Allium UPI

€3,000,000

Insufficient technical and organisational measures to ensure information security

Data della decisione

5 settembre 2025

Autorità

Estonian Data Protection Authority (AKI)

EE

Settore

Industry and Commerce

Paese

EE

Legge

GDPR

Stato

FINAL

Descrizione

The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a data breach involving the personal data of 750,000 individuals, including children and other vulnerable groups.

Problemi e violazioni

Insufficient technical and organisational measures to ensure information security

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.