Latest update · 28 September 2026
Lead Signal
Estonia's data protection authority, Andmekaitse Inspektsioon (AKI), imposed a EUR 3,000,000 fine on Allium UPI OU on 5 September 2025 over the Apotheka loyalty-programme data breach, which affected more than 750,000 individuals. This is the largest GDPR fine imposed in Estonia to date, and it was enabled by a 2023 legislative amendment to the Isikuandmete kaitse seadus (IKS) that significantly simplified the process for imposing GDPR-type fines directly on legal persons for infringements committed on or continuing from 1 November 2023. The fine is under appeal, with court hearings beginning 6 April 2026, and its outcome had not been resolved as of this cycle.
Other Developments
A statutory penalty ceiling underpins the escalation. IKS Sections 66-70 punish distinct categories of GDPR violation with fines of up to EUR 20,000,000, or for legal persons up to EUR 20,000,000 or 4 percent of worldwide annual turnover, whichever is greater, and these violations are classified as an Estonian misdemeanour rather than a criminal offence. The Allium UPI penalty sits well below this statutory ceiling, indicating headroom remains for larger sanctions in future cases of comparable or greater severity.
A private right of action stands alongside the regulatory penalty track. Any person who has suffered material or non-material damage from a GDPR infringement in Estonia has a direct right to claim compensation under Estonian law, independent of whatever action AKI itself takes. This dual-track structure, regulatory fine plus private compensation claim, means the more than 750,000 individuals affected by the Apotheka breach retain an independent civil avenue regardless of how the Allium UPI appeal resolves.
Cross-Monitor Connections
The scale and sector of the Allium UPI breach, a loyalty-programme data incident affecting a large consumer base, carries a commercial-privacy dimension that borders on the territory covered by the world-payments and advennt monitors where a loyalty or payments-adjacent business model intersects with large-scale personal data processing; readers tracking Estonian consumer-facing digital commerce should cross-reference those monitors for any related commercial development. No direct overlap with financial-integrity's AML/CFT tracking was identified this cycle.
Outlook
The Allium UPI appeal, with court hearings beginning 6 April 2026, is the clearest near-term signal to watch: its outcome will clarify how durable AKI's newly-simplified fining power actually is, particularly against the backdrop of the earlier annulment of AKI's Asper Biogene fine, which already introduced uncertainty about the regulator's practical enforcement capacity. A ruling upholding the EUR 3,000,000 fine would confirm the 2023 legislative simplification has produced a durable escalation in AKI's enforcement reach; a ruling against AKI would suggest the opposite.
Standing brief · as of 26 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Estonia's first full GDPR baseline this cycle carries one dominant signal. A challenger-fold review found that a November 2023 Estonian Penal Code amendment reportedly empowered AKI to impose GDPR Article 83-style fines up to EUR 20 million or 4% of global turnover. The same review found that AKI imposed a EUR 3 million fine in September 2025 against Allium UPI OÜ over the Apotheka loyalty-programme breach, which affected more than 7 million records. Commentary describes this as AKI's largest-ever sanction. Both facts currently rest on T4 practitioner sources and await T1/T2 primary-source confirmation.
Other Developments
AKI, based in Tallinn under Director General Pille Lehis, is Estonia's EDPB-member supervisory authority. The Personal Data Protection Act has implemented the GDPR in Estonia since 15 January 2019. Estonia has no general controller registration regime; AKI instead operates a national DPIA-trigger list adopted under GDPR Article 35(4). In a 2022 decision, AKI rejected a ride-hailing controller's reliance on contractual necessity for processing rider-rating data and ordered the processing suspended and the data deleted. AKI separately found the same controller had failed GDPR transparency obligations toward riders. In a 2020 case, AKI held that a third party's self-declared authorisation is not equivalent to voluntary, verifiable consent, and issued a precept with a one-day deadline and a EUR 100,000 penalty threat against three e-pharmacy chains. AKI issued a EUR 5,000 penalty precept against a Facebook-group administrator for disclosing debt data to thousands of unidentified members. AKI issued a EUR 10,000-per-point precept against Krediidiregister OÜ over unlawful disclosure of non-payment data. The EU Digital Omnibus, under EDPB/EDPS consultation since 25 November 2025, proposes amendments to the GDPR, EUDPR and ePrivacy Directive. EDPB and EDPS support raising the Article 30(5) records-of-processing exemption threshold from under-250 to under-750 employees. EDPB and EDPS also support easing the breach-notification risk threshold and deadline. EDPB and EDPS urged rejection of a proposal to narrow the Article 4(1) personal-data definition for pseudonymised data. A leaked Council compromise on 20 February 2026 reportedly already removed that narrower definition from the text. A related Omnibus strand would extend high-risk AI Act obligations, due August 2026, to a cap of December 2027. Estonia's Riigikohus lodged CJEU Case C-222/25 over a dispute between the Financial Intelligence Unit and GDPR/AML processing rules, with AKI as an involved party. The EU-UK adequacy decision, applicable to Estonia as an EEA state, remains valid until 27 December 2031. Estonia's specific national digital-consent age threshold under GDPR Article 8(1) could not be confirmed this cycle.
Cross-Monitor Connections
CJEU Case C-222/25 concerns the Estonian Financial Intelligence Unit's AML data processing and its GDPR interface, and is being routed to the financial-integrity monitor for AML-CFT assessment. The Digital Omnibus's proposed AI Act timeline extension is being routed to the artificial-intelligence monitor for AI-Act-first analysis; this brief retains only the profiling and automated-decision-making transparency angle from AKI's ride-hailing decision.
Outlook
AKI's reported fining-power expansion and its EUR 3 million Apotheka fine require primary-source confirmation before they can be treated as settled. The Digital Omnibus negotiation remains fluid on ROPA thresholds, breach-notification triggers and AI Act timelines even as the personal-data-definition change appears to have been dropped. The pending CJEU ruling in Case C-222/25 adds further uncertainty at the GDPR/AML interface.