Allium UPI
€3,000,000
Insufficient technical and organisational measures to ensure information security
Karar Tarihi
5 Eylül 2025
Otorite
Estonian Data Protection Authority (AKI)
EE
Sektör
Industry and Commerce
Ülke
EE
Hukuk
GDPRDurum
FINALAçıklama
The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a data breach involving the personal data of 750,000 individuals, including children and other vulnerable groups.
Sorunlar & İhlaller
Insufficient technical and organisational measures to ensure information security