Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security
Full text
Background informationDate of final decision: 22/09/2026National caseLegal Reference(s): Article 32 (Security of processing)Decision: Administrative fineWebsite topics: Cybersecurity, personal data breachesSummary of the DecisionOrigin of the caseIn August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a malicious actor gained access to a large volume of personal data and subsequently published data on the darknet. According to the company, the incident affected 2.2 million individuals. Among Miljödata’s customers affected by the attack are a majority of Sweden’s municipalities, several regions, and government agencies, as well as a large number of private companies. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.Key FindingsThe review shows that the company did not maintain a sufficiently high level of technical and organiza