Sweden’s data protection authority, IMY, has fined IT systems provider Miljödata $183,000 for failing to implement adequate security measures that led to a breach in August 2025. The incident exposed personal data of approximately 2.2 million individuals, prompting regulatory action under the country’s strict privacy laws. The fine, equivalent to 1.8 million Swedish kronor, reflects the scale of the failure and the sensitivity of the information involved.
Miljödata provides software solutions used by various public and private sector organizations across Sweden. The breach occurred due to insufficient safeguards in its IT infrastructure, allowing unauthorized access to systems containing personal identifiers such as names, addresses, and social security numbers. IMY determined that the company did not conduct proper risk assessments or maintain updated security protocols, despite known vulnerabilities in its environment. The regulator emphasized that data controllers and processors must ensure technical and organizational measures align with the General Data Protection Regulation, which applies in Sweden through national legislation.
Investigations revealed that the intrusion began in early August 2025 but was not identified until weeks later, allowing prolonged access to sensitive databases. Miljödata lacked real-time monitoring tools and failed to respond to anomalous activity alerts that could have triggered an earlier shutdown. IMY noted that the absence of intrusion detection systems and inadequate logging practices significantly delayed containment. The authority stated that timely detection is a fundamental requirement under data protection law, and the company’s oversight directly contributed to the extent of exposure.
Following the fine, Miljödata has committed to overhauling its security framework, including hiring external cybersecurity experts to audit its systems and implement multi-factor authentication across all access points. The company said it is also upgrading its incident response plan and increasing staff training on data protection obligations. IMY will monitor compliance through scheduled reviews and may impose additional penalties if improvements are not met within the specified timeline. Experts warn that similar failures could lead to higher fines under upcoming revisions to Sweden’s data protection act.
What type of data was exposed in the breach? The breach exposed personal data including names, addresses, phone numbers, and social security numbers of approximately 2.2 million individuals. No financial or health information was reportedly compromised in this incident.
Can affected individuals claim compensation for the breach? Under Swedish data protection law, individuals may seek compensation for material or non-material damage resulting from a breach. Claims must be filed through civil courts, and IMY’s fine does not automatically grant compensation to victims.
Is Miljödata allowed to continue operating after the fine? Yes, the company remains operational but is under regulatory supervision. IMY has required specific corrective actions, and continued non-compliance could lead to stricter sanctions, including processing restrictions or higher fines.