Skip to content
News · European Data Protection Board EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

Full text

Background informationDate of final decision: 22/09/2026National caseLegal Reference(s): Article 32 (Security of processing)Decision: Administrative fineWebsite topics: Cybersecurity, personal data breachesSummary of the DecisionOrigin of the caseIn August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a malicious actor gained access to a large volume of personal data and subsequently published data on the darknet. According to the company, the incident affected 2.2 million individuals. Among Miljödata’s customers affected by the attack are a majority of Sweden’s municipalities, several regions, and government agencies, as well as a large number of private companies. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.Key FindingsThe review shows that the company did not maintain a sufficiently high level of technical and organiza

How it connects