Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

  • National News
  • se

Background information

  • Date of final decision: 22/09/2026
  • National case
  • Legal Reference(s): Article 32 (Security of processing)
  • Decision: Administrative fine
  • Website topics: Cybersecurity, personal data breaches

Summary of the Decision

Origin of the case

In August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a malicious actor gained access to a large volume of personal data and subsequently published data on the darknet. According to the company, the incident affected 2.2 million individuals. Among Miljödata’s customers affected by the attack are a majority of Sweden’s municipalities, several regions, and government agencies, as well as a large number of private companies. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.

Key Findings

The review shows that the company did not maintain a sufficiently high level of technical and organizational security, given the types of personal data it processed. Miljödata failed to conduct adequate checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions or suspicious activity.

Decision

IMY, the Swedish Data Protection Authority, assesses that Miljödata acted negligently and has therefore decided to impose an administrative fine of SEK 1 800 000 (approximately EUR 160 000) for violating Article 32(1) GDPR.

For further information: 

 

Relevant topics
Cybersecurity
Personal data breaches

Latest news

  • National News
  • nl

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

  • National News

Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs

  • National News
  • ie

The Irish Data Protection Commission fines Google EUR 403 000 000 following Inquiry into Google’s processing of location data