Estonia Estonia

Allium UPI

3,000,000 €

GDPR enforcement action by Estonian Data Protection Authority (AKI) on 2025-09-05.

Rank · Sector
#16
of 597 in Industry and Commerce
Rank · Estonia
#1
of 8
Rank · All fines
#104
of 3,050

Case details

Authority
Estonian Data Protection Authority (AKI)
Date
2025-09-05
Controller / Processor
Allium UPI
Sector
Industry and Commerce
Quoted Articles
Unknown
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a data breach involving the personal data of 750,000 individuals, including children and other vulnerable groups.

Open original source Links to the regulator's original publication or another source.

Related fines