AKI (Estonia) - Allium UPI

From GDPRhub
AKI - Allium UPI
Authority: AKI (Estonia)
Jurisdiction: Estonia
Relevant Law: Article 32 GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided:
Published: 05.09.2025
Fine: 3,000,000
Parties: Allium UPI
National Case Number/Name: Allium UPI
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Estonian
Original Source: AKI (in ET)
Initial Contributor: n/a

The DPA fined a pharmeceutical wholesaler €3,000,000 over a large-scale breach involving information about pharmaceutical purchases. The company failed to implement sufficient security measures like multi-factor authentication.

English Summary

Facts

The case concerns Allium UPI, a pharmaceutical wholesaler. Allium UPI was in charge of managing the loyalty program of pharmaceutical chain Apotheka.

In early 2024 Allium UPI was targeted by a cyberattack. Unauthorised person managed to repeatedly access the company's systems and exfiltrate data backups for Apotheka's loyalty programs. These backups included the personal details of a large number of Apotheke customers who joined the loyalty programs between 2014 and 2020 as well as detailed information about their pharmaceutical purchases. The DPA investigated the incident ex officio.

Holding

The DPA found that Allium UPI failed to implement critical security measures including multi-factor authentication and access logs. The DPA also held that the leaked data were sensitive in nature. On these grounds, the DPA issued a €3,000,000 fine.

Comment

The DPA publicized the decision via a press release. The full text of the decision is unpublished at the time of writing.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Estonian original. Please refer to the Estonian original for more details.

A security incident occurred in the information system of the Apotheka loyalty program in early 2024. The investigation found that Allium UPI did not implement basic cyber hygiene and data protection measures. As a result, unauthorized persons repeatedly accessed the information system and database backup and downloaded a large amount of sensitive customer data.  
The leaked files contained personal data (first and last name, personal identification number, language, gender, email address, phone number, home address) and purchase history of those who joined the Apotheka customer program in 2014–2020. The latter included personalized information about purchased medicines, health measurement services, and other sensitive pharmacy products, such as pregnancy and ovulation tests, hearing aid accessories, blood pressure supplements, intimate hygiene products, and medications for skin problems. Such information refers to a person's health and intimate sphere of life. 
Elementary security measures were not implemented 
During the proceedings, it became clear that Allium UPI failed to implement several critical security measures that are also well-known to ordinary users. For example, multi-level authentication was not implemented, one personal administrator account was used by several people with the same username and password, activity log monitoring was inadequate, and database backups were stored insecurely. Roles and responsibilities were also not clearly defined. 
“If a company’s business model is based on processing customer data, protecting it must be an integral part of the business model. Every company that customers trust with their data has an obligation to protect it and keep it safe. If a company does not do this, it endangers the privacy and trust of its customers,” explained Pille Lehis, Director General of the Data Protection Inspectorate. “In this case, Allium UPI failed to implement the necessary security measures, and as a result, the data of hundreds of thousands of people was leaked.” 
“Our task is to protect people whose data has been leaked and who, as a result, cannot be sure how their data may be misused,” added Jekaterina Aader, a lawyer at the Data Protection Inspectorate. “Our role is to ensure that companies learn from these cases and increase their level of data protection. A fine is a last resort, the purpose of which is to implement responsibility and prevention,” said Aader. 
The size of the fine was determined taking into account the scope of the breach, the sensitivity of the leaked data, the number of affected persons and the company’s turnover. The decision was based on the European Union General Data Protection Regulation and the relevant guidelines of the European Data Protection Board. 
All data processors are obliged to ensure that personal data is processed securely. This means, among other things, continuous monitoring of systems, rapid elimination of security vulnerabilities and strict control of access. 
The fine decision has not yet entered into force. The company has the opportunity to appeal it within 15 days.