Swedish IT Provider Miljödata Fined $183,000 for GDPR Violations After Major Data Breach
Sweden's data privacy regulator, **IMY**, has levied a significant fine against IT systems provider **Miljödata** for failing to uphold adequate security standards. The penalty follows a major cyberattack in August 2025 that compromised the sensitive data of 2.2 million individuals, highlighting critical shortcomings in the company's security posture under **GDPR** regulations.

The **Swedish Authority for Privacy Protection (IMY)** has announced a fine of SEK 1.8 million (approximately $183,000 USD) against **Miljödata**, a key software provider for Sweden's municipal systems. The fine stems from a data breach in August 2025 that exposed the personal information of 2.2 million citizens.
### The Breach and its Impact
**Miljödata** specializes in developing and providing work environment and HR management systems, serving an estimated 80% of Sweden's municipal systems. On August 25, 2025, the company suffered a cyberattack that not only disrupted IT services across over 200 regions but also led to the compromise of sensitive resident data.
The threat actor, operating under the name “Datacarry,” demanded a ransom of 1.5 **Bitcoin** (valued at $168,000 at the time) to prevent the publication of the stolen information. Despite the demand, the data was subsequently leaked on the dark web.
### Exposed Sensitive Data
The compromised information was extensive and highly sensitive, including personal identity numbers, contact details, sickness absence records, rehabilitation information, and even details of school incidents involving underage individuals.
### IMY's Investigation and Findings
**IMY** launched an investigation in November 2025 to determine if **Miljödata** had violated its obligations under the **European Union’s General Data Protection Regulation (GDPR)**. The investigation concluded that the company's security measures were severely lacking.
Specifically, **IMY** found that **Miljödata** failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms essential for detecting intrusions and suspicious activity within its systems.
"**IMY**’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed," stated the regulator in its announcement. "The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity."
### GDPR Violation and Ongoing Investigations
These failures were deemed a clear violation of **Article 32(1) of the GDPR**, which mandates appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The $183,000 penalty reflects the gravity of these lapses.
**IMY** also noted that it has initiated separate investigations into two municipalities and one region connected to the **Miljödata** attack. These ongoing inquiries could potentially lead to additional penalties, underscoring the cascading accountability in data protection incidents.