The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate technical and organisational safeguards, including real‑time intrusion monitoring, after a cyberattack exposed data of 2.2 million individuals.
Why it matters: The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.