On 1 January 2026, amendments to Estonia’s Cybersecurity Act entered into force, transposing the NIS2 Directive into Estonian law. According to the Estonian Information System Authority (RIA), this increased the number of companies and institutions required to comply with cybersecurity obligations from around 3,500 to nearly 6,500.
The taxation of passenger cars in Estonia mainly depends on who owns the car, how it is used for business purposes, and whether private use is allowed. The Tax and Customs Board follows the principle that not only the actual use of the car matters, but also the possibility of private use.
The use of artificial intelligence has already been strategically implemented in many organisations. But even where it has not, everyone still has access to free AI tools. Whether it is ChatGPT, Claude, Gemini or another platform, these tools help people write texts, summarise information, organise ideas and perform analyses.
The Occupational Health and Safety Act (TTOS) obliges employers to prevent and mitigate psychosocial risks – this also includes situations where an employee does not feel safe or is afraid to speak directly to their manager about a concern.
The Defense Tax Act, adopted at the end of last year and widely debated due to the proposed taxation of corporate profits, has been repealed. Instead, permanently increased tax rates will now apply to value-added tax (VAT), income tax, and business income tax.
In a smaller company, implementing new software can take three to four months, while in larger companies it can take a couple of years. Change management is exceptionally important for the transition to be successful
E-invoices are a useful tool for every accountant to avoid mistakes caused by human error, which waste time and money. There are also many other business advantages to "selling" e-invoicing to a manager or client.
Grant Thornton Baltic audited the acquisition report prepared by Eesti Energia AS, the main shareholder of Enefit Green AS, for the acquisition of shares belonging to minority shareholders.
The 21st of May brought us sorrowful news: Aivar Kangust, former partner and sworn auditor at Grant Thornton Baltic, has passed away and embarked on the path of eternity.
In this article, we’ll explore how attackers are misusing trusted technologies - like OAuth and DKIM (more on these in a moment) - and why everyone should be cautious when a message or application requests access to user accounts.
From 1 July 2025 the standard VAT rate will be 24%.
Kristjan Järve and Madis Laas discussed the necessity of the recently published guidelines by the Tax and Customs Board and the process of their preparation in the show "Kasvukursil".
Lithuania is planning a comprehensive tax reform for 2026 aimed at strengthening national defense funding and supporting economic development. Grant Thornton Lithuania tax specialist Vykintas Valiulis has prepared a detailed overview on the topic.
When outsourcing accounting services, you can be sure that the work won't be left undone in case the accountant falls ill or goes on vacation.
The field of information security seems like a labyrinth full of abbreviations lately: NIS2, DORA, ISO 27001, E-ITS, SOC 2. Therefore, I will briefly advise on how to navigate information security regulations, standards, audits, and certifications.
On 26 February 2025, the European Commission (EC) released a new package of proposals (the Omnibus) to amend some key pillars of the European Green Deal. The overall goal of the Omnibus is to reduce reporting burdens, particularly for smaller and mid-sized entities, and increase efficiency in sustainability reporting.
New regulations have come into effect or will soon come into effect in Estonia, which will impose a range of information security obligations on various sectors. Entrepreneurs are struggling to understand where to start and which direction to go.
In recent months, there has been much discussion about reducing the reporting burden of sustainability for companies and the European Commission's desire to simplify reporting.
The Estonian information security standard (E-ITS) is an Estonian-language standard compatible with the Estonian legal system and developed for ensuring protection for business processes and information systems used for fulfilling public functions.