medium for transport

(1) The classified medium is transported in opaque double packaging.

(2) The classified medium must be securely packaged so that the opening of the package is detectable afterwards. Where necessary, additional measures must be taken to protect the contents of the package from access by unauthorized persons.

(3) The following is marked on the outer packaging:

1) name of the receiving processing entity;

2) registration date and number of the medium included in the package;

3) where necessary, the address of the receiving processing entity.

(4) The following is marked on the inner packaging:

1) the register of classified media of the recipient processing entity as the addressee;

2) the level of classification, registration date and number of the medium contained in the package and the number of items;

3) the marking "Leidmisel teavitada kohe Kaitsepolitseiametit” [upon finding notify the Internal Security Service immediately].

(5) In case the medium is transported in a public space without the purpose of transfer, bringing it back to the administrative or security area of ​the processing entity after the termination of the need for processing, both the outer and inner packaging of such a medium is marked with at least the name of the processing entity and, additionally to the inner packaging the classification level of the medium and the marking specified in clause 3 of subsection 4.

(6) For transportation of a medium classified as ‘restricted’, a bag, suitcase or other similar object which is locked or sealed or otherwise closed in such a manner as to prevent unauthorised persons from opening it may be used as an outer packaging. Such outer packaging need not be marked.

(7) A processing entity may, with the consent of the Internal Security Service, derogate from the packaging requirements for a classified medium set out in this section provided that the security of the medium is ensured by other measures.

§ 89. Vedamise korraldamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Enne salastatud teabekandja vedamist lepivad saatev töötlev üksus ning vastuvõttev töötlev üksus teabekandja vedamises kokku, järgides käesolevas määruses sätestatud nõudeid.

Kui salastatud teabekandja vedamise kohta kehtestatud nõudeid ei ole töötleval üksusel võimalik järgida, peab ta pöörduma salastatud teabekandja vedamise korraldamiseks Kaitsepolitseiameti või Kaitseväe poole.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 89. Organisation of transportation

(1) Prior to the transportation of a classified medium, the sending processing entity and the receiving processing entity agree on the transportation of the medium in compliance with the requirements laid down in this Regulation.

(2) In case it is not possible for the processing entity to comply with the requirements for the transportation of a classified medium, they must apply to the Internal Security Service or the Defence Forces for the organisation of the transportation of the classified medium.

§ 90. Vedamise viis

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandjat veetakse viisil, mis tagab, et teabekandja vedamisega seotud asjaoludest, sealhulgas selle vedamise faktist, on teadlikud üksnes isikud, kellele see on töö- või teenistusülesande tõttu vajalik.

Salastatud teabekandjat veetakse viivituseta, valides vedamiseks võimalikult lühikese teekonna ja ohutu viisi.

Kuller hoiab salastatud teabekandjat kuni üleandmiseni kogu aeg enda otseses valduses.

Kui konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandjat ei ole võimalik kohe vedada või teisele töötlevale üksusele üle anda, tagastatakse see saatva töötleva üksuse registripidajale või riigisaladuse kaitset korraldavale isikule.

Piiratud tasemel salastatud teabekandjat võib teisele töötlevale üksusele saata posti teel, kui on tagatud postisaadetise teekonna jälgimine ja saadetise väljastamine allkirja vastu.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 90. Method of transportation

(1) A classified medium is transported in a manner that ensures that only persons with the need-to-know about the circumstances related to the transport of the medium, including the fact of its transportation, are aware thereof due to their employment or service task.

(2) The classified medium is transported without delay choosing the shortest possible route and the safest possible manner for the transport.

(3) The courier keeps the classified medium in their direct possession all the time until delivery.

(4) In case it is not possible to immediately transport the medium classified at the ‘confidential’ and higher level or deliver to another processing entity, it is returned to the registrar of the sending processing entity or to the person organising the protection of state secrets.

(5) A medium classified as ‘restricted’ may be sent to another processing entity by mail, provided that the route of the postal item can be tracked and its delivery against signature is ensured.

§ 91. Kulleri juurdepääsuõigus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandjat vedaval kulleril peab olema asjakohasel tasemel salastatud teabele juurdepääsu õigus.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 91. Right of access of courier

A courier carrying a medium classified at the ‘confidential’ and higher level must have the right of access to information classified at the appropriate level.

§ 92. Salastatud teabekandja väljaviimine turvaalalt

Konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja võib turvaalalt välja viia üksnes saatva töötleva üksuse juhi, registripidaja või salastatud teabe kaitse juhendis määratud muu isiku loal ja vedamiseks mõeldud lukustatud kotis või kastis või plommitud diplomaatilise posti kotis.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 92. Removal of classified medium from security area

A medium classified at the ‘confidential’ and higher level may be taken out of the security area only with the permission of the head of the sending processing entity, registrar or another person appointed in the guidelines for the protection of classified information, and in a locked bag or box intended for transportation or in a sealed bag for diplomatic mail.

§ 93. Salastatud teabekandja üleandmis-vastuvõtmisakt

Salastatud teabekandja teisele töötlevale üksusele üleandmise kohta koostab saatev töötlev üksus üleandmis-vastuvõtmisakti. Piiratud tasemel salastatud teabekandja üleandmise kohta ei pea akti koostama.

Üleandmis-vastuvõtmisakti märgitakse:

teabekandja registreerimiskuupäev ja -number, kõrgeim salastatuse tase ning üleantavate ühikute arv. Üleandmis-vastuvõtmisakti ei tohi märkida viidet teabekandjal sisalduva teabe sisu kohta;

vastuvõtva töötleva üksuse nimi ja aadress;

üleandmise kuupäev ja kellaaeg;

vastuvõtja ees- ja perekonnanimi ning allkiri;

üleandja ees- ja perekonnanimi ning allkiri.

Vastuvõtja allkirjastab üleandmis-vastuvõtmisakti pärast pakendil ja aktis olevate kirjete võrdlemist.

Üleandmis-vastuvõtmisakti säilitatakse turvaalal vähemalt kümme aastat. Füüsilisel teabekandjal oleva akti võib hävitada pärast viie aasta möödumist, kui see on digiteeritud.

Ühes ja samas üleandmis-vastuvõtmisaktis võib kajastada mitme salastatud teabekandja üleandmist.

Käesolevat paragrahvi ei kohaldata teabekandjale, mida veetakse avalikus ruumis ilma üleandmise eesmärgita.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 93. Instrument of delivery and acceptance of classified medium

(1) Regarding the transfer of a classified medium to another processing entity, the sending processing entity prepares an instrument of delivery and acceptance. Such instrument needs not be prepared concerning the transfer of a medium classified as ‘restricted’.

(2) The following is marked in the delivery and acceptance instrument:

1) the registration date and number of the medium, the highest level of classification and the number of items to be transferred. The instrument of delivery and acceptance must not include a reference to the content of the information contained in the medium;

2) name and address of the receiving processing entity;

3) date and time of transfer;

4) given name and surname and signature of the recipient;

5) given name and surname and signature of the transferor.

(3) The recipient signs the instrument of delivery and acceptance after comparing the entries on the package and in the instrument.

(4) The instrument of delivery and acceptance is stored in the security area for at least ten years. An instrument on a physical medium may be destroyed after five years have passed in case it has been digitized.

(5) One and the same instrument of delivery and acceptance may record the transfer of several classified media.

(6) This section is not applied to a medium that is transported in a public space without the purpose of transfer.

§ 94. Salastatud teabekandja vastuvõtja kohustused

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandja vastuvõtmisel kontrollitakse, kas saadetis on kinnine ja avamisjälgedeta.

Avatud saadetise või avamisjälgedega saadetise või sellise kahtluse korral peab sellest kohe teavitama registripidajat või muud salastatud teabe kaitse juhendis määratud isikut.

Saadetis tuleb viivitamata üle anda registripidajale, kes korraldab teabe registreerimise ja töötleva üksuse sisese edastamise salastatud teabe kaitse juhendis sätestatud korras.

Registripidaja peab kontrollima, kas teabekandjad ja neis sisalduv vastavad märgitud ühikute arvule.

Käesolevat paragrahvi ei kohaldata teabekandjale, mida veetakse avalikus ruumis ilma üleandmise eesmärgita.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 94. Obligations of recipient of classified media

(1) Upon receipt of a classified medium it is verified whether the consignment is sealed and without traces of opening.

(2) In the case of an opened consignment or a consignment with traces of opening, or in case of such suspicion, the registrar or another person specified in the guidelines on the protection of classified information must be notified immediately.

(3) The consignment must be immediately handed over to the registrar, who organizes the registration of the information and the internal transfer inside the processing entity in accordance with the procedure provided in the instructions for the protection of classified information.

(4) The registrar must check whether the media and what is contained therein correspond to the indicated number of items.

(5) This section is not applied to a medium that is transported in a public space without the purpose of transfer.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 7. jagu Salastatud teabekandja vedamine › 2. jaotis Salastatud teabekandja vedamine administratiivala kaudu ühelt turvaalalt teisele

§ 95. Administratiivala kaudu vedav kuller

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud teabekandjat võib administratiivala kaudu ühelt turvaalalt teisele vedada üks kuller.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 95. Courier transporting through administrative area

A classified medium may be transported from one security area to another through an administrative area by one courier.

§ 96. Vedamise üldnõuete kohaldamine administratiivala kaudu vedamisel

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui teabekandja veetakse ühelt turvaalalt teisele administratiivala kaudu, ei kohaldata §-e 88 ja 92.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 96. Application of general requirements for transportation upon transporting through administrative area

In case a medium is transported from one security area to another through an administrative area, §§ 88 and 92 are not applied.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 7. jagu Salastatud teabekandja vedamine › 3. jaotis Salastatud teabekandja vedamine avaliku ruumi kaudu

§ 97. Avaliku ruumi kaudu vedav kuller

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Konfidentsiaalsel ja madalamal tasemel salastatud teabekandjat võib avaliku ruumi kaudu vedada üks kuller.

Salajasel ja kõrgemal tasemel salastatud teabekandjat peab avaliku ruumi kaudu vedama vähemalt kaks kullerit. Kaitsepolitseiameti, Kaitseväe, riigi julgeoleku volitatud esindaja või Välisluureameti loal võib seda teha üks kuller.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 97. Courier transporting through public space

(1) A medium classified at the ‘confidential’ and lower level may be transported through public space by one courier.

(2) A medium classified at the ‘secret’ and higher level may be transported through public space by at least two couriers. With the authorization of the Internal Security Service, the Defence Forces, the Estonian National Security Authority or the Foreign Intelligence Service, this may be done by one courier.

§ 98. Sõiduki kasutamine avaliku ruumi kaudu vedamisel

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salajasel ja kõrgemal tasemel salastatud teabekandjat veetakse üldjuhul autoga.

Auto aknad hoitakse suletud ja uksed lukustatud ning autojuht peab olema riigi ametiasutusega või saatva või vastuvõtva töötleva üksusega töö- või teenistussuhtes.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 98. Use of vehicle upon transporting through public space

(1) A medium classified at the ‘secret’ and higher level is generally transported by car.

(2) The windows of the car are kept closed and the doors locked, and the driver must be in an employment or service relationship with the state authority or the sending or receiving processing entity.

§ 99. Relva kandmine avaliku ruumi kaudu vedamisel

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Vähemalt üks täiesti salajasel tasemel salastatud teabekandjat vedav kuller peab kandma ametirelva. Kaitsepolitseiameti, Kaitseväe, riigi julgeoleku volitatud esindaja või Välisluureameti loal võib täiesti salajasel tasemel salastatud teabekandjat vedada ametirelva kandmata.

Ainsana ametirelva kandev kuller ei või teabekandja vedamise ajal juhtida sõidukit.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 99. Carrying weapon upon transporting through public space

(1) At least one courier transporting a medium classified as ‘top secret’ must carry a service weapon. With the permission of the Estonian Internal Security Service, the Defence Forces, the Estonian National Security Authority or the Foreign Intelligence Service, a medium classified as ‘top secret’ may be transported without carrying a service weapon.

(2) The courier who is the only one carrying a service weapon may not drive a vehicle while transporting a medium.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 7. jagu Salastatud teabekandja vedamine › 4. jaotis Salastatud teabekandja vedamine välismaale, välismaal ja välismaalt

§ 100. Välismaale, välismaal ja välismaalt kulleriga vedamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Välismaale, välismaal ja välismaalt veetakse konfidentsiaalsel ja kõrgemal tasemel salastatud teabekandja diplomaatilise või sõjalise kulleriga, kellel on asjakohasel tasemel salastatud teabele juurdepääsu õigus.

Vastavalt Kaitsepolitseiamet, Kaitsevägi, riigi julgeoleku volitatud esindaja või Välisluureamet võib anda kirjaliku loa lõikes 1 nimetatud teabekandjate vedamiseks diplomaatilise või sõjalise kullerita juhul, kui kulleri kasutamine tooks kaasa ebasoovitava viivituse või kui teistsuguse vedamise vajadus on tingitud objektiivsest olukorrast.

Kui salastatud teabekandjat soovib diplomaatilise või sõjalise kullerita vedada julgeolekuasutus, annab vedamiseks kirjaliku loa selle julgeolekuasutuse juht või tema volitatud isik.

Lõikes 2 nimetatud loas esitatakse nõuded, mida peab saadetise vedamisel täitma, eelkõige teekonna ja vedamiseks kasutatavate transpordivahendite kohta.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 100. Transporting to, in and from foreign states by courier

(1) A medium classified at the ‘confidential’ and higher level is transported to, in and from foreign states by a diplomatic or military courier who has the right of access to information classified at the appropriate level.

(2) The Estonian Internal Security Service, the Defence Forces, the Estonian National Security Authority or the Estonian Foreign Intelligence Service respectively may give a written authorisation for transporting the media specified in subsection 1 without using a diplomatic or military courier in case using the courier would result in an undesirable delay or in case the need to use a different form of transportation is due to an objective situation.

(3) In case a security authority wishes to transport a classified medium without using a diplomatic or military courier, the written authorisation for transportation is given by the head of that security authority or a person authorised thereby.

(4) The authorisation specified in subsection 2 sets out the requirements that must be met upon transportation of the consignment, in particular regarding the route and the means of transport used for transportation.

§ 101. Kuller välismaale, välismaal ja välismaalt vedamisel

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Välismaale, välismaal ja välismaalt vedamiseks peab kulleril olema diplomaatilise kulleri tunnistus, mille on väljastanud Välisministeerium, või diplomaatiline puutumatus.

Rahvusvahelise sõjalise operatsiooni piirkonnas võib salastatud teabekandjat vedada ka sõjalise kulleriga. Nõuded sõjalisele kullerile kehtestab Kaitseväe juhataja.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 101. Courier upon transportation to, in, from foreign states

(1) For transportation to, in and from foreign states, a courier must have a diplomatic courier certificate issued by the Ministry of Foreign Affairs, or diplomatic immunity.

(2) In the area of ​an international military operation, a classified medium may also be transported by a military courier. Requirements for military courier are established by the Commander of the Defence Forces.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 8. jagu Salastatud teabe elektrooniline töötlemine

§ 102. Elektrooniline töötlemine

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Salastatud teavet võib töödelda elektroonilise teabeturbe nõuetele vastavas töötlussüsteemis, millel on asjakohasel tasemel salastatud teabe töötlemiseks Välisluureameti poolt antud vastavussertifikaat või ajutine kasutusluba (edaspidi akrediteeritud süsteem) ja töötlemise ajal viibitakse sõltuvalt edastatavast teabest kas administratiiv- või turvaalal, välja arvatud §-s 103 sätestatud juhul.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 102. Electronic processing

Classified information may be processed in the processing system complying with the requirements for electronic information security, which has a certificate of compliance or a temporary use permit for processing classified information at the appropriate level of classification issued by the Estonian Foreign Intelligence Service (hereinafter accredited system) and during the processing they are staying, dependent on the communicated information, within the administrative or security area, except in the case provided in § 103.

§ 103. Elektroonilise töötlemise erandid

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Piiratud tasemel salastatud teavet võib töödelda avalikus ruumis:

möödapääsmatu vajaduse korral teabe operatiivseks edastamiseks või vastuvõtmiseks, kui kasutatakse avalikus ruumis töötlemiseks ette nähtud akrediteeritud süsteemi;

muu vajaduse korral teabe edastamiseks või vastuvõtmiseks üksnes juhul, kui kasutatakse avalikus ruumis töötlemiseks ette nähtud akrediteeritud süsteemi osaks olevat mobiiltelefoni.

[RT I, 06.10.2021, 1 – вступ. в силу 09.10.2021]

Kui konfidentsiaalsel või kõrgemal tasemel salastatud riigisaladuse või konfidentsiaalsel või salajasel tasemel salastatud välisteabe operatiivne edastamine on vajalik riigi julgeolekut, põhiseaduslikku korda või isikute elu, tervist või vara ähvardava vahetu ohu ennetamiseks või tõrjumiseks, võib seda edastada ja vastu võtta, kui kasutatakse vähemalt piiratud tasemel salastatud teabe töötlemiseks akrediteeritud süsteemi. Teabe edastaja ja vastuvõtja peavad iga kord sellest viivitamata teavitama oma töötleva üksuse riigisaladuse kaitset korraldavat isikut.

Kaitsevägi võib töödelda kuni salajasel tasemel salastatud operatsiooniplaanimist ja operatsioonijuhtimist käsitlevat riigikaitse riigisaladust või selle sisule vastavat salastatud välisteavet avalikus ruumis, kui sellise teabe edastamine on vajalik rahvusvahelises sõjalises koostöös osalemiseks või riigi sõjaliseks kaitsmiseks ning kasutatakse avalikus ruumis töötlemiseks ette nähtud akrediteeritud süsteemi.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui teabe edastaja või vastuvõtja viibib lõikes 1 või 2 sätestatud juhul avalikus ruumis, peab ta:

enne teabe suulist edastamist teavitama teist poolt oma viibimisest avalikus ruumis;

rakendama kõiki vajalikke meetmeid edastatava teabe kaitsmiseks avalikuks tuleku ning juurdepääsuõiguseta või teadmisvajaduseta isikute juurdepääsu eest.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Kui § 6 lõike 1 punktides 2–5 ja lõikes 3 nimetatud riigisaladuse või selle sisule vastava salastatud välisteabe operatiivne edastamata jätmine tooks kaasa jälitustoimingu nurjumise või seaks ohtu selles osalevad isikud, võib selle edastamise ja vastuvõtmise ajal viibida avalikus ruumis ning kasutada edastamiseks ja vastuvõtmiseks akrediteerimata süsteemi.

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 103. Exceptions in electronic processing

(1) Information classified as ‘restricted’ may be processed in a public space:

1) in case of unavoidable necessity for operational transmission or reception of information, in case an accredited system intended for processing in a public space is used;

2) where otherwise necessary for the transmission or receipt of information only in case a mobile phone that is part of an accredited system intended for processing in a public space is used.

(2) In case the operational transmission of a state secret, classified at the ‘confidential’ or higher level or foreign information classified as ‘confidential’ or ‘secret’, is necessary to prevent or counter an immediate threat to national security, constitutional order or the life, health or property of persons, it may be transmitted and received provided that a system accredited to process information classified at least at the ‘restricted’ level is used. The transmitter and receiver of information must immediately notify the person in charge of the protection of state secrets in their processing entity.

(2¹) The Defence Forces may process state secrets related to national defence dealing with operational planning and operational management classified up to the ‘secret’ level, or foreign classified information corresponding to that content, in public space, in case the transmission of such information is necessary for participation in international military cooperation or military defence of the state, and an accredited system intended for processing in public space is used.

(3) In case the sender or recipient of information is staying in a public space in the case provided in subsection 1 or 2, they are is required to:

1) notify the other party of their staying in a public space before communicating the information orally;

2) apply all the required measures to protect the transmitted information from disclosure to and access of persons without the right of access or need-to-know.

(4) in case a failure to operatively transmit the state secret specified in clauses 2–5 of subsection 1 and subsection 3 of § 6 or foreign classified information corresponding to that content would bring about a failure of surveillance activities or put the participating persons at risk, being present in a public space and using an unaccredited system for transmitting and receiving the corresponding information is allowed.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 9. jagu Elektrooniline teabeturve

§ 104. Mõisted

Käesolevas jaos kasutatakse mõisteid järgmises tähenduses:

elektrooniline teabeturve – teabe käideldavuse, salajasuse ja terviklikkuse tagamine salastatud teabe töötlussüsteemides;

töötlussüsteemi akrediteerimine – töötlussüsteemi elektroonilise teabeturbe nõuetele vastavuse hindamine;

käideldavus – teabe kasutamise ja teabele juurdepääsu võimalus volitatud isiku nõudel;

salajasus – teabe volitamata isikutele mittekättesaadavus või mittearusaadavus;

terviklikkus – teabe omadus olla volitamata isikute poolt muutmata, täiendamata või hävitamata;

oht – teabe käideldavuse, salajasuse või terviklikkuse potentsiaalne kahjustumine;

intsident – olukord, kus teave või selle kaitsmist toetavad süsteemitoimingud ja -vahendid kaotasid või võisid kaotada varguse, sabotaaži, terrorismiaktide, muu lubamatu tegevuse või turvanõrkuste tõttu salajasuse, terviklikkuse või käideldavuse (sealhulgas teabe kadumine, volitamata isikutele teatavakssaamine, volitamata isikute poolt muutmine või hävitamine või rünne süsteemi suhtes);

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

turvarisk – intsidendi esinemise tõenäosus;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

riskihaldus – vara, teabe, ohu, intsidendi ja turvariski analüüs, mille põhjal määratakse kindlaks teabe ja selle kaitsmist toetavate süsteemitoimingute ja -vahendite turvameetmed. Riskihaldus hõlmab süsteemi turvameetmete planeerimist, korraldamist, kasutamist ja kontrollimist, selleks et vältida turvariski väljumist vastuvõetavatest piiridest ja intsidente;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

haavatavuse analüüs – süsteemi üksikasjalik kontrollimine, et selgitada välja süsteemi turvanõrkused, ohud süsteemis töödeldava teabe salajasusele, terviklikkusele ja käideldavusele ning süsteemi vastuvõtlikkus mis tahes ründele või ohule;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

töötlussüsteemi turbejuhend – dokument, milles määratakse töötlussüsteemi tehnilisest lahendusest lähtudes kohustuslikud turvanõuded ning töötlussüsteemi eriõigustega kasutajate õigused ja kohustused töötlussüsteemi kasutamisel ning selle turvalisuse tagamisel;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

töötlussüsteemi kasutusjuhend – dokument, milles määratakse töötlussüsteemi turbejuhendis määratud kohustuslikest turvanõuetest lähtudes töötlussüsteemi kasutajate õigused ja kohustused töötlussüsteemi kasutamisel ning selle turvalisuse tagamisel;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

väline turvakeskkond – süsteemi paiknemiskohta ümbritsev keskkond, sealhulgas hoone või ala, milles toimuvad sündmused võivad mõjutada süsteemi turvalisust;

sisemine turvakeskkond – välise turvakeskkonnaga piirnev ruum või ala, kus paiknevad süsteemi komponendid või kus neid kasutatakse;

elektrooniline turvakeskkond – piirdub süsteemi komponentidega, mille abil teavet elektrooniliselt töödeldakse ning mille kaitseks süsteemi käitav personal rakendab elektroonilisi turvameetmeid;

paljastav kiirgus – töötlussüsteemist soovimatult kiirguv elektromagnetiline signaal, mis võimaldab ebaseaduslikku juurdepääsu teabele;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

kasutuslugu – töötlussüsteemi eesmärgi kirjeldus, millest selgub kes, millist teavet, kus ja kuidas töötleb;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

kaasaskantav töötlusseade – töötlussüsteemiks või selle osaks olev seade, mida saab töötlussüsteemi teiste osadega füüsiliselt ühendamata kasutada töötlussüsteemis oleva teabe töötlemiseks.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 104. Definitions

In this Division, the definitions are used in the following meaning:

1) electronic information security - ensuring availability, secrecy and integrity of information in the classified information processing systems;

2) accreditation of the processing system – assessment of the compliance with the requirements for electronic information security of the processing system;

3) availability – the possibility of using information and accessing information at the request of an authorized person;

4) secrecy - unavailability or incomprehensibility of information to unauthorized persons;

5) integrity – the property of information not to be altered, supplemented or destroyed by unauthorized persons;

6) threat – potential damage to the availability, secrecy or integrity of information;

7) incident - a situation where information or the system operations and devices supporting its protection have lost or could have lost secrecy, integrity or availability due to theft, sabotage, acts of terrorism, other prohibited actions or security weaknesses (including loss of information, disclosure to unauthorized persons, modification or destruction by unauthorized persons or attack on the system);

8) security risk – the probability of an incident occurring;

9) risk management – ​analysis of property, information, threat, incident and security risk, based on which the security measures of information and system operations and devices supporting its protection are determined. Risk management includes the planning, organization, use and control of security measures of the system in order to prevent security risk from exceeding acceptable limits and incidents;

10) vulnerability analysis - a detailed inspection of the system in order to find out security weaknesses of the system, threats to the secrecy, integrity and availability of information processed in the system, and the vulnerability of the system to any attack or threat;

11) security guide for the processing system - a document in which the mandatory security requirements and the rights and obligations of users with a special right to access the processing system are determined upon using the processing system and ensuring its security based on the technical solution of the processing system;

12) user guide for the processing system - a document in which the rights and obligations of the users of the processing system upon using the processing system and ensuring its security are determined based on the mandatory security requirements specified in the security guide for the processing system;

13) external security environment - the environment surrounding the location of the system, including a building or an area where the events taking place may affect the security of the system;

14) internal security environment - the external security environment bordering a room or area where system components are located or where they are used;

15) electronic security environment - is limited to the system components, by means of which information is processed electronically and for the protection of which the staff operating the system implements electronic security measures;

16) revealing radiation – an electromagnetic signal emitted undesirably from the processing system, which enables illegal access to information;

17) usage history – a description of the purpose of the processing system, which reflects who processes what information, where and how;

18) portable processing device - a device that forms a processing system or a part of it, which can be used for processing information in the processing system without being physically connected to other parts of the processing system.

§ 105. Elektroonilise teabeturbe põhimõtted

Käesolevas osas sätestatakse elektroonilise teabeturbe nõuded salastatud teabe kaitseks selle elektroonilisel töötlemisel.

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlusseadme, milles töötlemiseks lubatud kõrgeim teabe salastatuse tase on piiratud, võib viia väljapoole sisemist turvakeskkonda, kui:

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

salastatud teave on krüpteeritud nõuetele vastavate krüptomaterjalidega või kaitstud volitamata juurdepääsu eest muu Välisluureameti lubatud meetodiga;

[RT I, 06.10.2021, 1 – вступ. в силу 09.10.2021]

töötlusseadmel ei ole märgistust, mis viitaks töödeldava salastatud teabe salastatuse tasemele.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Elektroonilise teabeturbe tagamisel salastatud välisteabe kaitseks võetakse täiendavalt arvesse salastatud välisteabe avaldaja poolt ettenähtud nõudeid.

Elektroonilise teabeturbe tagamisel arvestatakse eelkõige järgmisi turvapõhimõtteid:

kasutada võib üksnes funktsioone, protokolle või teenuseid, mis on vajalikud teabe töötlemiseks või selle turvalisuse tagamiseks – minimaalsuse põhimõte;

katkematult peab toimuma süsteemi turvariskide ohjamine, sealhulgas vältimine, vähendamine, kõrvalejuhtimine ja lubatav aktsepteerimine – turvariskide pideva haldamise põhimõte – ja süsteemi turvalisuse regulaarne kontrollimine;

süsteemi kasutajatel on ainult tööülesannete täitmiseks vajalikud kasutajaõigused – privileegide piiratuse põhimõte;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

eeldatakse kõigi süsteemiga ühendatud teiste süsteemide ebausaldusväärsust ning nendega teabe vahetamisel peab rakendama piisavaid turvameetmeid – isekaitsvate sõlmede kasutamise põhimõte;

ühe kasutatava turvameetme rikke korral ei tohi süsteem muutuda ebaturvaliseks – sügavuti kaitse põhimõte.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 105. Electronic information security principles

(1) Electronic information security requirements for the protection of classified information upon processing it electronically are provided in this subchapter.

(4) A processing device, in which the highest level of information classification permitted for processing is ‘restricted’, may be taken outside the internal security environment in case:

1) the classified information has been encrypted with compliant cryptographic materials or protected from unauthorised access by another method authorised by the Estonian Foreign Intelligence Service;

2) the processing device bears no marking which would refer to the level of classification of the information processed therein.

(5) Upon ensuring electronic information security for the protection of foreign classified information, the requirements prescribed by the discloser of the foreign classified information are taken into account additionally.

(6) When ensuring electronic information security, the following security principles are considered in particular:

1) only the functions, protocols or services that are necessary for processing information or ensuring its security may be used - the principle of minimality;

2) management of system security risks, including prevention, reduction, diversion and permissible acceptance - the principle of continuous management of security risks - and regular control of system security must take place without interruption;

3) users of the system only have the user rights necessary to perform their tasks - the principle of privilege limitation;

4) the unreliability of all other systems connected to the system is assumed, and adequate security measures must be implemented upon exchanging information with them - the principle of using self-protecting nodes;

5) in case of a failure of one of the security measures used, the entire system must not lose its security - the in-depth defence principle.

§ 106. Töötlussüsteemile esitatavad nõuded

Salastatud teabe töötlussüsteemis peab olema tagatud salastatud teabe käideldavus, salajasus ja terviklikkus.

Salastatud teabe töötlussüsteem peab võimaldama:

tuvastada ja registreerida isikud, kes omasid või võisid omada juurdepääsu salastatud teabe kaitsmist toetavatele süsteemitoimingutele ja -vahenditele;

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

eristada süsteemi kasutajaid salastatud teabele juurdepääsu õiguse põhjal;

juurdepääsu teabele ja selle kaitsmist toetavatele süsteemitoimingutele ja -vahenditele üksnes juurdepääsuõiguse ja põhjendatud teadmisvajaduse olemasolul;

kontrollida teabe ning selle kaitsmist toetavate süsteemitoimingute ja -vahendite salajasust, terviklikkust, käideldavust, samuti nende päritolu, usaldatavust ja ühendusi;

saavutada olukorra, kus elektroonilise teabeturbe kaitsemehhanismid toimivad nõuetekohaselt süsteemi kogu kasutusaja jooksul;

ära hoida ja kõrvaldada intsidente ning vältida või vähendada nende tekkimisega kaasnevat kahju;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

käsitleda intsidente, mille käigus määratakse kindlaks ja registreeritakse süsteemile või selle osale avaldunud oht ja selle tagajärjel teabele tekkinud kahju ning selle kõrvaldamiseks võetud meetmed.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Täpsemad nõuded töötlussüsteemile, sealhulgas sellega seotud töötlevatele üksustele ja selle kasutajatele, on esitatud lisas 14. Välisluureamet võib lähtuvalt turbehinnangust seada töötlussüsteemile täiendavaid nõudeid.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Töötlev üksus võib rakendada lisas 14 esitatud nõuetest rangemaid nõudeid.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Töötlev üksus võib lisas 14 esitatud nõuet rakendada osaliselt või jätta rakendamata erandina üksnes juhul, kui sellest tulenevad riskid on kirjeldatud töötlussüsteemi riskianalüüsis, seda kompenseerivad turvameetmed on kirjeldatud töötlussüsteemi turbejuhendis ja Välisluureamet on need töötlussüsteemi akrediteerimisel heaks kiitnud.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Lisaks lõikes 2³ sätestatule võib töötlev üksus jätta lisas 14 esitatud nõude rakendamata juhul, kui rakendamine on töötlussüsteemi väiksuse või ülesehituse tõttu võimatu, seda on kirjeldatud töötlussüsteemi turbejuhendis ja Välisluureamet on selle töötlussüsteemi akrediteerimisel heaks kiitnud.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Kui lisas 14 esitatud nõude rakendamine nõuab töötlevalt üksuselt regulaarseid toiminguid, peab nende sagedus olema kirjeldatud töötlussüsteemi turbejuhendis ning vastama töötlussüsteemi kasutusintensiivsusele.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Töötlussüsteemi kohta käiv teave dokumenteeritakse töötlussüsteemi turbejuhendis ja töötlussüsteemi kasutusjuhendis.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemiga seotud töötlevad üksused teostavad oma ülesannete ulatuses pidevat töötlussüsteemi riskihaldust.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 106. Requirements for processing system

(1) The availability, secrecy and integrity of classified information must be ensured in the processing system of classified information.

(2) The processing system of classified information must enable:

1) identify and register persons who had or could have had access to system operations and devices supporting the protection of classified information;

2) distinguish the users of the system based on the right of access to classified information;

3) access to information and the system operations and devices supporting protection of information only in case there is a right of access and a justified need-to-know;

4) checking the secrecy, integrity, availability of information and the system operations and devices supporting its protection, as well as their origin, reliability and connections;

5) achieve a situation where the protection mechanisms of electronic information security function properly during the entire period of using the system;

6) prevent and eliminate incidents and prevent or reduce the damage caused by the incidents;

7) deal with incidents during which the threat to the system or its part and the resulting damage to the information and the measures taken to eliminate the damage are determined and recorded.

(2¹) More detailed requirements for the processing system, including related processing entities and the users thereof, are presented in Annex 14. Based on the security assessment, the Foreign Intelligence Service may set additional requirements to the processing system.

(2²) The processing entity may apply stricter requirements than those specified in Annex 14.

(2³) The processing entity may apply the requirement set out in Annex 14 in part or not apply it as an exception, only in case the resulting risks are described in the risk analysis of the processing system, the compensating security measures are described in the security guide for the processing system and the Foreign Intelligence Service has approved them during the accreditation of the processing system.

(2⁴) In addition to the provisions of subsection 2³, the processing entity may not implement the requirement presented in Annex 14, in case the implementation is impossible due to the small size or structure of the processing system, this is described in the security guide for the processing system and the Foreign Intelligence Service has approved this upon accreditation of the processing system.

(2⁵) In case the application of the requirement presented in Annex 14 requires the processing entity to carry out regular operations, their frequency must be described in the security guide for the processing system and must correspond to the intensity of use of the processing system.

(3) Information about the processing system is documented in the security guide and the user guide for the processing system.

(4) The processing entities related to the processing system perform continuous risk management of the processing system within the scope of their tasks.

§ 106¹. Töötlussüsteemiga seotud töötlevad üksused

Töötlussüsteemi eest vastutav töötlev üksus (edaspidi vastutav üksus):

vastutab töötlussüsteemi haldamise seaduslikkuse ning töötlussüsteemi ja selles töödeldava teabe turvalisuse tagamise eest;

korraldab töötlussüsteemi arendamist vastavalt kasutava üksuse vajadustele;

planeerib vahendid töötlussüsteemi haldamiseks ja arendamiseks;

otsustab kasutavate üksuste töötlussüsteemiga liitumise üle;

koostab koostöös haldava ja kasutava üksusega töötlussüsteemi riskianalüüsi ning hindab regulaarselt selle ajakohasust.

Töötlussüsteemi haldav töötlev üksus (edaspidi haldav üksus):

haldab töötlussüsteemi;

arendab töötlussüsteemi tehnilist lahendust vastavalt vastutava üksuse suunistele;

tagab töötlussüsteemi tehnilise lahenduse toimimise;

tagab töötlussüsteemi ja selles töödeldava teabe turvalisuse ning kontrollib regulaarselt turvameetmete toimimist.

Töötlussüsteemi kasutav töötlev üksus (edaspidi kasutav üksus):

töötleb töötlussüsteemis tema valduses olevat teavet;

esitab vastutavale üksusele töötlussüsteemi kasutamise ja arendamise vajadused;

tagab oma asukohapunktis töötlussüsteemi ja selles töödeldava teabe turvalisuse, arvestades riskianalüüsis määratud turvariske, nende vastuvõetavaid piire ja turvameetmeid.

Lõigetes 1–3 loetletud ülesandeid võib täita sama töötlev üksus, tingimusel et rollide lahusus on töötlussüsteemi turbejuhendis kirjeldatud ja sisemise töökorraldusega tagatud.

Ühe töötlussüsteemi vastutava üksuse ülesandeid ei või täita mitu töötlevat üksust.

Ühel töötlussüsteemil võib olla mitu haldavat üksust ja kasutavat üksust.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 106¹. Processing entities related to the processing system

(1) The processing entity responsible for the processing system (hereinafter the responsible entity):

1) is responsible for the legality of managing the processing system and ensuring the security of the processing system and the information processed therein;

2) organizes the development of the processing system according to the needs of the using entity;

3) plans resources for managing and developing the processing system;

4) decides on joining the processing system of the using entities;

5) prepares a risk analysis of the processing system in cooperation with the managing and using entity and regularly assesses its up-to-datedness.

(2) The processing entity managing the processing system (hereinafter the managing entity):

1) manages the processing system;

2) develops the technical solution of the processing system according to the guidelines of the responsible entity;

3) ensures the operation of the technical solution of the processing system;

4) ensures the security of the processing system and the information processed in it and regularly checks the operation of security measures.

(3) The processing entity using the processing system (hereinafter using entity):

1) processes the information in their possession in the processing system;

2) submits the needs for the use and development of the processing system to the responsible entity;

3) ensures the security of the processing system and the information processed therein at their location, taking into account the security risks determined in the risk analysis, their acceptable limits and security measures.

(4) The tasks listed in subsections 1-3 may be performed by the same processing entity, provided that the separation of roles is described in the security guide for the processing system and ensured by internal work arrangements.

(5) The tasks of one responsible entity for the processing system may not be performed by several processing entities.

(6) One processing system may have several managing entities and using entities.

§ 106². Töötlussüsteemi eest vastutav eriõigustega kasutaja

Töötlussüsteemi eest vastutaval eriõigustega kasutajal peab olema vähemalt töötlussüsteemis töödeldava teabe kõrgeimale salastatuse tasemele vastav juurdepääsuõigus.

Salastatud välisteabe töötlemiseks akrediteeritud töötlussüsteemi eest vastutava eriõigustega kasutaja puhul tuleb lisaks lõikes 1 sätestatule arvestada salastatud välisteabe avaldaja esitatud nõudeid.

Töötlussüsteemi eest vastutavad eriõigustega kasutajad määrab töötleva üksuse juht või tema volitatud isik kirjalikult.

Töötlussüsteemi eest vastutava eriõigustega kasutaja määramisest või vahetumisest teavitatakse viivitamata kirjalikult Välisluureametit ning Kaitsepolitseiametit. Üks julgeolekuasutus ei teavita süsteemi eest vastutava eriõigustega kasutaja määramisest või vahetumisest teist julgeolekuasutust.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 106². User with special rights responsible for processing system

(1) The user with special rights responsible for the processing system must have right of access corresponding to at least the highest level of classification of information processed in the processing system.

(2) In the case of a user with special rights responsible for the processing system accredited for the processing of foreign classified information, in addition to the provisions of subsection 1, the requirements submitted by the originator of foreign classified information must be taken into account.

(3) Users with special rights responsible for the processing system are appointed in writing by the head of the processing entity or a person authorized thereby.

(4) The Foreign Intelligence Service and the Internal Security Service are notified in writing immediately of the appointment or change of a user with special rights responsible for the processing system. One security authority does not notify another security authority of the appointment or change of a user with special rights responsible for the system.

§ 106³. Juurdepääs töötlussüsteemile

Töötlussüsteemi kasutaja võib olla teise töötleva üksuse juurdepääsuõiguse ja teadmisvajadusega töötaja või ametnik, kui see on vajalik teise töötleva üksuse ülesannete täitmiseks.

Töötlussüsteemi osad võivad asuda teise töötleva üksuse otseses valduses ning töötlussüsteemi eest vastutav eriõigustega kasutaja võib olla teise töötleva üksuse töötaja või ametnik, kui on tagatud § 106 lõikes 2 ja lisas 14 sätestatud nõuete täitmine.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 106³. Access to processing system

(1) The user of the processing system may be an employee or official of another processing entity with the right of access and a need-to know, in case this is necessary for the performance of the tasks of the other processing entity.

(2) Parts of the processing system may be in the direct possession of another processing entity, and the user with special rights responsible for the processing system may be an employee or official of another processing entity, in case compliance with the requirements provided in subsection 2 of § 106 and Annex 14 is ensured.

§ 107. Töötlussüsteemi turbejuhend

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemi turbejuhendis esitatakse:

töötlussüsteemi ja selles töödeldava teabe üldine kirjeldus;

vastutav üksus, haldavad üksused ja kasutavad üksused;

töötlussüsteemi eest vastutavate eriõigusega kasutajate ülesanded, õigused ja kohustused;

töötlussüsteemi turvalisuse korraldamise kirjeldus;

töötlussüsteemi tehniline kirjeldus, sealhulgas tehniline teave töötlussüsteemi ühenduste kohta teiste süsteemidega;

töötlussüsteemi riist- ja tarkvara loetelu, konfiguratsioon ja nende halduse kirjeldus;

töötlussüsteemile esitatavate turvanõuete kirjeldus, ülevaade töötlussüsteemi riskianalüüsi tulemustest ning neist lähtuvate turvameetmete loetelu.

Töötlussüsteemi turbejuhendi töötab välja vastutav üksus koostöös haldava üksusega ja selle kehtestab vastutava üksuse juht. Enne kehtestamist kooskõlastab vastutav üksus töötlussüsteemi turbejuhendi Välisluureametiga.

Töötlussüsteemi turbejuhendit täpsustatakse töötlussüsteemi ehitamise ja kasutamise käigus, juhul kui tehakse muudatusi, näiteks kui muudetakse töötlussüsteemi või selle osa kasutusotstarvet, ülesehitust, füüsilist asukohta, töötlussüsteemi riist- või tarkvaras tehakse suuremahulisi muudatusi, ilmnevad uued olulised ohud või muudetakse töötlussüsteemis töödeldava salastatud teabe taset. Töötlussüsteemi turbejuhendi muudatused kooskõlastab vastutav üksus Välisluureametiga.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 107. Security guide for processing system

(1) The security guide for the processing system sets out:

1) a general description of the processing system and information it processes;

2) a responsible entity, managing entities and using entities;

3) tasks, rights and obligations of users with special rights responsible for the processing system;

4) description of the security arrangements for the processing system;

5) technical specification of the processing system, including technical information about the connections of the processing system with other systems;

6) a list of the hardware and software of the processing system, their configuration and description of their management;

7) a description of the security requirements for the processing system, an overview of the results of the risk analysis of the processing system and a list of security measures based on them.

(2) The security guide for the processing system is developed by the responsible entity in cooperation with the managing entity and is established by the head of the responsible entity. Prior to establishment, the responsible entity coordinates the security guide for the processing system with the Foreign Intelligence Service.

(3) The security guide for the processing system is specified during the construction and use of the processing system, in case modifications are made, for example, in case the purpose of use, structure, physical location of the processing system or a part thereof is changed, large-scale modifications are made to the hardware or software of the processing system, new significant threats appear or the classification level of information processed in the processing system is changed. Changes to the security guide for the processing system are coordinated with the Foreign Intelligence Service by the responsible entity.

§ 108. Töötlussüsteemi kasutusjuhend

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemi kasutusjuhendis esitatakse:

töötlussüsteemi lühikirjeldus;

töötlussüsteemi kasutajad ning nende ülesanded, õigused ja kohustused;

salastatud teabe elektroonilise töötlemise juhised;

töötlussüsteemis kasutatavate teabekandjate töötlemise kirjeldus;

töötlussüsteemi intsidentide haldamise ja ohuolukorras tegutsemise kirjeldus.

Töötlussüsteemi kasutusjuhendi töötab töötlussüsteemi turbejuhendist lähtudes välja vastutav üksus koostöös haldava üksusega ja selle kehtestab vastutava üksuse juht. Enne kehtestamist kooskõlastab vastutav üksus töötlussüsteemi kasutusjuhendi Välisluureametiga.

Töötlussüsteemi kasutusjuhendit täpsustatakse töötlussüsteemi kasutamise käigus, juhul kui tehakse muudatusi, näiteks kui muudetakse töötlussüsteemi või selle osa kasutusotstarvet, ülesehitust, füüsilist asukohta, töötlussüsteemi riist- või tarkvaras tehakse suuremahulisi muudatusi, ilmnevad uued olulised ohud või muudetakse töötlussüsteemis töödeldava salastatud teabe taset. Töötlussüsteemi kasutusjuhendi muudatused kooskõlastab vastutav üksus Välisluureametiga.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 108. User guide for processing system

(1) The user guide for the processing system sets out:

1) a brief description of the processing system;

2) users of the processing system and their tasks, rights and obligations;

3) instructions for electronic processing of classified information;

4) description of the processing of media used in the processing system;

5) a description of the incident management of the processing system and actions to be taken in an emergency situation.

(2) The user guide for the processing system is developed by the responsible entity in cooperation with the managing entity, based on the security guide for the processing system, and established by the head of the responsible entity. Prior to the establishment, the responsible entity coordinates the user guide for the processing system with the Foreign Intelligence Service.

(3) The user guide for the processing system is specified during the use of the processing system, in case modifications are made, for example, in case changes are made to the purpose of use, structure, physical location of the processing system or a part thereof, large-scale changes are made to the hardware or software of the processing system, new significant threats become evident or the level of classified information processed in the processing system is changed. Modifications to the user guide for the processing system are coordinated with the Foreign Intelligence Service by the responsible entity.

§ 109. Töötlussüsteemi akrediteerimine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemi akrediteerimise eesmärk on veenduda, et töötlussüsteem vastab elektroonilise teabeturbe tagamiseks kehtestatud nõuetele.

Töötlussüsteemi akrediteerimise käigus Välisluureamet:

tutvub vastutava üksuse esitatud töötlussüsteemi eesmärgi ja kasutuslugudega;

vaatab üle töötlussüsteemi riskianalüüsi protsessi ja tulemused ning teeb kindlaks, et vastutav üksus on jääkriskid tuvastanud ja aktsepteerinud;

hindab töötlussüsteemi ülesehituse ning välimise, sisemise ja elektroonilise turvakeskkonna vastavust nõuetele;

hindab töötlussüsteemi turbejuhendit, töötlussüsteemi kasutusjuhendit ja muid töötlussüsteemi turvalisust puudutavaid dokumente;

hindab turvameetmete rakendamise ning töötlussüsteemi turvalisust puudutavate protseduuride vastavust nõuetele;

annab üldise turbehinnangu, mis väljendab töötlussüsteemis teabe kaitstuse vastavust nõuetele ja nende rakendamise hetkeseisu.

Välisluureamet algatab töötlussüsteemi akrediteerimise vastutava üksuse taotlusel või omal algatusel. Vastutav üksus lisab töötlussüsteemi akrediteerimise taotlusele töötlussüsteemi turbejuhendi ja töötlussüsteemi kasutusjuhendi. Lõike 2 punktides 1–3, 5 ja 6 nimetatud teabe esitab vastutav üksus Välisluureameti nõudmisel.

Töötlussüsteemi akrediteerimise tulemusena antakse töötlussüsteemile Välisluureameti peadirektori käskkirjaga vastavussertifikaat, kui:

töötlussüsteem vastab elektroonilise teabeturbe nõuetele või

töötlussüsteem ei vasta kõigile elektroonilise teabeturbe nõuetele, kuid sellest tingitud turvariskid on kompenseerivate turvameetmete tõttu püsivalt vastuvõetavad.

Töötlussüsteemi akrediteerimise tulemusena antakse töötlussüsteemile Välisluureameti peadirektori käskkirjaga ajutine kasutusluba, kui töötlussüsteem ei vasta kõigile elektroonilise teabeturbe nõuetele, kuid sellest tingitud turvariskid on ajutiselt vastuvõetavad.

Töötlussüsteemile, mida on vaja enne kasutusele võtmist testida, võib Välisluureameti peadirektori käskkirjaga väljastada testimiseks ajutise kasutusloa (edaspidi testimisluba). Testimisloa alusel võib töötlussüsteemi kasutada ja salastatud teavet töödelda üksnes töötlussüsteemi tehnilise lahenduse ja töötlussüsteemi ühenduste testimiseks. Testimisloa saamiseks peab vastutav üksus esitama töötlussüsteemi turbejuhendi ja töötlussüsteemi kasutusjuhendi üksnes nende olemasolu korral. Testimisloas määratakse töötlussüsteemi testimise tingimused, näiteks testimise eesmärk ja ulatus, testimise ajal töödelda lubatud teabe salastatuse tase ning testimise tähtaeg.

Uue töötlussüsteemi ehitamise ja kasutusele võtmise korral võib töötlev üksus esitada taotluse koos planeeritava töötlussüsteemi ülesehituse lühikirjeldusega, misjärel väljastatakse ajutine kasutusluba üksnes töötlussüsteemi turbejuhendi ja töötlussüsteemi kasutusjuhendi koostamiseks.

Välisluureamet keeldub peadirektori käskkirjaga töötlussüsteemile vastavussertifikaati või ajutist kasutusluba väljastamast ning keelab selle kasutamise salastatud teabe töötlemiseks, kui töötlussüsteem ei vasta elektroonilise teabeturbe nõuetele ja sellest tingitud turvariskid ei ole vastuvõetavad.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 109. Accreditation of processing system

(1) The purpose of accreditation of the processing system is to make sure that the processing system meets the requirements established to ensure electronic information security.

(2) During the accreditation of the processing system, the Foreign Intelligence Service:

1) examines the purpose and usage history of the processing system provided by the responsible entity;

2) reviews the process and results of the risk analysis of the processing system and makes sure that the responsible entity has identified and accepted residual risks;

3) evaluates the compliance of the structure of the processing system and the external, internal and electronic security environment with the requirements;

4) evaluates the security guide and user guide for the processing system and other documents concerning the security of the processing system;

5) evaluates the compliance with the requirements of the implementation of security measures and procedures concerning the security of the processing system;

6) provides a general security assessment, which expresses the compliance of information protection in the processing system with the requirements and current state of their implementation.

(3) The Foreign Intelligence Service initiates the accreditation of the processing system at the request of the responsible entity or on their own initiative. The responsible entity attaches the security guide and the user guide for the processing system to the application for accreditation of the processing system. The information specified in clauses 1–3, 5 and 6 of subsection 2 is provided by the responsible entity at the request of the Foreign Intelligence Service.

(4) As a result of accreditation of the processing system, a certificate of compliance is issued to the processing entity by the directive of the Director General of the Foreign Intelligence Service, in case:

1) the processing system is in compliance with the requirements of electronic information security or

2) the processing system does not meet all the requirements of electronic information security, but the resulting security risks are permanently acceptable due to compensating security measures.

(5) As a result of accreditation of the processing system, a temporary use permit is issued to the processing system by the directive of the Director General of the Foreign Intelligence Service in case the processing system does not meet all the requirements of electronic information security, but the resulting security risks are temporarily acceptable.

(6) A temporary use permit for testing (hereinafter testing permit) may be issued by the directive of the Director General of the Foreign Intelligence Service to the processing system which needs to be tested before being put into use, Based on the test permit, the processing system may be used and classified information may be processed only for testing the technical solution of the processing system and the connections of the processing system. In order to obtain a test permit, the responsible entity must submit the security guide and the user guide for the processing system only in case they are available. The testing permit specifies the conditions for testing the processing system, such as the purpose and scope of testing, the level of classification of information allowed to be processed during testing, and the testing deadline.

(7) In case of construction and commissioning of a new processing system, the processing entity may submit an application together with a brief description of the planned structure of the processing system, after which a temporary use permit is issued only for the preparation of the security guide and the user guide for the processing system

(8) The Foreign Intelligence Service refuses to issue a certificate of compliance or a temporary use permit to the processing system by the directive of the Director General and prohibits its use for processing classified information in case the processing system does not meet the requirements of electronic information security and the resulting security risks are not acceptable.

§ 110. Teabe andmise kohustus

Välisluureameti nõudel on töötlev üksus kohustatud viivitamata andma, sealhulgas kirjalikus vormis, teavet tema valduses oleva süsteemi ja elektroonilise teabeturbega seotud asjaolude kohta ning tagama Välisluureametile tööajal pideva ning puhkepäevadel ja riiklikel pühadel eelnevalt kokkulepitud ajal juurdepääsu süsteemi osadele, sõltumata nende paiknemiskohast.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 110. Obligation to provide information

At the request of the Foreign Intelligence Service, the processing entity is obliged to immediately provide, including in written form, information about the system in their possession and the circumstances related to electronic information security, and to ensure the Foreign Intelligence Service with continuous access to parts of the system during working hours and during rest days and national holidays at pre-agreed times, regardless of their location.

§ 111. Töötlussüsteemi uuesti akrediteerimine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlussüsteemi uuesti akrediteerimiseks esitab vastutav üksus taotluse:

vähemalt kaks kuud enne senise vastavussertifikaadi kehtivuse lõppemist;

vähemalt viis tööpäeva enne senise ajutise kasutusloa kehtivuse lõppemist.

Kui uuesti akrediteerimise taotlus koos asjaomase dokumentatsiooniga on enne senise vastavussertifikaadi või ajutise kasutusloa kehtivuse lõppemist esitatud, võib Välisluureamet senise vastavussertifikaadi või ajutise kasutusloa kehtivust kuni akrediteerimise lõpuni pikendada.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 111. Re-accreditation of processing system

(1) For the re-accreditation of the processing system, the responsible entity submits an application:

1) at least two months prior to the expiry of the current certificate of compliance;

2) at least five working days prior to the expiry of the current temporary use permit.

(2) In case the application for re-accreditation together with the relevant documentation is submitted before the expiry of the current certificate of compliance or temporary use permit, the Foreign Intelligence Service may extend the validity of the current certificate of compliance or temporary use permit until the expiry of accreditation.

§ 112. Vastavussertifikaadi ja ajutise kasutusloa kehtetuks tunnistamine

Välisluureamet tunnistab vastavussertifikaadi või ajutise kasutusloa kehtetuks:

vastutava üksuse taotluse alusel;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

kui vastutav, haldav või kasutav üksus ei ole täitnud Välisluureameti ettekirjutust elektroonilise teabeturbe nõude rikkumise või rikkumise ohu kõrvaldamiseks;

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

ilmneb vastavussertifikaadi või ajutise kasutusloa andmisest keeldumise aluseks olev asjaolu.

Vastavussertifikaat või ajutine kasutusluba tunnistatakse kehtetuks Välisluureameti peadirektori käskkirjaga.

Vastavussertifikaadi või ajutise kasutusloa kehtetuks tunnistamine tehakse vastutavale üksusele teatavaks kirjalikult.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 112. Revocation of certificate of conformity and temporary use permit

(1) The Foreign Intelligence Service declares the certificate of compliance or temporary use permit invalid:

1) based on the request of the responsible entity;

2) in case the responsible, managing or using entity has failed to comply with the precept of the Foreign Intelligence Service to eliminate the violation or risk of violation of an electronic information security requirement;

3) a fact underlying the refusal to grant a certificate of compliance or a temporary use permit becomes evident.

(2) The certificate of compliance or the temporary use permit is declared invalid by the directive of the Director General of the Foreign Intelligence Service.

(3) A responsible entity is notified of the revocation of a certificate of compliance or a temporary permit for use in writing.

§ 112¹. Salvestuskandjate hoiustamine kehtiva vastavussertifikaadi või ajutise kasutusloa puudumisel

Kehtiva vastavussertifikaadi või ajutise kasutusloa puudumisel peavad töötlussüsteemiga seotud töötlevad üksused tagama töötlussüsteemi osaks olnud salvestuskandjate ja nendes sisalduva teabe nõuetekohase hoiustamise.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 112¹. Storage of storage media in absence of valid certificate of compliance or temporary use permit

In the absence of a valid certificate of compliance or a temporary use permit, the processing entities related to the processing system must ensure proper storage of the storage media that have been part of the processing system, and the information contained therein.

§ 113. Riigi julgeoleku volitatud esindaja teavitamine

Välisluureamet teavitab süsteemile vastavussertifikaadi või ajutise kasutusloa andmisest, vastavussertifikaadi kehtivuse pikendamisest või kehtetuks tunnistamisest riigi julgeoleku volitatud esindajat, kui süsteemis töödeldakse salastatud välisteavet.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 113. Notification of Estonian National Security Authority

The Foreign Intelligence Service notifies the Estonian National Security Authority of the issue of a certificate of compliance or a temporary use permit for the system, extending the validity of the certificate of compliance or revoking it in case foreign classified information is processed in the system.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 10. jagu Salastatud välisteabe kaitse › 1. jaotis Salastatud välisteabe töötlemine

§ 114. Salastatud välisteabe töötlemise põhimõtted

Salastatud välisteabe töötlemisele kohaldatakse välislepingust tulenevaid või rahvusvahelise organisatsiooni või rahvusvahelise kokkuleppega loodud institutsiooni salastatud teabe kaitse nõudeid, arvestades käesolevas jaos sätestatut. Käesolevas jaos sätestatud töötlemisnõudeid ei kohaldata Välisluureametis arvele võetud krüptomaterjalile ning «Riigisaladuse ja salastatud välisteabe seaduse» § 52 lõikes 3 nimetatud teabele.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 114. Principles of processing foreign classified information

The processing of foreign classified information is subject to the requirements for the protection of classified information arising from a international agreement or an agreement of an international organization or an institution established by an international agreement, taking into account the provisions of this section. The processing requirements set forth in this section do not apply to cryptographic material registered with the Foreign Intelligence Service and to the information specified in subsection 3 of § 52 of the State Secrets and Classified Information of Foreign States Act.

§ 115. Salastatud välisteabe arvestus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Salastatud välisteabe arvestust peetakse riigisaladuse arvestusest eraldi, nii et on tagatud registriandmetele ja teabekandjatele juurdepääsu piirang teadmisvajaduse ja juurdepääsuõiguse alusel. Registris tuleb arvestust pidada iga salastatud välisteabe avaldaja kohta eraldi.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 115. Keeping record of foreign classified information

The records of foreign classified information are kept separately from the records of state secrets, so the restriction of access to register data and media is guaranteed on the basis of the need-to-know and the right of access. In the register, records must be kept separately for each originator of foreign classified information.

§ 116. Riigi julgeoleku volitatud esindaja peetav salastatud välisteabe põhiregister

Riigi julgeoleku volitatud esindaja peab salastatud välisteabe põhiregistrit, kus registreeritakse kõik riigile edastatud või riigis loodud täiesti salajasel tasemel salastatud välisteabe ja erimärgistusega salastatud välisteabe kandjad.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlevad üksused, kes on riigi julgeoleku volitatud esindaja põhiregistri kasutajad, on kohustatud täitma §-s 51 sätestatud nõudeid.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 116. Main register of foreign classified information kept by Estonian National Security Authority

(1) The Estonian National Security Authority keeps the main register of foreign classified information, where all media of foreign classified information transmitted to the state or created in the state at the ‘top secret’ level and media of foreign classified information with special marking are registered.

(2) Processing entities that are users of the main register of the Estonian National Security Authority are obliged to comply with the requirements set forth in § 51.

§ 117. Töötleva üksuse peetav salastatud välisteabe register

Salastatud välisteavet valdav töötlev üksus on kohustatud sisse seadma salastatud välisteabe registri ja teavitama sellest eelnevalt kirjalikult riigi julgeoleku volitatud esindajat.

Täiesti salajasel tasemel salastatud välisteabe ja erimärgistusega salastatud välisteabe töötlemiseks ning registri ja selle allregistri pidamiseks peab töötlev üksus saama riigi julgeoleku volitatud esindajalt kirjaliku nõusoleku. Riigi julgeoleku volitatud esindaja väljastab nõusoleku pärast kontrolli, mille käigus tuvastatakse, kas töötlemisnõuded on täidetud.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 117. Register of foreign classified information kept by processing entity

(1) The processing entity in possession of foreign classified information is obliged to set up a register of foreign classified information and to notify in writing the Estonian National Security Authority in advance.

(2) In order to process foreign information classified at the ‘top secret’ level and foreign classified information with a special marking and to keep the register and its sub-register, the processing entity must obtain written consent from the Estonian National Security Authority. The Estonian National Security Authority issues the consent after an inspection during which it is established whether the processing requirements are in compliance.

§ 118. Salastatud välisteavet sisaldava teabekandja registreerimine

Salastatud välisteavet valdav töötlev üksus on kohustatud tema valduses olevad täiesti salajasel tasemel salastatud välisteavet ja erimärgistusega salastatud välisteavet sisaldavad teabekandjad registreerima lisaks töötleva üksuse registrile riigi julgeoleku volitatud esindaja poolt peetavas põhiregistris esimesel võimalusel, kuid mitte hiljem kui seitse tööpäeva pärast salastatud teabekandja loomist või töötlevasse üksusesse saabumist.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Töötlev üksus ei pea riigi julgeoleku volitatud esindaja poolt peetavas põhiregistris registreerima neid teabekandjaid, mille on talle edastanud riigi julgeoleku volitatud esindaja või töötlev üksus, kes on riigi julgeoleku volitatud esindaja põhiregistri kasutaja.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Salastatud välisteavet valdav töötlev üksus on kohustatud kandma riigi julgeoleku volitatud esindaja antud registreerimisnumbri igale täiesti salajasel tasemel salastatud välisteavet ja erimärgistusega salastatud välisteavet sisaldavale teabekandjale.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 118. Registration of media containing foreign classified information

(1) The processing entity in possession of foreign classified information is obliged to register media containing foreign information classified at a ‘top secret’ level and foreign classified information with special marking in their possession in addition to the register of the processing entity, in the main register kept by the Estonian National Security Authority at the earliest opportunity, but not later than seven working days after the creation of the classified medium, or its arrival at the processing entity.

(3) The processing entity does not need to register in the main register kept by the Estonian National Security Authority such media that have been transmitted thereto by the Estonian National Security Authority or the processing entity that is the user of the main register of the Estonian National Security Authority.

(4) The processing entity in possession of foreign classified information is obliged to put the registration number given by the Estonian National Security Authority on every medium containing foreign classified information at a ‘top secret’ level and foreign classified information with special marking.

§ 118¹. Salastatud välisteavet sisaldava teabekandja märgistamine

Salastatud välisteavet sisaldavale teabekandjale tehakse salastatud välisteabe avaldaja salastatuse taseme märge, kui see on välislepinguga ette nähtud, ja sellele vastava taseme riigisaladuse märge.

Kui teabekandja sisaldab nii riigisaladust kui ka salastatud välisteavet, mille salastatuse tase on riigisaladuse salastatuse tasemest madalam, ei tehta sellele lõikes 1 nimetatud märget.

Salastatud välisteavet sisaldavale teabekandjale tehakse lisamärge „Salastatud välisteave“ suurtähtedega ning märgitakse salastatud välisteabe avaldaja nimi, salastatuse tase ja salastamistähtaeg, kui välisteabe avaldaja on selle märkinud. Kui välisteabe avaldaja ei ole tähtaega märkinud, tehakse märge „tähtaeg: määramata“ või „tähtaeg: tähtajatu“. Sellisel juhul kehtib salastatus, kuni välisteabe avaldaja ei ole teatanud teisiti.

Kui teabekandja sisaldab mitme avaldaja salastatud välisteavet, tuleb lõikes 3 sätestatud lisamärkes märkida kõik salastatud välisteabe avaldajad, salastatuse tasemed ja salastamistähtajad.

Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni salastatud välisteavet sisaldava teabekandja võib jätta lõigetes 1–4 sätestatud nõuete kohaselt märgistamata.

Riigi julgeoleku volitatud esindaja kirjalikul nõusolekul võib elektroonilise salastatud välisteabe jätta lõigetes 1–4 sätestatud nõuete kohaselt märgistamata, kui teave on märgistatud §-s 70 sätestatud korras.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 118¹. Marking of medium containing foreign classified information

(1) A medium containing foreign classified information is marked with the level of classification of the originator of foreign classified information, in case it is prescribed by an international agreement, and with the marking of the corresponding level of state secret.

(2) In case the medium contains both state secrets and foreign classified information, the level of classification of which is lower than the level of classification of state secrets, it is not marked as specified in subsection 1.

(3) Mediums containing foreign classified information is additionally marked "Salastatud välisteave” [foreign classified information] in capital letters, and the name of the originator of foreign classified information, the level of classification and the term of classification are indicated, in case the originator of foreign information has noted this. In case the originator of foreign information has not specified the deadline, the marking “tähtaeg: määramata” [deadline: unspecified] or "tähtaeg: tähtajatu] [deadline: without time-limit] is made. In such case, the classification applies until the originator of foreign information has not announced otherwise.

(4) In case the medium contains foreign classified information of several originators, all the originators of the foreign classified information, the levels of classification and the terms of classification must be indicated in the additional note provided in subsection 3.

(5) Medium containing foreign classified information of the European Union and the North Atlantic Treaty Organization may be left unmarked in accordance with the requirements provided in subsections 1-4.

(6) With the written consent of the Estonian National Security Authority, electronic foreign classified information may be left unmarked in accordance with the requirements set forth in subsections 1-4, in case the information is marked in accordance with § 70.

§ 119. Salastatud välisteavet sisaldava teabekandja edastamine

Täiesti salajasel tasemel salastatud välisteavet ja erimärgistusega salastatud välisteavet sisaldav teabekandja võetakse vastu ning edastatakse teistele töötlevatele üksustele ainult riigi julgeoleku volitatud esindaja kaudu, kui selline nõue tuleneb välislepingust.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Утратил силу

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Salastatud välisteavet sisaldava teabekandja võib edastada ainult sellisele töötlevale üksusele, kes on eelnevalt sisse seadnud salastatud välisteabe registri.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 119. Transmission of medium containing foreign classified information

(1) A medium containing foreign information classified as ‘top secret’ and specially marked foreign classified information is received and transmitted to other processing entities only through the Estonian National Security Authority, in case such a requirement arises from an international agreement.

(3) A medium containing foreign classified information may be transmitted only to such a processing entity that has previously established a register of foreign classified information.

§ 120. Täiesti salajasel tasemel salastatud välisteavet ja erimärgistusega salastatud välisteavet sisaldava teabekandja reprodutseerimine ja hävitamine

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Täiesti salajasel tasemel salastatud välisteavet ja erimärgistusega salastatud välisteavet sisaldavat teabekandjat reprodutseerib ja hävitab ainult riigi julgeoleku volitatud esindaja.

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Riigi julgeoleku volitatud esindaja võib anda riigiasutusele kirjaliku loa lõikes 1 nimetatud teabekandja reprodutseerimiseks või hävitamiseks.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 120. Reproduction and destruction of medium containing ‘top secret’ foreign classified information and foreign classified information with special marking

(1) Only the Estonian National Security Authority reproduces and destroys a medium containing foreign information classified as ‘top secret’ and foreign classified information with special marking.

(2) The Estonian National Security Authority may give a written permission to the state authority to reproduce or destroy the medium specified in subsection 1.

§ 122. Riigi julgeoleku volitatud esindaja kontroll

Riigi julgeoleku volitatud esindaja viib vähemalt korra kahe aasta jooksul läbi salastatud välisteavet valdavas töötlevas üksuses salastatud välisteabe kaitse tagamiseks rakendatavate turvameetmete ja nimetatud teavet töötlevate füüsiliste isikute juurdepääsu kontrolli.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 122. Inspection by National Security Authority

At least once every two years, the National Security Authority carries out inspection in the processing entity holding foreign classified information of the security measures implemented to ensure the protection of foreign classified information and of the access of natural persons processing the specified information.

§ 122¹. Salastatud teabe töötlemist eeldavad lepingud

Tsiviilõiguslik leping, mille täitmine eeldab salastatud välisteabe töötlemist või riigisaladuse edastamist välisriigile, rahvusvahelisele organisatsioonile või rahvusvahelise kokkuleppega loodud institutsioonile, peab sisaldama osa, millega lepitakse kokku vähemalt selles, kelle loodud ning millisel tasemel salastatud teavet töödeldakse ning millised on juhised teabe kaitsmiseks, arvestades käesolevast määrusest ja välislepingutest tulenevaid nõudeid.

Lõikes 1 nimetatud lepingu osa kooskõlastatakse enne lepingu sõlmimist riigi julgeoleku volitatud esindajaga.

Ühe kuu jooksul lepingu sõlmimisest tuleb riigi julgeoleku volitatud esindajale esitada koopia selle lõikes 1 nimetatud osast, samuti lepingu poolte nimed, registrikoodid, asukohariigid ning lepingu kehtivusaeg.

Lõikeid 2 ja 3 ei kohaldata „Riigisaladuse ja salastatud välisteabe seaduse“ § 52 lõikes 3 sätestatud juhul.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 122¹. Contracts requiring processing of classified information

(1) A civil law contract, the performance of which requires the processing of foreign classified information or the transfer of a state secret to a foreign state, international organization or institution established by international agreement, must contain a part by which it is agreed at least on the processing of classified information, created by whom and at what level the classified information is processed and what are the instructions for protecting the information, taking account of the requirements arising from this Regulation and international agreements.

(2) The part of the contract specified in subsection 1 is coordinated with the National Security Authority prior to the entry into the contract.

(3) Within one month as of the entry into the contract, a copy of the part specified in subsection 1, as well as the names, registry codes, countries of location and the validity period of the contract must be submitted to the National Security Authority.

(4) Subsections 2 and 3 are not applied in the case provided in subsection 3 of § 52 of the State Secrets and Classified Information of Foreign States Act.

§ 122². Rahvusvahelise külastustaotluse kinnitamine

Rahvusvahelise külastustaotluse kinnitab riigi julgeoleku volitatud esindaja, välja arvatud „Riigisaladuse ja salastatud välisteabe seaduse“ § 52 lõikes 3 sätestatud juhul.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 122². Approval of international visit request

An international visit request is approved by the National Security Authority, except in the case provided in subsection 3 of § 52 of the State Secrets and Classified Information of Foreign States Act.

5. peatükk SALASTATUD TEABE JA SALASTATUD TEABEKANDJA TÖÖTLEMISE NÕUDED › 10. jagu Salastatud välisteabe kaitse › 2. jaotis Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni salastatud välisteabele juurdepääsu ja töötlemise õiguse andmise, sellest keeldumise, selle pikendamise ja kehtetuks tunnistamise kord

§ 123. Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni salastatud välisteabele juurdepääsu õigus ja selle töötlemise õigus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni piiratud tasemel salastatud välisteabele juurdepääsu õiguse saamise eeltingimus „Riigisaladuse ja salastatud välisteabe seaduse“ § 27 lõikes 1, 2 või 5 nimetatud isikul on §-s 130 nimetatud tutvustuse läbimine ja kohustuse allkirjastamine.

Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni konfidentsiaalsel ja kõrgemal tasemel salastatud välisteabele juurdepääsu õigus on füüsilisel isikul juurdepääsusertifikaadi alusel.

Euroopa Liidu ja Põhja-Atlandi Lepingu Organisatsiooni piiratud ja kõrgemal tasemel salastatud välisteabe töötlemise õigus on isikul töötlemiseks mõeldud juurdepääsusertifikaadi (edaspidi töötlemissertifikaat) alusel.

Juurdepääsusertifikaadi saamise eeltingimus on riigisaladusele juurdepääsu luba ning töötlemissertifikaadi saamise eeltingimus on riigisaladuse töötlemisluba.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 123. Right of access to foreign classified information of European Union and North Atlantic Treaty Organization and right to process it

(1) A prerequisite for the person specified in subsections 1, 2 or 5 of § 27 of the State Secrets and Classified Information of Foreign States Act for obtaining the right of access to foreign information classified as ‘restricted’ of the European Union and the North Atlantic Treaty Organization is that the person has to undergo the briefing specified in § 130 and sign the obligation.

(2) A natural person has the right of access to foreign information classified at the ‘confidential’ and higher level of the European Union and the North Atlantic Treaty Organisation on the basis of a Personnel Security Clearance Certificate.

(3) A person has the right to process foreign information of the European Union and the North Atlantic Treaty Organization classified at the ‘restricted’ and higher level on the basis of a security clearance certificate intended for processing (hereinafter Facility Security Clearance Certificate).

(4) A prerequisite for obtaining a Personnel Security Clearance Certificate is the national Personnel Security Clearance, and a prerequisite for obtaining a Facility Security Clearance Certificate is a national Facility Security Clearance.

§ 124. Juurdepääsusertifikaadi ja töötlemissertifikaadi tasemete vastavus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Isikule ei anta:

kõrgemal tasemel salastatud välisteabele juurdepääsu sertifikaati, kui on tema riigisaladusele juurdepääsu loa tase;

kõrgemal tasemel salastatud välisteabe töötlemissertifikaati, kui on tema riigisaladuse töötlemisloa tase.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 124. Correspondence between levels of Personnel Security Clearance Certificate and Facility Security Clearance Certificate

A person is not given:

1) a Personnel Security Clearance Certificate for access to foreign classified information at a higher level than the level of their national Personnel Security Clearance;

2) a Facility Security Clearance Certificate for processing foreign classified information at a higher level than the level of their national Facility Security Clearance.

§ 125. Juurdepääsusertifikaadi ja töötlemissertifikaadi kehtivus

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Juurdepääsu- või töötlemissertifikaadi kehtivusaja otsustab riigi julgeoleku volitatud esindaja vastavalt taotluses märgitud soovitavale kehtivusperioodile, juurdepääsuloa või töötlemisloa kehtivusele ja juurdepääsuvajaduse põhjendatusele. Kui välislepingust tulenevad juurdepääsuõiguse andmisest keeldumise alused on rangemad võrreldes „Riigisaladuse ja salastatud välisteabe seaduses“ sätestatud alustega, võetakse juurdepääsu- või töötlemissertifikaadi kehtivusaja otsustamisel arvesse ka välislepingust tuleneva asjaolu esinemist.

Juhul, kui isiku riigisaladusele juurdepääsu luba või töötlemisluba lõppeb enne juurdepääsu- või töötlemissertifikaadi kehtivusaja lõppu, kaotab juurdepääsu- või töötlemissertifikaat kehtivuse.

Kui juurdepääsu- või töötlemissertifikaat kaotab kehtivuse enne oma kehtivusaja lõppu, tuleb see tagastada riigi julgeoleku volitatud esindajale.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 125. Validity of Personnel Security Clearance Certificate and Facility Security Clearance Certificate

(1) The validity period of a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate is decided by the Estonian National Security Authority according to the desired period of validity specified in the application, the validity of the Personnel Security Clearance and the justification of the need-to know. In case the grounds for refusal of the right of access arising from an international agreement are stricter compared to the grounds provided in the "State Secrets and Classified Information of Foreign States Act", the existence of a circumstance arising from an international agreement is also taken into consideration upon deciding on the validity period of the Personnel Security Clearance Certificate or a Facility Security Clearance Certificate.

(2) In the event that a national Personnel Security Clearance or a national Facility Security Clearance of a person expires before the validity period of the Personnel Security Clearance Certificate or a Facility Security Clearance Certificate expires, the Personnel Security Clearance Certificate or a Facility Security Clearance Certificate loses its validity.

(3) In case a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate becomes invalid before the expiry of its validity period, it must be returned to the Estonian National Security Authority.

§ 126. Juurdepääsusertifikaadi taotlemine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Juurdepääsusertifikaadi taotlemiseks esitab riigiasutus, Eesti Pank või Kaitseliit, kelle ülesannete tõttu tekib isikul juurdepääsuvajadus, või selleks volitatud asutus (edaspidi taotleja) riigi julgeoleku volitatud esindajale:

kirjaliku taotluse, milles märgitakse salastatud välisteabe avaldaja ja salastatuse tase, millele juurdepääsu taotletakse, juurdepääsusertifikaadi taotletav kehtivusaeg, samuti isiku nimi, isikukood, sünnikoht, kodakondsus, kontaktandmed ja ametikoht;

isiku juurdepääsuloa või muu riigisaladusele juurdepääsu õigust kinnitava dokumendi või selle koopia, välja arvatud juhul, kui taotleja on julgeolekuasutus.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

„Riigisaladuse ja salastatud välisteabe seaduse“ § 30¹ lõikes 1 nimetatud isikule juurdepääsusertifikaadi taotlemiseks esitab Kaitsevägi riigi julgeoleku volitatud esindajale ametikohtade loetelu, milles on märgitud iga ametikoha kohta selleks nõutava salastatud välisteabele juurdepääsu õiguse tase.

Lõikes 2 nimetatud isikute juurdepääsusertifikaatide taotlemiseks esitab riigi julgeoleku volitatud esindajale riigiasutus, kelle põhiülesanne on koordineerida ja korraldada reservteenistusega seotud tegevusi ja arvestuse pidamist:

teabe sõjaväelise auastmega sõjaaja ametikohale isiku nimetamise kohta;

taotletava juurdepääsusertifikaadi kehtivusaja, samuti isiku nime, isikukoodi, sünnikoha, kodakondsuse ja kontaktandmed;

teabe isikule riigisaladusele juurdepääsu andmise õiguse andmise ja kehtivuse kohta.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 126. Application for Personnel Security Clearance Certificate

(1) In order to apply for a Personnel Security Clearance Certificate, a state authority, Eesti Pank or the Defence League, due to whose tasks the person needs access, or an authorised authority (hereinafter the applicant) submits to the Estonian National Security Authority:

1) a written application stating the originator of the foreign classified information and the level of classification to which access is applied for, the requested validity period for the Personnel Security Clearance Certificate, as well as the person's name, personal identification number, place of birth, citizenship, contact information and the post;

2) a copy of the national Personnel Security Clearance or other document confirming the right of access to state secrets, or their copy, unless the applicant is a security authority.

(2) In order to apply for a Personnel Security Clearance Certificate for the person specified in subsection 1 of § 30¹ of the State Secrets and Classified Information of Foreign States Act, the Defence Forces submit a list of posts to the Estonian National Security Authority, in which the level of access to foreign classified information required for each post is indicated.

(3) In order to apply for Personnel Security Clearance Certificates for the persons specified in subsection 2, the state authority, whose main task is to coordinate and organize activities and maintain the records related to reserve service, submits to the Estonian National Security Authority:

1) information on the appointment of a person with a military rank to a wartime post;

2) the validity period of the requested Personnel Security Clearance Certificate, as well as the person's name, personal identification number, place of birth, citizenship and contact information;

3) information on the granting of the right for access to a state secret to a person of and the validity thereof.

§ 128. Töötlemissertifikaadi taotlemine

Töötlemissertifikaadi taotlemiseks peab taotleja esitama riigi julgeoleku volitatud esindajale järgmised dokumendid:

taotleja kirjalik taotlus, milles nimetatakse salastatud välisteabe avaldaja ja välisteabe salastatuse tase, millele juurdepääsu taotletakse, ning põhjendatakse isiku salastatud välisteabele juurdepääsu vajadust;

töötlemisloa koopia;

salastatud teabe kaitse juhendi koopia;

koopia dokumendist, millega määratakse nimeliselt juriidilise isiku riigisaladuse kaitset korraldav isik, samuti nende isikute nimekiri, kes hakkavad salastatud välisteavet töötlema, ning vajaduse korral dokumendid neile füüsilise isiku juurdepääsusertifikaadi taotlemiseks.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 128. Application for Facility Security Clearance Certificate

In order to apply for a Facility Security Clearance Certificate, the applicant must submit the following documents to the Estonian National Security Authority:

1) a written application of the applicant, which specifies the name of the originator of foreign classified information and the level of classification of foreign information to which access is applied for, and justifies the need of a person to access foreign classified information;

2) a copy of the Facility Security Clearance;

3) a copy of the guide on the protection of classified information;

4) a copy of the document designating by name the person organizing the protection of state secrets in the legal person, as well as a list of persons who commence processing foreign classified information, and, where necessary, the documents to apply for a Personnel Security Clearance Certificate for natural persons.

§ 129. Juurdepääsusertifikaadi ja töötlemissertifikaadi andmise otsustamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Kui juurdepääsu- või töötlemissertifikaadi andmise taotlus või sellele lisatud dokumendid ei vasta nõuetele, annab riigi julgeoleku volitatud esindaja taotlejale kümne tööpäeva jooksul teada puudustest ja määrab tähtaja nende kõrvaldamiseks.

Juurdepääsu- või töötlemissertifikaadi andmise või sellest keeldumise otsustab riigi julgeoleku volitatud esindaja ühe kuu jooksul nõuetekohase taotluse saamisest. Põhjendatud vajaduse korral võib tähtaega pikendada, teavitades sellest taotlejat.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 129. Deciding on grant of Personnel Security Clearance Certificate and Facility Security Clearance Certificate

(1) In case the application for granting a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate or the documents attached thereto are not in compliance with the requirements, the Estonian National Security Authority notifies the applicant of the deficiencies within ten working days and sets a term for elimination of them.

(2) The Estonian National Security Authority decides on the issue or refusal to issue a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate within one month as of receiving a proper application. In the case of a justified need, the term may be extended, notifying the applicant thereof.

§ 129¹. Teenistusvälisele füüsilisele isikule Euroopa Liidu või Põhja-Atlandi Lepingu Organisatsiooni piiratud tasemel salastatud välisteabele juurdepääsu õiguse andmine

Teenistusvälisele füüsilisele isikule Euroopa Liidu või Põhja-Atlandi Lepingu Organisatsiooni piiratud tasemel salastatud välisteabele juurdepääsu õiguse andmise otsustab „Riigisaladuse ja salastatud välisteabe seaduse” § 27 lõike 5 punktides 1–3 nimetatud isik.

Lõikes 1 nimetamata juhtudel otsustab juurdepääsuõiguse andmise riigi julgeoleku volitatud esindaja.

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

Перевода этой нормы на английский нет.

§ 130. Salastatud välisteabe kaitse nõuete tutvustamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Enne esmakordset piiratud tasemel salastatud välisteabele juurdepääsu õiguse või juurdepääsusertifikaadi andmist ning vajaduse korral ka juurdepääsuõiguse või juurdepääsusertifikaadi korduval andmisel tutvustatakse isikule salastatud välisteabe kaitse aluseid. Tutvustuse korraldab:

juurdepääsusertifikaadi andmise korral riigi julgeoleku volitatud esindaja või volitatud asutus;

piiratud tasemel salastatud välisteabele juurdepääsu õiguse andmise korral riigiasutus, Eesti Pank või Kaitseliit, mille töö- või ametikohal isik töötab või mille juhi otsuse alusel on tal juurdepääsuõigus, muudel juhtudel riigi julgeoleku volitatud esindaja.

[RT I, 27.08.2025, 2 – вступ. в силу 01.09.2025]

Salastatud välisteabe kaitse alustega tutvumise järel kinnitab isik lisas 13 toodud vormil allkirjaga, et on teadlik salastatud välisteabe kaitse nõuetest, vastutusest nende rikkumise eest ja kohustusest hoida temale teatavaks saavat salastatud välisteavet.

Lõikes 1 nimetatud tutvustuse korraldaja säilitab lõikes 2 nimetatud kinnitust salastatud välisteabele juurdepääsu õiguse või juurdepääsusertifikaadi kehtivuse ajal ning vähemalt viis aastat pärast selle lõppemist.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Эстонский текст этой нормы изменился после переведённой редакции (01.01.2025): перевод не соответствует действующему тексту.

§ 130. Briefing on requirements for protection of foreign classified information

(1) Before the first granting of the right of access to foreign information classified at the ‘restricted’ level or issue of a Personnel Security Clearance Certificate, and, where necessary, also upon the repeated granting of the right of access or the Personnel Security Clearance Certificate, the person is briefed on the grounds for the protection of foreign classified information. The briefing is organized by:

1) in the case of the issue of a Personnel Security Clearance Certificate, the Estonian National Security Authority or an authorized body;

2) in the case of granting the right of access to foreign information classified at a ‘restricted’ level, the state authority, Eesti Pank or the Defence League, in whose place of employment or post the person is employed, or based on the decision of the head of which the person has the right of access.

(2) After being briefed on the grounds for the protection of foreign classified information, the person confirms by signing the form given in Annex 13 that they are aware of the requirements for the protection of foreign classified information, the liability for violation of them and the obligation to keep the foreign classified information that becomes known to the person.

(3) The organizer of the briefing specified in subsection 1 retains the confirmation specified in subsection 2 during the validity of the right of access to foreign classified information or the Personnel Security Clearance Certificate and for at least five years after its expiry.

§ 131. Juurdepääsusertifikaadi ja töötlemissertifikaadi edastamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Riigi julgeoleku volitatud esindaja edastab juurdepääsu- või töötlemissertifikaadi viie tööpäeva jooksul taotlejale.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 131. Delivery of Personnel Security Clearance Certificate and Facility Security Clearance Certificate

The Estonian National Security Authority delivers a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate to the applicant within five working days.

§ 132. Juurdepääsusertifikaadi ja töötlemissertifikaadi vormistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Juurdepääsu- või töötlemissertifikaadil peavad olema vähemalt järgmised andmed:

väljaandmise kuupäev ja number;

juurdepääsu- või töötlemissertifikaadi saanud füüsilise isiku ees- ja perekonnanimi, sünniaeg, isikukood, sünnikoht ja kodakondsus või juriidilise isiku nimi, aadress ja registrikood;

salastatud välisteabe kõrgeim tase ja erikategooriad, millele juurdepääsu või mille töötlemise õigus isikule antakse;

kehtivusaeg.

Juurdepääsusertifikaat ja töötlemissertifikaat vormistatakse inglise ja eesti keeles.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 132. Formalising of Personnel Security Clearance Certificate and Facility Security Clearance Certificate

(1) A Personnel Security Clearance Certificate or a Facility Security Clearance Certificate must contain at least the following data:

1) date and number of issue;

2) given name and surname, date of birth, personal identification code, place of birth and citizenship of a natural person who has received a Personnel Security Clearance Certificate or a Facility Security Clearance Certificate or the name, address and registry code of a legal person;

3) the highest level and special categories of foreign classified information to which the person is granted the right of access or processing;

4) period of validity.

(2) The Personnel Security Clearance Certificate and the Facility Security Clearance Certificate are issued in English and Estonian.

§ 134. Juurdepääsusertifikaadi ja töötlemissertifikaadi kehtetuks tunnistamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Juurdepääsu- või töötlemissertifikaat tunnistatakse kehtetuks:

isiku juurdepääsuvajaduse äralangemisel;

uue juurdepääsu- või töötlemissertifikaadi väljastamisel enne eelmise juurdepääsu- või töötlemissertifikaadi kehtivusaja lõppu;

juurdepääsu- või töötlemissertifikaadile kantud isikuandmete muutumisel;

kui väljastatud juurdepääsu- või töötlemissertifikaadi kehtivusajal ilmneb mõni selle väljastamist välistav asjaolu.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 134. Revocation of Personnel Security Clearance Certificate and Facility Security Certificate

A Personnel Security Clearance Certificate or a Facility Security Clearance Certificate is revoked:

1) in the case of a lapse in the need of a person for access;

2) upon the issue of a new Personnel Security Clearance Certificate or a Facility Security Clearance Certificate to a person before the expiry of the previous Personnel Security Clearance Certificate or Facility Security Clearance Certificate;

3) in case the personal information entered on the Personnel Security Clearance Certificate, or a Facility Security Clearance Certificate is modified;

4) in case during the period of validity of the Personnel Security Clearance Certificate or Facility Security Clearance Certificate issued, any circumstance excluding the issue thereof becomes evident.

§ 135. Juurdepääsu- ja töötlemissertifikaadi andmise aluseks olnud andmete muutmisest teavitamine

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Taotleja teavitab viivitamata riigi julgeoleku volitatud esindajat juurdepääsuõiguse saanud isiku salastatud välisteabele juurdepääsu vajaduse või riigisaladusele juurdepääsu loa või õiguse või töötlemisloa lõppemisest ning § 134 punktides 3 ja 4 nimetatud sündmusest.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 135. Notification of amendment of data based on which Personnel Security Clearance Certificateand Facility Security ClearanceCertificate were issued

An applicant immediately informs the Estonian National Security Authority of the lapse in the need for access to foreign classified information, or of a national Personnel Security Clearance or right, or a national Facility Security Clearance of the person who has the right of access, and of the event specified in clauses 3 and 4 of § 134.

6. peatükk NÕUSOLEKU, KINNITUSE, JUURDEPÄÄSULOA JA TÖÖTLEMISLOA NING NENDE KEHTIVUSE PIKENDAMISE TAOTLUSE, JUURDEPÄÄSULOA JA TÖÖTLEMISLOA TAOTLEJA JA PIKENDAJA ANKEEDI VORMIDE KEHTESTAMINE

§ 137. Riigisaladusele juurdepääsu loa vormid

Füüsiline isik esitab riigisaladusele juurdepääsu loa (edaspidi juurdepääsuluba) lisas 1 toodud taotluse vormil.

Füüsiline isik esitab juurdepääsuloa kehtivuse pikendamise lisas 2 toodud taotluse vormil.

Füüsiline isik täidab juurdepääsuloa taotlemisel või juurdepääsuloa kehtivuse pikendamise taotlemisel juurdepääsuloa taotleja ja pikendaja ankeedi (lisa 3).

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Утратил силу

[RT I, 26.10.2016, 2 – вступ. в силу 29.10.2016]

Füüsiline isik täidab juurdepääsuloa ja selle kehtivuse pikendamise taotlemisel ankeedi lisana nõusoleku vormi (lisa 5).

Füüsiline isik kinnitab juurdepääsuloa ja selle kehtivuse pikendamise taotlemisel, et ta on teadlik riigisaladuse kaitse nõuetest, vastutusest nende rikkumise eest ja kohustusest hoida temale teatavaks saavat riigisaladust (lisa 6).

Üksnes piiratud taseme riigisaladusele juurdepääsu õigust taotlev või omav isik täidab lõikes 5 nimetatud nõusoleku vormi ja annab lõikes 6 nimetatud kinnituse.

[RT I, 14.01.2011, 6 – вступ. в силу 17.01.2011]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 137. Forms related to national Personnel Security Clearance

(1) A natural person submits an application for a Personnel Security Clearance using the form of application specified in Annex 1.

(2) A natural person submits an application for the extension of a Personnel Security Clearance using the form specified in Annex 2.

(3) Upon application for a Personnel Security Clearance or for the extension of the period of validity thereof, a natural person fills out the form of an applicant for and extender of Personnel Security Clearance (Annex 3).

(5) Upon application for a Personnel Security Clearance or extension of the period of validity thereof, a natural person fills out the consent form (Annex 5) annexed to the application form.

(6) Upon application for a Personnel Security Clearance or extension thereof, a natural person confirms that they are aware of the requirements for the protection of state secrets, the liability for violation of such requirements and the obligation to maintain the state secrets that have become known thereto (Annex 6).

(7) A person who is applying for or holding the right of access only to state secrets classified as ‘restricted’ fills out the form of consent specified in subsection 5 and gives the confirmation specified in subsection 6.

§ 138. Riigisaladuse töötlemisloa vormid

Juriidiline isik esitab riigisaladuse töötlemisloa (edaspidi töötlemisluba) taotluse lisas 7 toodud vormil.

Juriidiline isik esitab töötlemisloa kehtivuse pikendamise taotluse lisas 8 toodud vormil.

Juriidiline isik esitab töötlemisloa taotlemisel või töötlemisloa kehtivuse pikendamise taotlemisel töötlemisloa taotleja ja pikendaja ankeedi (lisa 9).

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

Утратил силу

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

Juriidiline isik täidab töötlemisloa ja selle kehtivuse pikendamise taotlemisel ankeedi lisana nõusoleku vormi (lisa 11).

Juriidiline isik kinnitab töötlemisloa ja selle kehtivuse pikendamise taotlemisel, et ta on teadlik riigisaladuse kaitse nõuetest, vastutusest nende rikkumise eest ja kohustusest hoida temale teatavaks saavat riigisaladust (lisa 12).

Lõikeid 1–3, 5 ja 6 kohaldatakse ka füüsilisest isikust ettevõtjale.

[RT I, 06.03.2019, 7 – вступ. в силу 09.03.2019]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 138. Forms related to national Facility Security Clearance

(1) A legal person submits an application for a permit to process state secrets (hereinafter Facility Security Clearance) using the form specified in Annex 7.

(2) A legal person submits an application for the extension of a Facility Security Clearance using the form specified in Annex 8.

(3) Upon application for the issue of a Facility Security Clearance or for the extension of the period of validity thereof, a legal person submits the form of the applicant for or extender of Facility Security Clearance (Annex 9).

(5) Upon application for a Facility Security Clearance or extension of the period pf validity thereof, a legal person fills outs the consent form (Annex 11) annexed to the application form.

(6) Upon application for a Facility Security Clearance or for the extension of the period of validity thereof, a legal person confirms awareness of the requirements for the protection of state secrets, liability for violation of such requirements and obligation to maintain the state secrets that have become known thereto (Annex 12).

(7) Subsections 1–3, 5 and 6 are also applied to a self-employed person.

7. peatükk MÄÄRUSE RAKENDAMINE

§ 138¹. Määruse rakendamine

Enne 5. juunit 2023. a käesoleva määruse § 6 lõike 1 punkti 2 alusel salastatud teave jääb riigisaladuseks vastavalt salastamise ajal kehtinud nõuetele.

Enne 5. juunit 2023. a kehtestatud riigisaladuse kaitse juhend viiakse käesoleva määruse nõuetega kooskõlla hiljemalt 1. oktoobriks 2023. a.

Alates 5. juunist 2023. a kehtivaid nõudeid registrisse kantavale teabele kohaldatakse teabekandjale, mis registreeritakse alates 5. juunist 2023. a.

Arhiivihoidlas olev teabekandja viiakse kooskõlla 5. juunist 2023. a kehtivate märgistamise nõuetega teabekandja töötlemisel, välja arvatud vahetult hoidmise ja säilitamisega seotud toimingud, kuid hiljemalt 1. juuniks 2028. a.

Enne 5. juunit 2023. a töötlussüsteemile antud vastavussertifikaat või ajutine kasutusluba kehtib selle kehtivuse tähtaja lõpuni.

Enne 5. juunit 2023. a füüsilisele isikule või töötlemisloa alusel salastatud teavet töötlevale isikule antud juurdepääsusertifikaat kehtib selle kehtivusaja lõpuni.

Töötlussüsteemi turbejuhend ja töötlussüsteemi kasutusjuhend tuleb viia §-des 107 ja 108 sätestatuga kooskõlla hiljemalt järgmise akrediteerimiseks ajaks.

Enne 5. juunit 2023. a soetatud salastatud teabekandja hävitamise seadet, mis ei vasta käesoleva määruse § 83 nõuetele, võib kasutada järgmiselt:

paberipurustajat kuni 30. aprillini 2026. a;

Välisluureametiga kooskõlastatud salvestuskandja hävitamise seadet selle elutsükli lõpuni.

[RT I, 31.05.2023, 3 – вступ. в силу 05.06.2023]

Vastutava üksuse infoturbejuhi ülesandeid täitev isik peab vastama § 23 lõikes 3 sätestatud nõudele hiljemalt 1. jaanuaril 2025. a.

[RT I, 29.12.2023, 8 – вступ. в силу 01.01.2024]

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 138¹. Implementation of Regulation

(1) Information classified before 5 June 2023 on the basis of clause 2 of subsection 1 of § 6 of this Regulation remains a state secret in accordance with the requirements in force at the time of classification.

(2) The guide for the protection of state secrets established before 5 June 2023 is brought into compliance with the requirements of this Regulation at the latest by 1 October 2023.

(3) The requirements for information to be entered in the register valid from 5 June 2023, are applied to a medium that is registered as of 5 June 2023.

(4) The medium in the archive storage is brought into compliance with the marking requirements valid as of 5 June 2023 upon processing the medium, except for actions directly related to storage and preservation, but at the latest by 1 June 2028.

(5) The certificate of compliance or temporary use permit issued to the processing system before 5 June 2023 is valid until the end of its validity period.

(6) A Personnel Clearance Certificate issued to a natural person or a person processing classified information on the basis of a Facility Security Clearance before 5 June 2023 is valid until the expiry of its period of validity.

(7) The security guide and the user guide for the processing system must be brought into compliance with the provisions of §§ 107 and 108 at the latest by the time of the next accreditation.

(8) Equipment for the destruction of classified media acquired before 5 June 2023, which is not in compliance with the requirements of § 83 of this Regulation, may be used as follows:

1) paper shredder until 30 April 2026;

2) A device for destruction of the storage medium coordinated with the Foreign Intelligence Service until the end of its life cycle.

(9) The person performing the duties of the information security manager of the responsible entity must meet the requirement provided in subsection 3 of § 23 at the latest on 1 January 2025.

§ 139. Määruse jõustumine

Määrus jõustub 1. jaanuaril 2008. a.

Paragrahvi 8 lõike 1 punktid 4, 5, 7, 8 ja 11 jõustuvad 1. jaanuaril 2009. a, välja arvatud teabe osas, mis oli riigisaladuseks enne 1. jaanuari 2008. a.

Paragrahvi 70 lõige 1 jõustub 1. jaanuaril 2009. a.

Перевод редакции 01.01.2025; эстонский текст нормы с тех пор не менялся.

§ 139. Entry into force of Regulation

(1) This Regulation enters into force on 1 January 2008.

(2) Clauses 4, 5, 7, 8 and 11 of subsection 1 of § 8 enter into force on 1 January 2009, except in respect of information which was a state secret before 1 January 2008.

(3) Subsection 1 of § 70 enters into force on 1 January 2009.