Swedish DPA fines Miljödata EUR 160,000 for insufficient technical and organisational security measures
Original title: Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security
Swedish DPA (IMY) fined Miljödata SEK 1,800,000 (approximately EUR 160,000) for violating Article 32(1) GDPR following a cyberattack in August 2025 that compromised personal data of 2.2 million individuals. The company failed to maintain sufficiently high levels of technical and organisational security, lacked adequate software installation checks, and had no automated real-time system monitoring. Organisations processing personal data must implement robust security measures proportionate to the sensitivity of data processed, including real-time intrusion detection and rigorous software vetting procedures to prevent unauthorised access and data breaches.
What changed
- Swedish DPA (IMY) imposed an administrative fine of SEK 1,800,000 (approximately EUR 160,000) on Miljödata i Karlskrona for violations of Article 32(1) GDPR regarding insufficient technical and organisational security measures
- Miljödata failed to conduct adequate checks and security controls when installing new software, which contributed to the cyberattack vulnerability
- The company did not have automated real-time monitoring systems to detect intrusions or suspicious activity on its networks
- The DPA determined that Miljödata acted negligently in maintaining security standards for processing sensitive personal data including identity numbers, contact details, and data related to sick leave and student incidents
Who is affected
IT service providers, cloud service providers, and organisations processing sensitive personal data on behalf of public sector entities (municipalities, regions, government agencies) and private companies in the EU
Summary generated by a language model; the official text prevails. Not legal advice.