Back to Feed
GDPROct 8, 2026

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

Swedish DPA fines Miljödata EUR 160K for insufficient security measures after 2.2M-person breach

Summary

Sweden's Data Protection Authority (IMY) has fined IT service provider Miljödata i Karlskrona approximately EUR 160,000 (SEK 1.8M) for violating GDPR Article 32 following a cyberattack in August 2025. The attack compromised personal data of 2.2 million individuals, including employees of Swedish municipalities, regions, government agencies, and private companies. The DPA found that Miljödata failed to maintain adequate technical and organizational security measures, including insufficient software installation checks and lack of real-time automated monitoring to detect intrusions.

Full text

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security National News 08 October 2026 se Background informationDate of final decision: 22/09/2026National caseLegal Reference(s): Article 32 (Security of processing)Decision: Administrative fineWebsite topics: Cybersecurity, personal data breachesSummary of the DecisionOrigin of the caseIn August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a malicious actor gained access to a large volume of personal data and subsequently published data on the darknet. According to the company, the incident affected 2.2 million individuals. Among Miljödata’s customers affected by the attack are a majority of Sweden’s municipalities, several regions, and government agencies, as well as a large number of private companies. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.Key FindingsThe review shows that the company did not maintain a sufficiently high level of technical and organizational security, given the types of personal data it processed. Miljödata failed to conduct adequate checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions or suspicious activity.DecisionIMY, the Swedish Data Protection Authority, assesses that Miljödata acted negligently and has therefore decided to impose an administrative fine of SEK 1 800 000 (approximately EUR 160 000) for violating Article 32(1) GDPR.For further information: Administrative Fine against Miljödata Relevant topics Cybersecurity Personal data breaches Latest news RSS Feed National News nl Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling08 October 2026 National News gr Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs08 October 2026 National News ie The Irish Data Protection Commission fines Google EUR 403 000 000 following Inquiry into Google’s processing of location data23 September 2026All news

Entities

Miljödata i Karlskrona (vendor)IMY (Swedish Data Protection Authority) (vendor)