Regulatory Watch  /  Sweden  /  Fine
Moderate impactFineDecided

Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures

The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate technical and organisational safeguards, including real‑time intrusion monitoring, after a cyberattack exposed data of 2.2 million individuals.

Why it matters: The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security
European Data Protection Board news · primary source · Oct 8, 2026
Details
JurisdictionSweden
RegulatorSwedish Data Protection Authority (IMY)
LawGeneral Data Protection Regulation
StatusDecided
PublishedOctober 8, 2026
Effectivenot stated
DecisionSeptember 22, 2026
Penaltyadministrative fine of SEK 1 800 000 (approximately EUR 160 000)
OrganisationsMiljödata i Karlskrona
Topicssecurity, breach notification
Datapersonal, sensitive