Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Legal Update European Union Rules in force

Swedish DPA Fines IT Provider Miljödata EUR 160 000 Over Insufficient Data Security Measures

The Swedish DPA fined IT provider Miljödata approximately EUR 160 000 for failing to maintain adequate system security and intrusion monitoring following a major cyberattack.

What Changed

  • An August 2025 cyberattack on IT service provider Miljödata led to the publication of sensitive personal data belonging to 2.2 million individuals on the darknet.
  • The Swedish DPA found Miljödata negligent due to inadequate software installation checks and a lack of automated real-time intrusion monitoring.
  • IMY fined Miljödata SEK 1 800 000 (approx. EUR 160 000) for breaching Article 32(1) of the GDPR.

Organisations utilizing third-party IT service providers face significant compliance and security risks when vendor safeguards fail. In a final decision dated 22/09/2026, the Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1 800 000 (approximately EUR 160 000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) of the General Data Protection Regulation (GDPR). The enforcement action stems from a cyberattack in August 2025, during which a malicious actor gained unauthorized access to systems processing extensive personal data and subsequently published the stolen data on the darknet. According to Miljödata, the security incident impacted 2.2 million individuals. Affected customers include a majority of Sweden’s municipalities, several regions, government agencies, and a substantial number of private companies.

The compromised data comprised personal identity numbers, contact details, and sensitive information concerning sick leave, rehabilitation, and student-related incidents in schools. Following a review of the incident, IMY concluded that Miljödata failed to maintain an adequate level of technical and organizational security commensurate with the risks and sensitive nature of the personal data processed. Specifically, the regulatory authority determined that the company did not perform adequate security checks when installing new software and lacked automated real-time monitoring capabilities necessary to detect intrusions or suspicious system activity.

Assessing Miljödata’s failures as negligent, IMY issued the fine under Article 32(1) GDPR, which mandates appropriate security measures to ensure data confidentiality, integrity, and resilience. This enforcement action highlights the rigorous standard of care expected from IT service providers and data processors handling high-risk personal data across public and private sectors in the European Union.

Who May Be Affected

IT service providers, Swedish municipalities, regional authorities, government agencies, private companies, and the 2.2 million individuals whose personal data was compromised.

Cross-Border Context

Reflects standard EU GDPR enforcement actions under Article 32 regarding data processor obligations and cybersecurity safeguards.

What to check next

  • Full text of the Swedish Data Protection Authority (IMY) decision dated 22/09/2026.
  • Guidance from the EDPB and national DPAs on real-time intrusion detection and software installation security checks.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.