← Enforcement
GDPR EU 2016/679 Estonia

AKI fines: every known enforcement case of Estonia's Data Protection Inspectorate

A complete public registry of fines issued by the Estonian Data Protection Inspectorate — from token misdemeanour fines of a few dozen euros on individuals up to €3 million against the Apotheka pharmacy chain. What was violated, which decisions were overturned in court, and why Estonia is the EU's most lenient GDPR jurisdiction — and is right now ceasing to be one.

Estonia has always been a blank spot on the GDPR enforcement map. While Ireland was hitting Meta with €1.2 billion and the Netherlands fined Uber €290 million, the Estonian Andmekaitse Inspektsioon (AKI) issued — over the first five years of GDPR (May 2018 to November 2022) — 29 fines totalling €1,924. The largest single fine was €280. That is not a typo. Two hundred and eighty euros.

In September 2025 that changed: AKI issued €3,000,000 to OÜ Allium UPI, the operator of the Apotheka pharmacy chain’s loyalty program. The largest fine in the history of Estonian data protection. And the story behind it isn’t about a vindictive regulator — it’s about a legal system that physically couldn’t fine legal entities under GDPR for six years, until parliament fixed it in November 2023.

This post is the full registry of AKI’s publicly known cases — with concrete amounts, GDPR articles, descriptions of the violations, and the fate of each decision in court. Direct links to the regulator, Estonian press, and the enforcementtracker.com registry on every case.

Why Estonian fines are so small

The problem isn’t with the inspectorate — it’s with the Penal Code.

Estonia has no administrative fines under GDPR — only misdemeanour proceedings (väärteomenetlus). This is a quasi-criminal procedural construction that, until recently, required identifying a specific natural person responsible inside the organisation. If AKI wanted to punish a company for a leaked database, it first had to identify the specific IT person, director, or officer who failed to supervise — and prove their personal guilt. In practice this is nearly impossible for organisational violations.

In parallel, a general cap of €400,000 on misdemeanour fines applied — already below the GDPR ceiling (€20M / 4% of turnover).

Hence the historical statistics cited in Sorainen’s Baltic survey — between 25 May 2018 and November 2022 AKI issued 29 fines totalling €1,924, with €280 the largest and roughly €66 the average. In parallel, 18 non-compliance levies (sunniraha) totalling €33,000, the largest one €10,000.

The year-by-year breakdown, per AKI’s official statistics page:

YearInquiries (narrow category)Misdemeanour casesFines (total)
20211,8131110
20221,325712
20231,910812
20241,74277
20251,78465

The “inquiries” column on the statistics page (1,742 for 2024) counts “questions, memoranda and freedom-of-information requests”. A separate, broader figure of 4,162 inquiries for 2024 appears in AKI’s press release: it also includes advice-line calls, media inquiries, demand letters and appeals. These are two different counting methodologies — comparing the older narrow figure to the broader press-release figure as if they were the same metric is not legitimate.

AKI’s statistics page does not publish per-year totals for fine amounts or averages — for those you need the annual report PDF.

Reform of 1 November 2023: AKI finally gets teeth

The amendments to the Penal Code (Riigi Teataja, IKS), effective 1 November 2023:

  1. Removed the requirement to identify a specific natural person — a legal entity now answers for “insufficient oversight or organisational failure” as a standalone offence. You can fine the company itself.
  2. Raised the statute of limitations from 2 to 3 years — more cases reach a decision before timing out.
  3. Made it explicit that the general €400,000 cap does not apply to specific GDPR provisions — opening the way to fines at the GDPR level (€20M / 4% of turnover).

This explains why all the genuinely large Estonian fines are dated 2024–2025: before the reform they could not legally be issued.

DLA Piper’s country profile for Estonia puts it bluntly: “Estonian law does not recognize administrative fines, requiring enforcement through misdemeanor proceedings instead” — and ties the 2023 reform directly to the appearance of the first €3M fine.

Full registry of known cases

Cases ordered by fine amount, from record to historic micro-cases. For each: what they did, how much, whether contested, and a source link.

Quick guide to the GDPR articles cited below (so you don’t need to keep EUR-Lex open in another tab):

  • Art. 5 — the seven core principles of data protection: lawfulness, fairness and transparency; purpose limitation (data collected for X cannot be used for unrelated Y); data minimisation; accuracy; storage limitation (delete when no longer needed); integrity and confidentiality; accountability.
  • Art. 6 — the six lawful bases for processing personal data: consent, contract, legal obligation, vital interest, public task, legitimate interest. You need exactly one to lawfully process anyone’s data.
  • Art. 7 — the conditions for valid consent (freely given, specific, informed, unambiguous; easy to withdraw).
  • Art. 9 — special-category data (health, genetics, biometrics, religion, sexual orientation, etc.) — stricter rules than ordinary data.
  • Art. 12 / Art. 14 — transparency: you must clearly tell people what data you collect, why, how long you keep it, what their rights are.
  • Art. 24 — the controller’s overall responsibility: you must put in place (and be able to demonstrate) appropriate measures to ensure processing complies with GDPR.
  • Art. 25 — data protection by design and by default: privacy safeguards must be built into systems from the start, not bolted on later.
  • Art. 32 — security of processing: you must implement appropriate technical and organisational measures (encryption, access control, monitoring, etc.).
  • Art. 37–38 — Data Protection Officer requirements: when a DPO is mandatory, who can be appointed, conditions of independence.

1. Allium UPI OÜ (Apotheka) — €3,000,000 — 5 September 2025

What happened. In early 2024 a hacker accessed the Apotheka loyalty program database and exfiltrated data on more than 750,000 individuals — names, personal ID codes (isikukood), contact details, delivery addresses, and detailed purchase histories (especially sensitive for a pharmacy — purchase records expose medical conditions). According to AKI’s investigation, unauthorised access happened repeatedly, and basic security controls — two-factor authentication, monitoring of suspicious activity — simply weren’t in place.

GDPR Articles. Per AKI’s 2025 annual report, the fine was grounded in Art. 5(1)(f) (the integrity-and-confidentiality principle), Art. 24 (the controller’s general responsibility), Art. 25 (data protection by design and by default) and Art. 32 (security of processing) — not Art. 32 alone. The core failure: inadequate technical and organisational security measures.

Decision. AKI issued €3,000,000 — the largest fine in Estonian data protection history and the first Estonian fine to make international headlines.

Status. UNDER APPEAL. Allium UPI is part of Margus Linnamäe’s MM Grupp (the holding behind the Magnum Medical wholesale arm and the Apotheka, Apotheka Beauty and Pet City retail chains). The company filed an appeal, publicly stating that they “were not negligent and did not leave the data unprotected.” Court hearings began on 6 April 2026. As of May 2026 the case is in active proceedings; no first-instance decision has been issued.

Sources: AKI press release (5 September 2025), enforcementtracker ETid-2858, aritehnoloogia.ee — Allium UPI’s appeal statement, kaubandus.ee — court hearings began 6 April 2026.


2. Asper Biogene OÜ — €85,000 — 10 January 2025

What happened. In 2023 the systems of genetic-testing lab Asper Biogene were attacked and roughly 100,000 files containing personal and health data on approximately 10,000 people were stolen, including genetic test results. AKI’s Director General Pille Lehis called it the largest health-data leak in Estonian history by number of affected individuals. After the breach, extortion attempts followed — fraudsters wrote to affected individuals threatening to publish their data.

GDPR Articles. Per AKI’s 2024 annual report, the €85,000 was split across two separate offences citing Art. 5(1)(f) + Art. 32 (the €80,000 count) and Art. 37(5) + Art. 38(6) (the €5,000 count) — not Art. 32 plus a generic “Art. 37–38”.

Decision. AKI split the violations into two offences:

  • €80,000 — breach of the integrity-and-confidentiality principle (Art. 5(1)(f)) and inadequate security (Art. 32) for special-category data (genome + health is the most sensitive data a private company can process).
  • €5,000 — DPO requirements (Art. 37(5) on competence, Art. 38(6) on conflict of interest): the company appointed its sole board member as DPO. Per AKI, this person lacked both independence (clear conflict with management) and competence in data protection.

Total: €85,000.

Status. OVERTURNED IN COURT. Tartu County Court annulled the decision and terminated proceedings on 26 June 2025. AKI filed a cassation appeal to the Supreme Court (Riigikohus), which refused to take the case in late August 2025 (ERR reported the refusal on 28 August 2025). Asper Biogene won definitively. On enforcementtracker this entry (ETid-2594) shows €0 — that reflects the post-court status.

Sources: enforcementtracker ETid-2594, Postimees, Riigikohus ruling.


3. Viljandi Haigla SA — €40,000 — 2024

What happened. Viljandi Hospital management was investigating missing psychotropic medication from the hospital pharmacy. Their solution: collect urine samples from 18 employees. AKI’s logic: even if employees formally consented, in an employment relationship such “consent” is not freely given (GDPR Art. 7), and the processing concerns health data — a special category under Art. 9.

GDPR Articles. Per AKI’s 2024 annual report, the €40,000 was for breaching the data-subject consent rules set out in Art. 5, Art. 6, Art. 7 and Art. 9 — AKI framed it as a violation of the procedure for obtaining valid consent, not (as previously stated here) only Articles 6, 9 and 7(4).

Decision. €40,000.

Status. OVERTURNED IN COURT. Tartu County Court ruled on 18 December 2024 that the hospital had not violated GDPR — the testing was voluntary, evidenced by the fact that not every employee provided a sample (had there been pressure, all would have). AKI’s cassation appeal reached the Supreme Court on 27 January 2025. In early June 2025 Riigikohus confirmed the hospital was not guilty (ERR reported the ruling on 5 June 2025), but changed the basis of termination from “no offence” to “expiry of statute of limitations.”

Sources: ERR (Riigikohus ruling), Sakala (Postimees), Eesti Kohtud.


4. SA Pere Sihtkapital — €30,000 — 26 June 2024

What happened. The Pere Sihtkapital (“Family Endowment”) foundation ran a survey of childless Estonian women on behalf of the University of Tartu. To distribute the survey, the foundation obtained personal data on thousands of women from the Population Register — names, ID codes, email addresses, phone numbers — and surveyed them on sensitive topics around reproduction and family life. AKI classified this as processing without an adequate legal basis: data from a state register cannot be used for an arbitrary sociological survey, even a research one.

GDPR Articles. Art. 5 (minimisation, purpose limitation) + Art. 6 (legal basis) + Art. 9 (special categories — health/reproductive data).

Decision. €30,000.

Status. OVERTURNED — final. On 13 May 2025, Harju County Court annulled the fine and closed proceedings — but on procedural grounds, not on the merits. The court ruled that the Estonian provision did not comply with EU law in how legal-entity guilt should be established. AKI filed a cassation appeal to the Supreme Court (Riigikohus). In June 2025 Riigikohus refused to accept the appeal, leaving the District Court’s annulment final. AKI explicitly noted that no court level ever substantively addressed whether the data processing complied with GDPR — the case ended on a procedural argument.

Sources: AKI, case outcome, ERR (county court annulment), ERR (Supreme Court refusal, case closed).


5. Krediidiregister OÜ — precept + €10,000 per unfulfilled requirement — 2023

Not a fine in the strict sense, but an ettekirjutus (precept) with attached sunniraha (non-compliance levies). Public enough to make the EDPB news feed.

What happened. Krediidiregister OÜ published on its website payment-default and tax-debt data of natural persons linked to legal entities. Access opened after a “I accept the legitimate interest” click — without authenticating the user and without logging access. AKI’s audit found:

  • legitimate interest was not actually assessed;
  • unidentified users had access to sensitive data;
  • the privacy policy was full of holes and didn’t comply with Art. 12, 14 GDPR;
  • third-party cookies were set without consent.

GDPR Articles. Art. 5 (principles) + Art. 6 (legal basis) + Art. 7 (consent conditions) + Art. 12 and 14 (transparency and information).

Decision. A detailed precept: stop disclosing data of natural persons, verify legitimate interest before each disclosure, limit the scope of disclosed data, eliminate unidentified access, align the privacy policy with GDPR, stop third-party cookies without consent. €10,000 sunniraha attached to each requirement in case of non-compliance.

Status. Corrective proceedings, no classical fine. Krediidiregister was forced to bring its site into compliance.

Source: EDPB news.


6. Curiosity queries (uudishimupäring) and the historic micro-fines, 2018–2024

Estonia’s pre-2024 enforcement record is dominated by uudishimupäring — “curiosity queries”: officials and healthcare workers looking up data about acquaintances, neighbours or relatives in state information systems (police databases, the national health information system) with no work-related basis. Legally this is processing outside official duties — typically Art. 5 (purpose limitation) plus Art. 6 (no lawful basis).

Because, until the 1 November 2023 reform described above, AKI could only fine an identifiable natural person via väärteomenetlus, these cases produced a long tail of token fines rather than headline penalties:

  • Per Sorainen’s Baltic survey, between 25 May 2018 and November 2022 AKI issued 29 fines totalling €1,924 — the largest €280, the average roughly €66.
  • AKI’s own 2024 annual report gives the longer view: from May 2018 to December 2024 misdemeanour fines were imposed 35 times, ranging €12–280, averaging €66, all on natural persons only — two of those decisions were later annulled in court.
  • The same report notes that fines in recently completed uudishimupäring proceedings now fall in the €300–800 range, and that in 2024 AKI issued one €500 fine under Penal Code §157¹ for unlawful disclosure of special-category data.

None of these individual micro-cases appear in named public registries — they sit below the threshold enforcementtracker.com tracks for legal entities. The pattern, not any single case, is the point: before legal entities could be fined at all, Estonian “GDPR enforcement” in practice meant dozens of sub-€300 penalties on individual officials, which is exactly why the five-year aggregate stayed under €2,000.


Open complaints (no public fine)

The noyb registry lists four cases against AKI — these are noyb’s (Max Schrems’ organisation) complaints about AKI’s inaction, not AKI’s fines against anyone:

  • Elisa Eesti AS (C029-19, filed 17.08.2020) — data transfer violations. Status: pending more than 4 years.
  • Allepal OÜ (C029-20, 18.08.2020) — data transfers. Marked as “won” by noyb (likely AKI applied corrective measures without a fine).
  • SIA TV NET (C029-21, 17.08.2020) — Latvian TV NET, data transfers. Pending more than 4 years.
  • Bolt (C056, 02.03.2022) — data subject rights. Marked as “won” — likely Bolt brought practice into compliance, no fine issued.

These cases highlight another characteristic AKI pattern: even with a clear complaint, the inspectorate prefers to issue a precept rather than fine. Hard fines remain the exception.


What AKI fines for most often

Looking at the cases above, three persistent themes emerge:

1. Data leaks due to weak security (Art. 32). Allium UPI €3M, Asper Biogene €80K — both about the same thing: a company with a large customer base failed to set up basic controls (2FA, monitoring, encrypted backups) — and got hacked. This is the most expensive class of violation.

2. Using data outside its original purpose. Pere Sihtkapital (survey instead of register), Viljandi haigla (testing for an internal investigation instead of medical care), Krediidiregister (disclosure instead of credit control). Art. 5 — purpose limitation. Often coupled with special categories under Art. 9 (health, genetics).

3. “Curiosity” by employees in internal systems — uudishimupäring. Officials and healthcare workers querying state systems with no work-related basis: dozens of micro-fines to individuals across 2018–2024. This is routine enforcement work, no headlines.

What you won’t see on this list: fines for web analytics, cookies, missing consent banners, badly worded consent forms. Across its entire history, AKI has issued zero public fines for non-consenting analytics — unlike France’s CNIL, which ordered French sites off Google Analytics in 2022, or Austria’s DSB. That doesn’t mean Estonia tolerates anything — it means AKI prioritises leaks and abuse of sensitive data, not tracker questions.

Why AKI keeps losing in court

Of the major cases between 2023–2025, three have been definitively overturned: Asper Biogene, Pere Sihtkapital, and Viljandi haigla. In all three Riigikohus confirmed the outcome — either by deciding on the merits (Asper Biogene, Viljandi haigla) or by refusing AKI’s cassation appeal (Pere Sihtkapital, June 2025). Allium UPI is the only major case still pending.

This isn’t AKI doing a poor job — it’s a structural problem with Estonian law:

  • The quasi-criminal väärtegu construction is poorly suited for organisational GDPR violations.
  • The 1 November 2023 reform fixed part of the problem but does not apply retroactively — cases initiated before the reform (Pere Sihtkapital, Viljandi) run on the old rules and often fall on the fact that, at the time of the violation, no specific responsible person could be identified.
  • The 2-year statute of limitations (pre-reform) was already closing some cases on its own — Riigikohus, in Viljandi haigla, explicitly changed the basis to “limitation expired.”

Allium UPI is the first major case initiated after the reform. Its outcome is the real test of whether the new construction works in court. The decision will set the tone for the next 5–10 years in Estonia.

What this means if you run a business in Estonia

Don’t get comfortable just because the historic maximum is €3M, and even that is being contested. The trend is unambiguous: before 2023 there was nothing to fine with; after 2023 there is. Apotheka is the first such case, not the last. AKI now has the legal tool; the 2024 annual report and press release record 4,162 inquiries for 2024 and a clear shift toward harder responses to leaks.

What AKI catches most often is what you can avoid through pure engineering:

  • Customer-database leaks from weak protection — 2FA, key rotation, access monitoring, encrypted backups.
  • Processing of special categories (health, biometrics, genetics) without a separate legal basis and enhanced security.
  • Using data from state registers, loyalty programs, medical records “off-purpose” — Art. 5 (purpose limitation).
  • Appointing a DPO formally (board member, director, accountant) — without real independence and competence. This is a separate offence; in Asper Biogene it cost €5,000.
  • Employee access to data without a service need — uudishimupäring. Solved with logging and alerts, not stern words on the carpet.

What AKI almost never fines for — but this is no licence: analytics and cookies. That said, if you run Google Analytics with data transfers to the United States, formally you’re in the same category for which CNIL ordered French website operators to bring their setup into compliance in 2022 (CNIL orders to comply). AKI hasn’t pursued this — but noyb files complaints across Europe, and Estonian sites are already in their portfolio (noyb AKI).

Sources for independent verification

If you want to double-check or look for newer cases:

  • enforcementtracker.com — CMS Law’s registry of every GDPR fine in EU/EEA. Country filter → Estonia shows all Estonian entries. As of May 2026, two: ETid-2858 (Allium UPI) and ETid-2594 (Asper Biogene). The Pere Sihtkapital, Viljandi haigla and the uudishimupäring micro-fine cases above are not in this CMS registry — likely because they’re misdemeanour-procedure fines below the threshold the registry typically tracks for legal entities.
  • aki.ee/uudised — official AKI news in Estonian, with press releases on fines. The site is bot-protected; open it in a browser.
  • aastaraamat.aki.ee — AKI’s 2024 annual report with statistics and key court cases.
  • edpb.europa.eu/…/estonia — European Data Protection Board publications tagged Estonia.
  • Riigi Teataja, IKS — current text of the Estonian Personal Data Protection Act.
  • Postimees, ERR, Sakala — Estonian media systematically cover every new AKI fine and court decision.

Short conclusion

For 5+ years Estonia was the EU’s most lenient GDPR jurisdiction — not because AKI didn’t want to fine, but because the Penal Code didn’t let it fine legal entities. The reform of 1 November 2023 fixed that. Allium UPI €3M is the first case of the new era, and its outcome in Harju County Court will decide how serious fines get from here on.

If you build a product that processes user data, most cases above show that AKI fines you not for your choice of analytics tool, but for leaks, off-purpose processing, and a formal approach to the DPO. A privacy-by-design approach (data minimisation, no cookies and no fingerprinting, local geo lookup without sending IPs anywhere, short retention windows) takes you out of all three categories — not as a marketing claim, but as an engineering position.