Content type · 12 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Country: Estonia (12) Clear filter
Filter by Topic Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
A private website operator published documents they collected from public registers The DPA held that the operator failed to ensure that later access restrictions imposed by the authorities are considered and that a legitimate interest could not be blanket legal… 2.1.-4/26/1106-2333-4 ·Estonia Oct 1, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia Apr 16, 2026
€3M Allium UPI: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000.000 euro - De Estische Autoriteit voor Gegevensbescherming (AKI). ESTONIA ·Insufficient technical and organisational measures to ensure information security Sep 5, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·Insufficient technical and organisational measures to ensure information security Sep 5, 2025
Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected… ESTONIA ·Insufficient technical and organisational measures to ensure information security Jan 10, 2025
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·Insufficient technical and organisational measures to ensure information security Jul 15, 2024
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·Art. 5, 6 Dec 1, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·Art. 5, 6 Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·Art. 5, 6 Dec 1, 2020
€56 Health care worker: Insufficient legal basis for data processing Acess to personal data in a health database for private research activities. ESTONIA ·Art. 5, 6 Aug 17, 2020
€48 Police Officer: Insufficient legal basis for data processing Acess to personal data in a police database for private research activities. ESTONIA ·Art. 5, 6 Aug 17, 2020
€500 Housing Association: Insufficient legal basis for data processing Fine of EUR 500 against a housing association for publishing photos showing members of the association without their consent. ESTONIA ·Art. 6 Apr 30, 2020