Skip to content
Content type · 51 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Sweden (50) Clear filter
1–50 of 51 sort newestlargest fineoldest
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Supervisory Authorities Information Provision Modalities and Communication Methods Jul 3, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·IMY ·Art. 32 Security Personal Data Controllers Jan 26, 2026
€6,800 AB Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on AB Storstockholms Lokaltrafik. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN ·IMY ·Art. 6, 9 Controllers Processing Processing Agreement Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on Waxholms Ångfartygs AB. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN ·IMY ·Art. 6, 9 Controllers Processing Supervisory Authorities Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 6, 9 Processing Personal Data Controllers Jun 18, 2025
€6,800 AB Storstockholms Lokaltrafik: Onvoldoende juridische basis voor de verwerking van gegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 6, 9 Types of Special Categories of Personal Data Processing Supervisory Authorities Jun 18, 2025
€9,200 Discriminatiecommissarissen: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 9.200 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·IMY ·Art. 6, 13 Controllers Personal Data Supervisory Authorities Dec 11, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€26,500 Östersund Municipality's Department for Children and Education: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 26,500 on the Östersund Municipality's Department for Children and Education. The authority had failed to carry out a data protection… SWEDEN ·Art. 35 ·Insufficient technical and organisational measures to ensure information security DPIA Supervisory Authorities Security Nov 28, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 7, 2023
€30,000 H&M Hennes & Mauritz GBC AB: Insufficient fulfilment of data subjects rights The Swedish DPA has imposed a fine of EUR 30,000 on H&M for sending out marketing messages, despite the fact that data subjects had exercised their right to objection. Six data… SWEDEN ·Art. 12, 21 ·Insufficient fulfilment of data subjects rights Right to Object Direct Marketing Personal Data Oct 17, 2023
€70,000 Schockholm School borard: Non-compliance with general data processing principles The Swedish DPA has fined the Stockholm School Board EUR 70,000 for excessive video surveillance in a school. A school had installed extensive video surveillance due to past… SWEDEN ·IMY ·Art. 5, 6, 13 Supervisory Authorities Processing Video Surveillance Oct 3, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Personal Data Identification Aug 28, 2023
€1M Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€1.1M Bonnier News AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 1.1 million on Bonnier News AB. During its investigation, the DPA found that Bonnier News collects customer data, for example, through… SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Consent Personal Data Marketing Jun 26, 2023
€4.9M Spotify: Insufficient fulfilment of data subjects rights The Swedish Data Protection Authority (DPA) has imposed a fine of EUR 4.9 million on the music streaming provider Spotify. The DPA had launched an investigation after receiving a… SWEDEN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities International Transfer Jun 12, 2023
€17,600 Skåne region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has fined Skåne region EUR 17,600. An employee of the region had lost an unencrypted USB stick containing the social security numbers and sensitive personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Encryption Personal Data Apr 26, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·IMY ·Art. 32 Security Personal Data Privacy by Design & Default Jan 17, 2023
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Personal Data International Transfer Supervisory Authorities Mar 28, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·IMY ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 26, 2022
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·IMY ·Art. 5, 6, 13 Retention Period Identification Fairness & Transparency Jun 21, 2021
€34,800 Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra… SWEDEN ·IMY ·Art. 5, 32 Controllers Processing Video Surveillance Jun 9, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13, 14 Supervisory Authorities Personal Data Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Encryption Personal Data Jun 7, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€29,500 Uppsalahem AB: Insufficient legal basis for data processing The Swedish DPA (Integritetsskyddsmyndigheten) fined the housing company Uppsalahem AB SEK 300,000 (EUR 29,500). The housing company had installed surveillance cameras in an… SWEDEN ·IMY ·Art. 5, 6 Legitimate Interest Processing Security Dec 15, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·IMY ·Art. 5, 32 Security Encryption Controllers Dec 11, 2020
€1.2M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 12,000,000 (EUR 1,168,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€1.5M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 15,000,000 (EUR 1,463,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€243,800 Östergötland Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Östergötland Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€390,100 Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Karolinska University Hospital of Solna SEK 4,000,000 (EUR 390,100) for failing to implement adequate technical and… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Education Dec 3, 2020
€341,300 Sahlgrenska University Hospital: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Sahlgrenska University Hospital SEK 3,500,000 (EUR 341,300) for failing to implement adequate technical and organizational… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€2.9M Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Capio St. Göran AB SEK 30,000,000 (EUR 2,900,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€243,800 Västerbotten Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Västerbotten Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·IMY ·Art. 5, 6, 13 +2 Monitoring Supervisory Authorities Processing Nov 25, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN ·IMY ·Art. 5, 32 Security Data Breaches Education Nov 24, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·IMY ·Art. 5, 6 Processing Video Surveillance Monitoring Jun 16, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·IMY ·Art. 5, 6 Personal Data Processing Public Authority May 12, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·IMY ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€5M Google LLC: Insufficient fulfilment of data subjects rights Original Fine Summary: The Swedish data protection authority has fined Google LLC € 7 million for failing to adequately comply with its obligations regarding the right of data… SWEDEN ·IMY ·Art. 5, 6, 17 Personal Data Supervisory Authorities Telecommunications Mar 11, 2020
€35,000 Nusvar AB: Insufficient legal basis for data processing Nusvar AB, operator of the website Mrkoll.se, which provides information on all Swedes over 16 years of age, had published information on people who are overdue. SWEDEN ·IMY ·Art. 6 Processing Supervisory Authorities Dec 16, 2019