An Estonian court upholds the 3 million euro fine imposed on Allium UPI for data security failures

The Estonian court of first instance upheld the 3,000,000 € fine imposed on a data controller for security measures deemed insufficient given the volume and sensitivity of the data processed, including health data.

Facts and context

The Harju County court confirmed, by a decision dated 2 September 2026, the sanction imposed by the Estonian Data Protection Authority (Andmekaitse Inspektsioon - AKI) against the company Allium UPI OÜ, including a fine of 3,000,000 €, for failures related to the security of personal data.

The case follows an appeal filed by Allium UPI OÜ against the AKI decision, which sanctioned the company after a cyberattack allowed the illegal download of data from holders of the "Apotheka" loyalty card.

Grounds of the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The court considered that the responsibility of Allium UPI OÜ, as the controller of the loyalty program, was engaged not only because of the cyberattack suffered but especially due to the inadequacy of its technical and organizational measures. It was found that these measures were not commensurate with the volume and sensitive nature of the data processed, which included health data. The court noted specific failures, notably in the protection of administrative accounts, security monitoring, and the methods of backup storage.

Authority's decision

Consequently, the court deemed the 3,000,000 € fine imposed by the AKI on Allium UPI OÜ to be justified and proportionate. The court also ordered the procedural costs to be borne by the company.

Lessons learned

This decision confirms that:

  • The adequacy of technical and organizational security measures must be rigorously assessed according to the volume and sensitivity of the data processed, especially when it concerns large-scale health data.
  • The occurrence of a cyberattack does not in itself constitute a ground for exemption from liability; the analysis by the authority and courts focuses on the sufficiency of the security measures implemented before the incident.
  • Failures in fundamental security areas, such as privileged account management, system monitoring, and backup management, are decisive factors in assessing a breach of the security obligation.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire