Enforcement · Estonian Data Protection Authority (AKI) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Allium UPI: Insufficient technical and organisational measures to ensure information security
The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI.
Full text
The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a data breach involving the personal data of 750,000 individuals, including children and other vulnerable groups.
Industry: Industry and Commerce
How it connects
Related across sources
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) CJEU Dec 14, 2023 Integrity and Confidentiality Principle Data Breaches Notification Obligation
C-293/12 Digital Rights Ireland Ltd v Minister for Communications C-293/12 (Digital Rights Ireland) CJEU Apr 8, 2014 IP Address Storage Limitation Right to be Forgotten
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
Guidelines 02/2022 application of Article 60 GDPR Guidelines ·EDPB Mar 14, 2022 Supervision Supervisory Authorities Processors
Opinion 15/2025 certification criteria of BDO Consulting GmbH ·Opinion ·EDPB Jul 14, 2025 Certification Supervision Supervisory Authorities
Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Apr 17, 2023 Right of Access Personal Data Right to Rectification