# Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Estonian Data Protection Authority (AKI)
- Date: 2025-01-10
- Original: https://www.enforcementtracker.com/ETid-2594
- Canonical: https://overview.legal/posts/48709
- Topics: Notified Body Responsibilities and Operational Obligations, Security, Genetic Data, Healthcare, Processing Agreement, Personal Data, Supervisory Authorities, Special Categories of Data, Law Enforcement, Types of Special Categories of Personal Data

## Summary

The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected approximately 100,000 files containing personal, health and genetic data. Asper Biogene OÜ also appointed a member of the board of directors as DPO, resulting in a conflict of interest. A fine of EUR 80,000 was imposed for the inadequate security measures. The unlawful appointment of the DPO was fined EUR 5,000. ---UPDATE--- The T

## Full text

The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected approximately 100,000 files containing personal, health and genetic data. Asper Biogene OÜ also appointed a member of the board of directors as DPO, resulting in a conflict of interest. A fine of EUR 80,000 was imposed for the inadequate security measures. The unlawful appointment of the DPO was fined EUR 5,000. ---UPDATE--- The Tartu County Court overturned the DPA's decision. The DPA has appealed against the court's decision.

GDPR Articles: Unknown
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/48709 · 2026-08-22
