Rahapesu Andmebüroo andmekogu põhimäärus
in forcefrom 30.05.2024· RT I, 25.05.2024, 14· Rahandusminister
Official English translation: Statutes of Database of Financial Intelligence Unit · RT V, 29.03.2022, 2
The official English translation is published in Riigi Teataja for information. Only the Estonian text has legal force.
The translation is of the version in force from 01.01.2021, not of the current one. Provisions whose Estonian text has changed since are marked. The Estonian text prevails.
Translation in Riigi Teataja ↗Contents
Click the dot before a section, subsection or point: exact citation, link, explanation, wording history, case law and notes.
1. peatükk Üldsätted
§ 1. Andmekogu asutamine ja nimetus
Määrusega kehtestatakse Rahapesu Andmebüroo andmekogu (edaspidi andmekogu) põhimäärus. Andmekogu ametlik lühend on RABIS.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 1. Establishment and name of database
This Regulation establishes the statutes of the database of the Financial Intelligence Unit (hereinafter database). The official abbreviation of the database is RABIS.
§ 2. Andmete töötlemine
Andmekogus töödeldakse Rahapesu Andmebüroo ülesannetest tulenevate toimingute ja menetlustega seotud andmeid.
Andmekogu andmeid kasutatakse rahapesu ja terrorismi rahastamise tõkestamise seaduse §-s 54 sätestatud Rahapesu Andmebüroo ülesannete täitmiseks.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 2. Processing of data
(1) The data related to the operations and proceedings deriving from the duties of the Financial Intelligence Unit are processed in the database.
(2) The data of the database are used for performance of the duties of the Financial Intelligence Unit provided in § 54 of the Money Laundering and Terrorist Financing Prevention Act.
§ 3. Andmekogu pidamise viis
Andmekogu peetakse infotehnoloogilise andmekoguna, mille koosseisu kuulub analüütikarakendus (edaspidi andmeladu), ja paberil toimikutena (edaspidi toimik).
Andmekogu on liidestatud infosüsteemide andmevahetuskihiga X-tee ja see kuulub riigi infosüsteemi koosseisu. Andmete andmekogusse kandmisel esitatakse päringuid sellega liidestatud andmekogu vastutavale töötlejale ja saadakse andmeid sellega liidestatud andmekogust.
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 3. Manner of maintaining database
The database is maintained as an information technology database and as files on paper (hereinafter file).
§ 4. Toimik
Toimik koosneb käesoleva määruse §-s 20 nimetatud dokumentidest ja teistest menetluse käigus kogutud ning toimingute aluseks olevatest dokumentidest ja tõenditest.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 4. File
A file consists of the documents specified in § 20 of this Regulation and of other documents and evidence collected in the course of proceedings and serving as grounds for operations.
§ 5. Andmekogus töödeldavate andmete kaitse
Andmekogus töödeldavate andmete käideldavuse, tervikluse ja konfidentsiaalsuse tagamiseks rakendatakse vastavaid organisatsioonilisi, füüsilisi ja infotehnoloogilisi turvameetmeid.
Andmekogus töödeldavate andmete turvaklass on K2T2S3. Andmekogus töödeldavate andmete turbeaste on kõrge (H).
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 5. Protection of data processed in database
(1) Relevant organisational, physical and information technology security measures are applied in order to ensure the availability, integrity and confidentiality of the data processed in the database.
(2) The security class of the data processed in the database is K2T2S3. The security level of the data processed in the database is high (H).
§ 6. Andmekogu vastutav ja volitatud töötleja
Andmekogu vastutav töötleja on Rahapesu Andmebüroo (edaspidi vastutav töötleja).
Andmekogu volitatud töötlejad on Siseministeeriumi infotehnoloogia- ja arenduskeskus ja Rahandusministeeriumi Infotehnoloogiakeskus (edaspidi volitatud töötleja).
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 6. Controller and processor of database
(1) The Financial Intelligence Unit is the controller of the database (hereinafter controller).
(2) The IT and Development Centre of the Ministry of the Interior is the processor of the database (hereinafter processor).
§ 7. Vastutava ja volitatud töötleja ülesanded
Vastutav töötleja:
vastutab andmekogu toimingute õiguspärasuse eest;
tagab andmekogu pidamise õigusaktides sätestatud nõuetele vastavalt;
tagab õigustatud isikutele juurdepääsu andmekogule;
tagab koos volitatud töötlejaga organisatsiooniliste ja tehniliste meetmete abil andmekogu andmete tervikluse, andmekogu andmete kaitse ja säilimise;
vastutab isikuandmete töötlemise nõuete täitmise eest;
vastutab andmekogu andmete nõuetekohase väljastamise eest;
korraldab koos volitatud töötlejaga andmekogu arendamist.
Siseministeeriumi infotehnoloogia- ja arenduskeskus volitatud töötlejana:
arendab andmekogu vastavalt vastutavalt töötlejalt saadud ettepanekutele;
tagab andmekogu majutamiseks vajaliku infotehnoloogilise keskkonna ja selle tehnilise valmisoleku teenusleppes kokku lepitud ulatuses ja korras.
Rahandusministeeriumi Infotehnoloogiakeskus volitatud töötlejana tagab andmelao majutamiseks vajaliku infotehnoloogilise keskkonna ja selle tehnilise valmisoleku teenusleppes kokku lepitud ulatuses ja korras.
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 7. Duties of controller and processor
(1) The controller:
1) is responsible for the lawfulness of the operations of the database;
2) ensures that the database is maintained in compliance with the requirements provided by legislation;
3) ensures access of entitled persons to the database;
4) ensures the integrity of the data, and protection and preservation of the data in the database together with the processor by means of organisational and technical measures;
5) is responsible for compliance with the requirements for processing of personal data;
6) is responsible for issue of data from the database in compliance with the requirements;
7) organises the development of the database together with the processor.
(2) The processor:
1) develops the database in accordance with the proposals received from the controller;
2) ensures the informational technology environment necessary for hosting the database and its technical readiness in the extent and in accordance with the procedures agreed upon in a service agreement.
2. peatükk Andmekogusse kantavad andmed
§ 8. Andmekogusse kantavad andmed
Andmekogusse kantakse järgmised andmed:
teate koostaja andmed;
teataja andmed;
teate andmed;
tehingu osapoolte andmed;
tehingu andmed;
selle isiku andmed, kelle kohta teade esitati;
volituse andmed;
dokumendid.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 8. Data entered in database
The following data are entered in the database:
1) data on the person preparing the report;
2) data on the reporter;
3) data on the report;
4) data on the parties to the transaction;
5) data on the transaction;
6) data on the person with regard to whom the report has been submitted;
7) data on authorisation;
8) documents.
§ 9. Teate koostaja andmed
Teate koostaja kohta kantakse andmekogusse järgmised andmed:
ees- ja perekonnanimi;
isikukood;
sidevahendi andmed (sidevahendi tüüp, veebilehe andmed, telefoninumber, e-posti aadress).
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 9. Data on person preparing report
The following data on the person preparing a report are entered in the database:
1) given name and surname;
2) personal identification code;
3) details of telecommunications (type of telecommunications, data of the website, telephone number, e-mail address).
§ 10. Teataja andmed
Teataja kohta kantakse andmekogusse järgmised andmed:
teataja isiku tüüp;
nimi;
registrikood;
kohustatud isiku liik;
põhitegevusala;
teatega seotud tegevusala;
kontaktandmed, sealhulgas kontaktaadress Eestis, mitteresidendi puhul tegevuskoht, päritoluriik, maksuresidentsus (riik) või mitteresidendist osanikuga residendi puhul omanikfirma andmed;
teave selle kohta, kas teate esitaja on tehingu üks osapooltest.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 10. Data on reporter
The following data on the reporter are entered in the database:
1) type of the entity of the reporter;
2) name;
3) registry code;
4) type of the obliged entity;
5) principal activity;
6) activity related to the report;
7) contact details, including the contact address in Estonia; in case of a non-resident, their place of business, country of origin, tax residency (country), or in case of a resident with a non-resident shareholder, the data on the owner company;
8) information on whether the person submitting the report is a party to the transaction.
§ 11. Teate andmed
Teate kohta kantakse andmekogusse järgmised andmed:
teate liik;
teate number, kui see on olemas;
põhiajend;
lisaajendid;
märge „Kiire“, kui see on teatele lisatud, ja selle põhjendus;
teataja saadetud viimase teate number koos kuupäevaga;
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 11. Data on report
The following data on the report are entered in the database:
1) type of the report;
2) number of the report if any;
3) main indication;
4) additional indications;
5) notation “Kiire” [“Urgent”] if it is added to the report and reasons therefor;
6) number of the latest report sent by the reporter, including the date;
§ 12. Tehingu osapoolte andmed
Tehingu osapoolte kohta kantakse andmekogusse järgmised andmed:
isiku tüüp;
isiku nimi või ees- ja perekonnanimi;
isiku registri- või isikukood;
isikut tõendava dokumendi andmed (dokumendi number, liik, väljaandmise kuupäev, dokumendi välja andnud riigi nimi);
isiku roll;
asutamise aeg;
lõpetamise aeg;
kontaktandmed, sealhulgas kontaktaadress Eestis, mitteresidendi puhul tegevuskoht, päritoluriik, maksuresidentsus (riik) või mitteresidendist osanikuga residendi puhul omanikfirma andmed;
sidevahendi andmed (sidevahendi tüüp, veebilehe andmed, telefoninumber, e-posti aadress);
pangakonto andmed (kontonumber, pank, panga asukoht).
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 12. Data on parties to transaction
The following data on the parties to the transaction are entered in the database:
1) type of the person;
2) name or given name and surname of the person;
3) registry code or personal identification code of the person;
4) data on the identification document (number, type, date of issue of the document, name of the country and authority which has issued the document);
5) role of the person;
6) date of foundation;
7) date of dissolution;
8) contact details, including the contact address in Estonia; in case of a non-resident, their place of business, country of origin, tax residency (country), or in case of a resident with a non-resident shareholder, the data on the owner company;
9) details of telecommunications (type of telecommunications, data of the website, telephone number, e-mail address);
10) bank account details (account number, bank, registered office of the bank).
§ 13. Tehingu andmed
Tehingu kohta kantakse andmekogusse järgmised andmed:
tehingu liik;
tehingu objekt;
tehingu alamliik;
tehingu kirjeldus;
tehingu summa ja valuuta;
tehingu eest tasumise viis;
tehingu tegijate (maksja ja makse saaja andmed) andmed;
maksja ja makse saaja pangakonto andmed (kontonumber, pank, panga asukoht);
teave selle koha, kas küsiti teavet vara päritolu kohta;
teave vara kohta (kirjeldus, väärtus, väärtuse hindamise kuupäev, asukohariik);
teave vara päritolu kohta;
teave selle kohta, kas tuli tagastusnõue;
teave tagastusnõude kohta (kuupäev, number, sisu, tagastusnõude SWIFT-kirje koopia, konto omanik, kontonumber).
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 13. Data on transaction
The following data on the transaction are entered in the database:
1) type of the transaction;
2) object of the transaction;
3) subtype of the transaction;
4) description of the transaction;
5) amount and currency of the transaction;
6) manner of payment for the transaction;
7) data on the persons making the transaction (data on the payer and beneficiary);
8) details of the bank account of the payer and beneficiary (account number, bank, registered office of the bank);
9) information on whether information on the origin of the assets was requested;
10) information on the assets (description, value, date of assessment of the value, country of location);
11) information on the origin of the assets;
12) information on whether a claim for refund was received;
13) information on the claim for refund (date, number, contents, copy of the SWIFT-item of the claim for refund, account owner, account number).
§ 14. Isiku andmed, kelle kohta teade esitati
Füüsilise isiku kohta, kelle kohta teade esitati, kantakse andmekogusse järgmised andmed:
ees- ja perekonnanimi;
isikukood ja sünniaeg;
sugu;
sünnikoht riigi täpsusega;
kodakondsus;
elukohariik;
isikut tõendava dokumendi andmed (dokumendi number, liik, väljaandmise kuupäev, dokumendi välja andnud riigi nimi);
andmed isiku karistuse kohta (karistuse liik ja kestus, karistuse määramise kuupäev, karistuse täitmisele pööramise ja täitmise lõppemise kuupäev, otsuse tegija, kriminaalasja number, kohtuasja number);
kontaktandmed, sealhulgas kontaktaadress, e-posti aadress ja telefoninumber.
Juriidilise isiku kohta, kelle kohta teade esitati, kantakse andmekogusse järgmised andmed:
nimi;
registrikood;
registreerimise andmed;
põhitegevusala;
kontaktandmed, sealhulgas kontaktaadress, e-posti aadress, telefoninumber, veebilehe aadress;
tegeliku tegutsemiskoha andmed, sealhulgas aadress;
pangakonto asukoht ja panga nimi;
tegelik kasusaaja;
esindusõigusliku isiku ees- ja perekonnanimi ning isikukood ja sünniaeg;
andmed karistuse kohta (karistuse liik ja kestus, karistuse määramise kuupäev, karistuse täitmisele pööramise ja täitmise lõppemise kuupäev, otsuse tegija, kriminaalasja number, kohtuasja number).
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 14. Data on person with regard to whom report has been submitted
(1) The following data on a natural person with regard to whom the report has been submitted are entered in the database:
1) given name and surname;
2) personal identification code and date of birth;
3) place of birth, specifying the country;
4) citizenship;
5) country of residence;
6) data of the identification document (number, type, date of issue of the document, name of the country and authority which has issued the document);
7) data on the sanctions imposed on the person (type and duration of the sanction, date of imposing the sanction, date of authorising the enforcement of the sanction and end date of enforcement, person who made the decision, criminal case number, court case number);
8) contact details, including contact address, e-mail address and telephone number.
(2) The following data on a legal person with regard to whom the report has been submitted are entered in the database:
1) name;
2) registry code;
3) data on registration;
4) principal activity;
5) contact details, including contact address, e-mail address, telephone number, website address;
6) data on the place of business, including address;
7) location of the bank account and name of the bank;
8) personal data of the executive officer (for example, manager, director) (given name and surname, personal identification code, date of birth);
9) data on the sanctions imposed on the person (type and duration of the sanction, date of imposing the sanction, date of authorising the enforcement of the sanction and end date of enforcement, person who made the decision, criminal case number, court case number).
§ 15. Volitaja ja volituse andmed
Volitaja ja volituse kohta kantakse andmekogusse järgmised andmed:
volitatud isiku liik;
volitaja tüüp;
volitaja ees- ja perekonnanimi;
volitaja isikukood ja sünniaeg;
volitaja sünnikoht riigi täpsusega;
volitaja kodakondsus;
volitaja elukohariik;
volitaja kontaktandmed, sealhulgas kontaktaadress, e-posti aadress ja telefoninumber;
volitamise vorm;
volituse väljaandmise kuupäev;
volituse kehtivuse lõpukuupäev;
volituse väljastanud riik;
volituse sisu.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 15. Data on principal and authorisation
The following data on the principal and authorisation are entered in the database:
1) type of the authorised person;
2) type of the principal;
3) given name and surname of the principal;
4) personal identification code and date of birth of the principal;
5) place of birth of the principal, specifying the country;
6) nationality of the principal;
7) country of residence of the principal;
8) contact details of the principal, including the contact address, e-mail address and telephone number;
9) form of authorisation;
10) date of issue of the authorisation;
11) date of expiry of the authorisation;
12) country of issue of the authorisation;
13) contents of the authorisation.
§ 16. Andmekogusse kantavad dokumendid
Andmekogusse kantakse teatega kaasas olevad dokumendid, sealhulgas:
kontode avamise dokumendid ja kontoväljavõtted ajavahemiku kohta, kui kahtlased tehingud on tehtud või kui rahvusvahelise finantssanktsiooni subjekt oli krediidiasutuse klient;
identifitseeritud mitteresidendist füüsilise isiku isikut tõendava dokumendi isikuandmete ja fotoga lehekülje koopia;
identifitseeritud mitteresidendist juriidilise isiku registreerimistunnistuse või sellega võrdväärse dokumendi koopia;
tehingus osaleva volitatud isiku esindusõigust tõendava dokumendi koopia;
tehingu aluseks oleva kirjaliku leppe või korralduse ja nende lisade koopia;
muud tehingut iseloomustavad dokumendid.
Andmekogusse kantakse muud rahapesu või sellega seotud kuritegude ja terrorismi rahastamise tõkestamise, tuvastamise ja kohtueelse uurimise käigus kogutud või koostatud dokumendid.
Andmekogusse kantakse teave dokumendi liigi ja dokumendi kuupäeva kohta ning vajaduse korral dokumendi sisukirjeldus.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 16. Documents entered in database
(1) The documents accompanying the report are entered in the database, including:
1) documents on opening of accounts and account extracts regarding the period during which suspicious transactions were made, or during which the subject of international sanctions was a client of the credit institution;
2) copy of the page with the personal data and photo of the identification document of the identified non-resident natural person;
3) copy of the registration certificate or equivalent document of the identified non-resident legal person;
4) copy of the document certifying the right of representation of the authorised person participating in the transaction;
5) copy of the written agreement or order constituting the grounds for the transaction, and of any annexes thereto;
6) other documents characterising the transaction.
(2) Other documents collected or prepared in the course of countering, identifying or pre-trial investigation of money laundering, related criminal offences and terrorist financing are entered in the database.
(3) Information on the type and date of the documents, and where necessary, also a description of the contents of the documents are entered in the database.
§ 17. Muud andmekogusse kantavad andmed
Lisaks §-des 8–16 nimetatud andmetele kantakse andmekogusse:
andmekogu vastutava töötleja analüüsi tulemusena saadud teave tehingute, nendes osalejate ja tehingutega seotud teiste asjaolude kohta;
muul viisil teatavaks saanud teave kahtlaste ja ebaharilike tehingute ja toimingute ning tehingute ja toimingute osapoolte kohta;
rahapesu ja terrorismi rahastamise tõkestamise seaduse 7. ja 8. peatükis ning rahvusvahelise sanktsiooni seaduse 5. peatükis sätestatud järelevalve tegemise käigus kogutud andmed;
Rahapesu Andmebüroole esitatavate rahvusvaheliste sanktsioonide rakendamise teadete andmed;
Rahapesu Andmebüroole esitatavates aruannetes sisalduvad andmed ning Rahapesu Andmebüroole õigusaktide ja ettekirjutuste alusel esitatavad andmed;
rahapesu ja terrorismi rahastamise tõkestamiseks ning sellele viitava teabe vastuvõtmiseks, kogumiseks, väljanõudmiseks, registreerimiseks, töötlemiseks, analüüsimiseks ning edastamiseks tehingute ja toimingute osapoolte rahvastikuregistri andmed, karistusregistri andmed, e-toimiku süsteemi andmed, äriregistri andmed, maksukohustuslaste registri andmed, elektroonilise arestimissüsteemi andmed, kinnistusraamatu andmed, liiklusregistri andmed, tegelike kasusaajate andmekogu andmed, Eesti väärtpaberite keskregistri andmed ja infosüsteemi POLIS andmed;
rahapesu ja terrorismi rahastamisele ning finantssanktsiooni rikkumisele viitavad üldsusele suunatud ja avalikest allikatest kättesaadavad andmed.
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 17. Other data entered in database
In addition to the data specified in §§ 8–16, the following data are entered in the database:
1) information on the transactions, parties thereto and other circumstances related to transactions obtained as a result of the analysis of the controller of the database;
2) information on suspicious and unusual transactions and operations which has become known in any other manner;
3) data collected in the course of the supervision provided in Chapters 7 and 8 of the Money Laundering and Terrorist Financing Prevention Act;
4) data on the notices of implementation of financial sanctions.
3. peatükk Andmete kandmine andmekogusse
§ 18. Andmeandjad
Andmekogusse esitavad andmeid rahapesu ja terrorismi rahastamise tõkestamise seaduse §‑s 2 sätestatud isikud (edaspidi kohustatud isik), rahvusvahelise sanktsiooni seaduses sätestatud isikud, kellel tekib kohustus sanktsiooni rakendada, isik, kes esitab teabe kahtlase ja ebahariliku tehingu või toimingu kohta, ning andmekogu vastutav töötleja.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 18. Data media
Data are submitted to the database by the persons provided in § 2 of the Money Laundering and Terrorist Financing Prevention Act (hereinafter obliged entities), the persons obliged to implement a sanction as provided in the International Sanctions Act, persons submitting information on suspicious and unusual transactions or operations, and the controller of the database.
§ 19. Andmekogudevaheline andmevahetus
Andmekogu vastutaval töötlejal on lubatud seadusega või seaduse alusel kehtestatud õigusaktiga talle pandud ülesannete täitmiseks esitada päringuid teistesse riigi või kohaliku omavalitsuse andmekogudesse ja sealt saada andmeid. Andmevahetus andmekogudega toimub infosüsteemide andmevahetuskihi kaudu.
Andmekogu vastutav töötleja töötleb järgmisi andmeid:
rahvastikuregistri andmed;
karistusregistri andmed;
e-toimiku süsteemi andmed;
äriregistri andmed;
maksukohustuslaste registri andmed;
elektroonilise arestimissüsteemi andmed;
kinnistusraamatu andmed;
liiklusregistri andmed;
tegelike kasusaajate andmekogu andmed;
Eesti väärtpaberite keskregistri andmed;
isikut tõendavate dokumentide andmekogu andmed;
töötamise registri andmed;
majandustegevuse registri andmed;
sissesõidukeeldude riikliku registri andmed;
infosüsteemi POLIS andmed.
Lõikes 2 nimetatud andmete täpne koosseis on toodud käesoleva põhimääruse lisas.
Lõikes 2 nimetatud andmeid töödeldakse järgmiselt:
rahapesu ja terrorismi rahastamise tõkestamiseks ning sellele viitava teabe vastuvõtmiseks, kogumiseks, väljanõudmiseks, registreerimiseks, töötlemiseks, analüüsimiseks ja edastamiseks ning strateegilise analüüsi tegemiseks töödeldakse kõiki nimetatud andmeid;
järelevalve tegemiseks kohustatud isikute tegevuse üle, tegevuslubade taotluste lahendamiseks, majandustegevuse peatamiseks või keelamiseks või tegevusloa peatamiseks või kehtetuks tunnistamiseks majandustegevuse seadustiku üldosa seaduses sätestatud korras, arvestades rahapesu ja terrorismi rahastamise tõkestamise seaduse erisusi, töödeldakse punktides 1, 2, 4, 5 ja 7–13 nimetatud andmeid;
rahvusvahelise sanktsiooni seadusest tulenevate ülesannete täitmiseks töödeldakse punktides 1–13 nimetatud andmeid.
Andmekogu vastutav töötleja esitab päringuid, sealhulgas automatiseeritult, ja saab andmeid Euroopa Liidu ja rahvusvahelistest infosüsteemidest vastavalt Euroopa Liidu ja rahvusvahelistes õigusaktides sätestatule.
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 19. Data exchange among databases
(1) The controller of the database has the right, in order to perform the duties assigned to it by law or by legislation established pursuant to law, to submit queries to other databases of the state or local governments and obtain data therefrom. The data exchange with databases takes place via the data exchange layer of information systems.
(2) The controller of the database submits queries, including automatically, and obtains data from the following databases or information channels:
1) commercial register;
2) population register;
3) criminal records database;
4) register of taxable persons;
5) e-file system;
6) electronic system of information inquiries and arrest mediation.
(3) The controller of the database submits queries, including automatically, and obtains data from the information systems of the European Union and international information systems in compliance with the provisions of the EU and international legislation.
§ 20. Andmete andmekogusse kandmise alusdokumendid
Andmete andmekogusse kandmise alusdokumendid on rahapesu ja terrorismi rahastamise tõkestamise seaduse alusel Rahapesu Andmebüroo ülesannetest tulenevates toimingutes ja menetlustes esitatud, koostatud ja kogutud dokumendid.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 20. Source documents for entry of data in database
The source documents for entry of data in the database are the documents submitted, prepared and collected in the course of the operations and proceedings deriving from the duties of the Financial Intelligence Unit on the basis of the Money Laundering and Terrorist Financing Prevention Act.
§ 21. Andmete andmekogusse kandmine
Andmekogusse andmete kandmise pädevus on vastutava töötleja kindlaks määratud ametnikul või töötajal temale teenistusülesannete täitmiseks määratud ulatuses.
Kohustatud isik edastab andmed turvalise elektroonilise kanali kaudu, mis on selleks otstarbeks loodud.
Kande kohta säilitatakse järgmised andmed:
kande tegija eesnimi või -nimed ja perekonnanimi või -nimed;
kande tegemise kuupäev ja kellaaeg.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 21. Entry of data in database
(1) The competence to enter data in the database lies with the official or employee designated by the controller, in the extent assigned to them for the performance of their service duties.
(2) The obliged entity forwards the data via a secure electronic channel created for this purpose.
(3) The following data are retained regarding an entry:
1) given name(s) and surname(s) of the person making the entry;
2) date and time of making the entry.
§ 22. Andmete õigsuse tagamine
Andmeandja vastutab tema esitatud andmete ja alusdokumentidel olevate andmete õigsuse eest alusdokumendi esitamise ajal.
Andmekogu vastutav töötleja vastutab, et andmekogusse kantud andmed vastavad andmeandja esitatud andmetele.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 22. Ensuring correctness of data
(1) The person submitting data is responsible for the correctness of the data submitted by them and the data in the source documents at the time of submission of the source document.
(2) The controller of the database is responsible for the conformity of the data entered in the database with the data submitted by the person submitting the data.
§ 23. Ebaõigete andmete parandamine
Kui vastutav töötleja avastab andmekogus ebaõigeid andmeid või kui talle on nendest teada antud, korraldab ta andmete parandamise viivitamata pärast ebaõigetest andmetest teadasaamist ning lisab andmekogusse õigeid andmeid tõendava dokumendi või selle koopia ja märgib andmekogusse paranduse aluseks oleva dokumendi, paranduse tegemise aja ning paranduse teinud ametniku ees- ja perekonnanime.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 23. Rectification of incorrect data
If the controller detects incorrect data in the database or is informed about incorrect data, the controller organises the rectification of the data immediately after having become aware of the incorrect data, and adds the document evidencing the correct data or a copy thereof to the database, and enters the document constituting the grounds for rectification, the time of rectification and the given name and surname of the official making the rectification in the database.
4. peatükk Juurdepääs andmekogu andmetele ja nende väljastamine andmekogust
§ 24. Juurdepääs andmekogu andmetele
Juurdepääs andmekogusse kantud andmetele on vastutava töötleja kindlaks määratud ametnikul või töötajal talle teenistus- ja tööülesannete täitmiseks määratud ulatuses ja viisil.
Juurdepääs andmekogule on volitatud töötleja kindlaks määratud töötajal talle tööülesannete täitmiseks määratud ulatuses.
Andmekogule on Rahapesu Andmebüroo juhi loal juurdepääs isikul, kes teeb infotehnoloogilisi arendus- ja hooldustöid vastutava töötlejaga kokku lepitud tingimustel, ulatuses ja korras.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 24. Access to data in database
(1) The access to the data entered in the database is granted to the officials or employees designated by the controller, in the extent and in the manner assigned to them for the performance of their service and employment duties.
(2) The access to the database is granted to the employees designated by the processor, in the extent assigned to them for the performance of their service duties.
(3) The access to the database is granted with the permission of the head of the Financial Intelligence Unit to persons who perform information technology development and maintenance work, on the terms, in the extent and in accordance with the procedure agreed upon with the controller.
§ 25. Andmete väljastamine andmekogust ja logimine
Andmekogu vastutav töötleja väljastab andmekogusse kantud andmeid kolmandatele isikutele, kui andmete väljastamiseks on seaduses sätestatud alus.
Andmekogu vastutav töötleja peab arvestust selle üle, kellele, mis eesmärgil, millal, kuidas ja missuguseid andmeid on väljastatud.
Iga andmekogusse tehtud päringu või kande kohta säilitatakse vähemalt järgmised andmed:
päringu või kande teinud isiku ees- ja perekonnanimi;
päringu või kande tegemise kuupäev ja kellaaeg.
Lõikes 3 nimetatud andmeid säilitatakse kümme aastat päringu või kande tegemisest arvates, pärast seda andmed kustutatakse.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 25. Issue of data from database and logging
(1) The controller of the database issues data entered in the database to third persons if there are grounds for the issue of data provided by law.
(2) The controller of the database keeps record of the persons to whom, for which purpose, when, how and which data are issued.
(3) At least the following data are retained for every query or entry made in the database:
1) given name and surname of the person making the query or entry;
2) date and time of making the query or entry.
(4) The data specified in subsection 3 are retained for ten years after a query or entry is made, and thereafter the data are deleted.
5. peatükk Andmekogu andmete säilitamine, järelevalve andmekogu pidamise üle, andmekogu pidamise rahastamine ja andmekogu likvideerimine
§ 26. Andmekogu andmete säilitamine
Repealed
Andmekogu andmeid ja andmekogusse kantud dokumente isiku kohta, välja arvatud järelevalve ja tegevuslubadega seonduva tegevuse käigus kogutud andmeid ja dokumente, säilitatakse andmekogus 15 aastat pärast vastava teate või toimiku sulgemist. Andmed isiku kohta, isiku seosed teiste andmetega ja temaga seotud dokumendid kustutatakse andmekogust nii, et oleks tagatud isikute, teadete ja toimikute andmete terviklikkus.
Järelevalve ja tegevuslubadega seonduva tegevuse käigus kogutud andmeid ja dokumente säilitatakse andmekogus kümme aastat järelevalvemenetluse lõppemisest või väljastatud tegevusloa kehtivuse lõppemisest arvates.
Repealed
The Estonian text of this provision has changed since the translated version (01.01.2021): the translation does not match the text in force.
§ 26. Retention of data of database
(1) The data of the database and documents entered in the database concerning a person are retained in the database for 15 years after the closure of the respective report or file. The data on a person, the links of the person with other data and the documents related to the person are deleted from the database in such manner as to ensure the integrity of the data on persons, reports and files.
(2) As an exception to subsection 1, the documents and archival records to be transferred to the National Archives pursuant to subsection 9 of § 60 of the Money Laundering and Terrorist Financing Prevention Act are retained in the Financial Intelligence Unit for 30 years. The respective documents are deleted after the transfer.
§ 27. Järelevalve andmekogu pidamise üle
Järelevalvet andmekogu pidamise üle teostab Riigi Infosüsteemi Amet ja Andmekaitse Inspektsioon vastavalt õigusaktides sätestatud pädevusele.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 27. Supervision over maintenance of database
Supervision over the maintenance of the database is exercised by the Information System Authority and Data Protection Inspectorate in accordance with the competence provided by legislation.
§ 28. Andmekogu rahastamine
Andmekogu hooldus- ja arendustöid ning pidamist rahastatakse riigieelarvest vastutavale ning volitatud töötlejale selleks otstarbeks eraldatud vahenditest.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 28. Financing of database
The maintenance and development work and the maintenance of the database are financed from the state budget from the funds allocated for this purpose to the controller and processor.
§ 29. Andmekogu likvideerimine
Andmekogu likvideerimise otsustab valdkonna eest vastutav minister.
Andmekogu likvideeritakse kooskõlas arhiiviseaduses ja avaliku teabe seaduses sätestatud nõuetega.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 29. Liquidation of database
(1) The liquidation of the database is decided by the minister in charge of the policy sector.
(2) The database is liquidated in compliance with the requirements provided in the Archives Act and Public Information Act.
§ 30. Määruse jõustumine
Määrus jõustub 2021. aasta 1. jaanuaril.
Paragrahvi 26 lõige 1 jõustub 2024. aasta 1. jaanuaril.
Translation of the version of 01.01.2021; the Estonian text of this provision has not changed since.
§ 30. Entry into force of Regulation
(1) This Regulation enters into force on 1 January 2021.
(2) Subsection 1 of § 26 enters into force on 1 January 2024.