The Swedish Authority for Privacy Protection (IMY) on October 1, 2026 made public a decision imposing an administrative fine of SEK 1.8 million on Miljödata i Karlskrona AB, an IT service provider, for breaching Article 32.1 of the General Data Protection Regulation (GDPR) during an August 2025 ransomware attack. According to IMY, the company failed to conduct adequate checks when installing new software and had no automated real-time monitoring of its systems, which left personal data that included health-related information within reach of a threat actor.
In Short
A Swedish software company that handles sick-leave and rehabilitation records for municipalities, regions and businesses was hacked in August 2025, and the country's privacy regulator has fined it SEK 1.8 million for not protecting that data well enough. About 2.2 million people were affected, according to the company, and the records included health-related details, so the case reaches employees, students and any organisation that passes personal data to an outside software supplier. The company can appeal within three weeks of receiving the decision, and the regulator is still reviewing two municipalities and one region over the same attack.
What happened inside Miljödata's systems
Miljödata supplies web-based services for managing sick leave, rehabilitation, incident reporting and work-environment work to private and public customers, according to the decision, which carries case number IMY-2025-21177 and is dated September 22, 2026. Most of the individuals registered in the services are employees of the company's customers. Miljödata notified IMY of a personal data incident on August 26, 2025, and the authority opened its supervision on that basis.
Three days without an alarm
IMY's account of the intrusion rests largely on what Miljödata itself reported. A ransomware attack began on August 20, 2025, when the threat actor carried out an SQL injection against a support component of a firewall product installed on one of the company's servers. IMY describes the method in a footnote as an intrusion technique that exploits a vulnerability in SQL, the programming language used to query and update relational databases. The injection opened the server; the attacker then escalated its privileges and gave itself the highest rights in the system.
During the night to August 23, several servers were encrypted and data was extracted. A technical alarm about errors in the services went off with IT operations that afternoon, and Miljödata began isolating all of its servers - about an hour after the discovery, according to the decision. On September 2, 2025, the company's own investigation found indications that data had been taken from the systems. On September 14, 2025, the attacker published parts of the leaked information, including personal data, on the Darknet.
The intruder therefore spent three days in the environment. According to IMY, the attacker could bypass virus detection, security monitoring and multi-factor authentication, grant itself high privileges on the server that hosted the vulnerable component, and move laterally between servers for several days without being noticed. All of this happened although Miljödata had two-factor authentication active on internal services and separate privilege accounts for different roles. The monitoring that existed was aimed mainly at performance and availability. It raised no alarm over suspicious activity from August 20 onward, and the endpoint detection and response (EDR) tool the company used proved insufficiently resilient. After the incident, Miljödata put EDR and security operations center (SOC) monitoring in place around the clock.
An outdated component, installed a week earlier
The support component was installed on the server roughly seven days before the incident, according to the decision. IMY found that the version supplied was outdated and contained a critical vulnerability that was already known, and that information about the flaw had been available on the vendor's website for more than a year before the installation. The decision does not name the vendor; it describes only a well-known supplier of such products.
Miljödata told the authority that it carried out the installation but never explicitly approved the installed version, and that it had no reason to suspect an outdated release because the item was an expensive product from a reputable supplier. The company has a process for installing and approving new components, run by a system administrator and covering needs analysis and an assessment of the effect on operations and security. According to Miljödata, however, nobody saw cause to verify that the expected version had arrived.
IMY reached a different conclusion. Checking that the right version was installed was a basic security measure, the authority found, and more so because the component sat on a server exposed to the internet and was new software that had not been tested in a separate environment before integration. By skipping the check, Miljödata installed a component carrying a critical vulnerability that the attacker later exploited.
The second failing concerned detection. IMY held that automatic real-time monitoring, able to identify suspicious activity and intrusion or attempted intrusion, was a basic measure given the risks of the processing. With such monitoring, the company would have had better conditions to spot the intrusion sooner and limit its reach, according to the authority.
Who and what was exposed
According to Miljödata, about 2,200,000 natural persons were registered in the services and covered by the incident, the decision states. The company has more than 300 customers across Sweden, a large share of them municipalities, regions and other public bodies. IMY's press release goes further: a majority of Sweden's municipalities, several regions and government agencies, and a large number of private companies are among the customers hit.
Each person's record held about 20 data points, among them name, contact details, personal identity number and employment and organisation information. The services also handled health data, notably sick-leave details, rehabilitation documentation and records of incidents involving students, along with personnel notes. Children appear to a limited extent, where they held a job with a customer or featured in registered student-incident cases. Some protected personal data was processed as well, even though the services were not meant to hold it.
Miljödata had encrypted attachments and free-text fields. IMY accepted that this limited the scope of the incident and the harm that registered individuals could suffer, but it declined to treat the encryption as proof that the data had been shielded from unauthorised access. Access to the information, the authority noted, made it possible to expose a large number of details about each person directly.
Why IMY held a processor responsible
Miljödata acts mainly as a data processor for its customers, the decision explains, with the customers as controllers. In a limited scope the company is itself a controller, for its own personnel and for some customer, system and supplier administration. Where services reach customers through third-party agreements with other vendors, Miljödata is a sub-processor. IMY did not work out which role applied to each activity, because Article 32 binds controllers and processors alike. It added that Miljödata designs and delivers the services and so had the practical ability to put protective measures in place.
Article 32.1 requires appropriate technical and organisational measures, weighing the state of the art, implementation costs, the nature, scope, context and purposes of the processing, and the risks to individuals. It lists examples: pseudonymisation and encryption, the ability to keep confidentiality, integrity, availability and resilience in place, the ability to restore access after an incident, and a process for regularly testing and evaluating the measures. IMY relied on the EU Court of Justice judgment of December 14, 2023 in case C-340/21, which it summarised as treating Article 32 as a risk-management system that does not demand the elimination of every incident; the test is tied to the concrete circumstances.
On those circumstances, the authority found that the processing demanded a high level of security. It cited the breadth of the data, the roughly 20 data points per person, the health information, the children and the personal identity numbers, which receive particular protection under Article 87 of the GDPR and the Swedish supplementary act (2018:218). Miljödata had taken a different view of the risk. According to the decision, the company rated the risks of the processing as low overall and the likelihood of a cyberattack as relatively low, partly because of its limited public profile, while judging the consequences of an attack as severe.
How the fine was calculated
The turnover basis
Under Article 83.4, a breach of Article 32 can draw a fine of up to EUR 10 million or, for an undertaking, up to 2 percent of total worldwide annual turnover of the preceding financial year, whichever is higher. IMY applied the EU competition-law concept of an undertaking. Miljödata's 2025 annual report shows that it is a wholly owned subsidiary of Persona Grata Informationssystem Aktiebolag. Under the Akzo principle from EU case law, 100 percent ownership creates a presumption that the parent exercises decisive influence, and nothing in the case rebutted it.
No consolidated group accounts had been drawn up, so IMY added the turnover of the two companies for the 2025 financial year. The parent reported SEK 0; Miljödata reported SEK 58,476,045. Two percent of that sum is SEK 1,169,521, which is below the static EUR 10 million ceiling, so the maximum fine available in the case was EUR 10 million, according to the decision.
The SEK 1.8 million actually imposed is higher than the two-percent figure and far below the ceiling. Set against the turnover IMY used, it works out to roughly 3.1 percent, and against 2.2 million affected individuals to less than one krona each. Both are calculations from the figures in the decision, not numbers IMY states.
Severity, negligence and the factors weighed
IMY classed the infringement as one of high severity, using the low, medium and high scale in the European Data Protection Board's Guidelines 04/2022. Beyond the scale and sensitivity of the data described above, it stressed that the breach touched the central processing of Miljödata's core business, where the company can be expected to have good conditions for putting appropriate safeguards in place. The authority added that the EU Court of Justice has recognised that damage can arise from the mere loss of control over personal data, even without proven misuse, and that the shortcomings made it easy for the attacker to reach and then publish data on the Darknet.
On culpability, IMY found negligence. The vulnerability information had been public for over a year, and both the version check and robust monitoring counted as basic measures. That Miljödata put automatic real-time monitoring in place a short time after the incident showed, in IMY's view, that the company had the ability to take such measures. A company can be fined for conduct it could not have been unaware of, the authority noted, whether or not it knew the conduct broke the rules, and it concluded that Miljödata could not have been unaware.
The weighing of mitigating and aggravating factors ran as follows:
- Measures taken before the incident, such as encrypting attachments and free-text fields, were judged not to go beyond what the processing called for.
- Measures taken afterward were not shown to have reduced the harm enough to count as mitigating.
- Self-reporting and cooperation with IMY did not count in the company's favour, and neither did its steps to let customers meet their own deadlines for notifying IMY.
- Information efforts did count, to some extent: individual meetings with several hundred controllers, a coordinating function towards Sveriges Kommuner och Regioner, with which most customers are affiliated, and several information meetings.
- IMY found no other aggravating or mitigating factors.
Miljödata's position
Miljödata told IMY that it did not consider that it had processed personal data in breach of the GDPR, according to the decision. It argued that the intrusion was a criminal act and not of high severity, that the incident did not stem from deliberate or negligent conduct, and that it had applied more extensive measures than the regulation requires. Registered individuals had suffered no concrete harm of significance, the company said, pointing out that no controller or data subject had made a specific claim against it. It added that it had reported the incident itself, cooperated throughout, had not been investigated under the GDPR before, and had faced significant costs from the incident. If any sanction was warranted at all, a reprimand would be the only effective, proportionate and dissuasive one, in the company's view.
IMY disagreed. It ruled that the infringement was not a minor one of the kind that can end in a reprimand under recital 148, and that the combination of high severity and the company's turnover supported a fine it assessed as effective, proportionate and dissuasive.
Why the case matters beyond Sweden's HR software market
The case has little to do with advertising on its face. Miljödata sells software for sick leave and work-environment management, not media or measurement. Yet Article 32 reaches every controller and processor that holds personal data, and IMY has applied it to a marketing-related practice before. In 2024, IMY fined the pharmacy companies Apoteket AB SEK 37 million and Apohem AB SEK 8 million under the same article for sending customer data to Meta through a tracking pixel. Apoteket reported 2023 turnover of SEK 23.27 billion, roughly 400 times the turnover IMY applied to Miljödata, though the years differ, and the estimate for Apoteket was up to 930,000 affected people, less than half of the 2.2 million at Miljödata. The two cases rest on different facts, but the gap in the amounts points to the weight that turnover carries in IMY's method alongside severity.
Three features of the Miljödata decision speak to supplier relationships of the kind that run through advertising and marketing technology. First, a company that mostly acts as a processor was held directly accountable under Article 32, without an activity-by-activity sorting of its roles. Second, IMY treated a purchased component from a known vendor as something the buyer was expected to verify, and it did not accept the product's price or the supplier's reputation as a reason to skip the check. Third, the categories of data attracted a higher security bar: health information, children's data and personal identity numbers pushed IMY's assessment of the necessary protection upward.
Fines remain the exception in European enforcement. About 1.3% of GDPR cases handled between 2018 and 2023 ended in a fine, according to European Data Protection Board figures that PPC Land analysed. IMY's own English-language news list for the topic also shows fines against Sportadmin on January 28, 2026 and against two companies in the SL Group on July 3, 2025; the attached documents give no details on either. Fines issued by the Swedish authority are open to judicial review, and a Stockholm court upheld IMY's SEK 58 million fine against Spotify on June 3, 2025, a transparency case rather than a security one.
Appeal route and open reviews
According to the decision, an appeal must reach IMY in writing within three weeks of the day the party received the decision. If it arrives in time, IMY forwards it to the Administrative Court in Stockholm (Förvaltningsrätten i Stockholm) for review. The attached documents do not say whether Miljödata has appealed or paid.
The decision is confined to Miljödata. It does not assess the position of the customers that used the services. IMY says only, in its press release, that it has initiated reviews of two municipalities and one region in connection with the attack and that these are ongoing; the documents do not name them.
IMY's Director-General, Eric Leijonram, who took the decision, framed the finding in these terms in the press release: "In this case, Miljödata has fallen short, resulting in a threat actor gaining access to data concerning a significant portion of Sweden's population." He added: "We take this incident very seriously. My hope is that other organizations also take note of this decision and, where necessary, review the security of the personal data they are responsible for."
Timeline
- 2018 to 2023: About 1.3% of GDPR cases handled by European authorities ended in a fine.
- Beginning of 2024: The component vendor publishes information about the vulnerability on its website, according to the decision.
- August 30, 2024: IMY's decision fining Apoteket AB SEK 37 million and Apohem AB SEK 8 million under Article 32 is made public.
- June 3, 2025: A Stockholm court upholds IMY's SEK 58 million fine against Spotify.
- About a week before August 20, 2025: The support component is installed on a Miljödata server.
- August 20, 2025: The ransomware attack begins with an SQL injection.
- Night to August 23, 2025: Several servers are encrypted and data is extracted.
- August 23, 2025: A technical alarm about service errors leads to discovery of the intrusion, and servers are isolated about an hour later.
- August 26, 2025: Miljödata notifies IMY of the personal data incident.
- September 2, 2025: Miljödata finds indications that data was extracted.
- September 14, 2025: The attacker publishes parts of the leaked information on the Darknet.
- September 22, 2026: IMY issues decision IMY-2025-21177 with a SEK 1.8 million fine.
- October 1, 2026: IMY publishes its English press release on the fine.
- Ongoing: IMY reviews of two municipalities and one region.
Related PPC Land coverage
- Swedish DPA fines Apoteket and Apohem for transferring sensitive data to Meta - Covers IMY's 2024 Article 32 decision against two pharmacy companies, with fines tied to turnover and severity.
- GDPR enforcement data shows low fine rates across European authorities - Analyses European Data Protection Board figures showing that about 1.3% of cases between 2018 and 2023 ended in fines.
- Stockholm court upholds Spotify's fine for data transparency failures - Reports on the June 2025 court ruling that confirmed an IMY fine against Spotify.
Summary
- Who: The Swedish Authority for Privacy Protection (IMY) and Miljödata i Karlskrona AB, a wholly owned subsidiary of Persona Grata Informationssystem Aktiebolag, whose services registered about 2.2 million individuals, according to the company.
- What: IMY imposed an administrative fine of SEK 1.8 million for violating Article 32.1 of the GDPR, finding that Miljödata skipped a version check on a security component and lacked automated real-time monitoring; reviews of two municipalities and one region continue.
- When: The attack ran from August 20 to August 23, 2025; Miljödata notified IMY on August 26, 2025; the decision is dated September 22, 2026 and was published on October 1, 2026.
- Where: Sweden, with Miljödata's more than 300 customers spread across the country; an appeal would go through IMY to the Administrative Court in Stockholm.
- Why: IMY concluded that the processing required a high level of security, that Miljödata acted negligently, and that a fine was the effective, proportionate and dissuasive response to an infringement of high severity.
Discussion