Sweden's data protection authority IMY fined the IT provider Miljödata i Karlskrona SEK 1,800,000 (approximately EUR 160,000) on September 22, 2026 for violating Article 32(1) GDPR, with the decision published on October 8, 2026. The fine follows an August 2025 cyberattack in which a malicious actor exfiltrated and published on the darknet personal data of 2.2 million individuals across Sweden's municipalities, regions, agencies and private companies.

EU IT service providers, managed-service providers, SaaS and cloud platforms, and other data processors handling personal data at scale must immediately verify their own Article 32(1) GDPR technical and organisational measures, above all software-change verification and real-time intrusion monitoring, or face the same fine regime: up to EUR 10 million or 2 percent of worldwide annual turnover under Article 83(4) GDPR.

  • Authority : IMY (Integritetsskyddsmyndigheten, the Swedish Data Protection Authority)
  • Entity : Miljödata i Karlskrona, IT service provider and data processor for Swedish public-sector bodies
  • Measure and amount : administrative fine of SEK 1,800,000 (approximately EUR 160,000)
  • Legal basis : Article 32(1) GDPR (security of processing); fine under Article 83(4) GDPR
  • Decision date : September 22, 2026 (published October 8, 2026)
  • Official source : IMY, Administrative Fine against Miljödata

What happened

IMY's review found that Miljödata's security was not proportionate to the personal data it processed for Swedish public-sector and private customers. The compromised records included personal identity numbers, contact details, and sensitive data on sick leave, rehabilitation, and school incidents.

IMY concluded that Miljödata acted negligently and imposed the administrative fine. The case was published as national news by the European Data Protection Board on October 8, 2026.

The breach

IMY held that Miljödata's technical and organisational security was not proportionate to the personal data it processed. Two failings drove the decision: the company ran inadequate checks when installing new software, and had no automated real-time monitoring to detect intrusions or suspicious activity.

The provision enforced is Article 32(1) GDPR, which requires technical and organisational measures appropriate to the risk. The fine is set under Article 83(4) GDPR, capped at EUR 10 million or 2 percent of worldwide annual turnover.

Who else is in the same regime

Article 32 GDPR binds every controller and processor in the EU, and a national DPA's decision is a direct signal to the whole processor market. The same standard applies to EU IT service providers and managed-service providers processing large volumes of personal data, Swedish public-sector IT providers and municipal data processors, and EU SaaS and cloud providers holding bulk or special-category data, plus their sub-processors.

Miljödata is the sanctioned entity, not the audience. Any EU processor holding bulk or special-category data such as health, rehabilitation or student records faces the same standard: Article 32(1) demands measures proportionate to the data's volume and sensitivity.

What to check now

  • Verify software-change verification controls: confirm adequate checks run when installing or updating software, the specific gap IMY identified.
  • Deploy or test automated real-time monitoring to detect intrusions and suspicious activity across systems holding personal data, the second specific gap IMY identified.
  • Re-assess Article 32(1) GDPR measures against the volume and sensitivity of personal data you process; IMY held the bar rises with bulk and special-category data.
  • Review access management, logging and network segregation for systems processing bulk or special-category personal data such as health, rehabilitation and student records.
  • Document the security measures and their review cycle so the processor can evidence Article 32(1) compliance on demand to its competent supervisory authority.

Continuous per-jurisdiction monitoring surfaces processor-security enforcement the moment a DPA publishes it.

Live
EU: GDPR enforcement decisions relayed by the EDPB (national DPA fines and EDPB binding decisions)
Monitor GDPR ENFORCEMENT DECISIONS against companies across the European Union, as published by the European Data Protection Board (EDPB), for the AI, data and digital governance industry (GDPR, one-stop-shop cross-borde
Email 40+ news

Sources