Sweden fines Miljödata SEK 1.8m over mass data breach
Sweden’s privacy regulator has fined the systems supplier Miljödata SEK 1.8 million after a 2025 intrusion exposed data on 2.2 million people, ruling that the company’s security fell short of GDPR Article 32.1.

Sweden’s data protection authority has fined the systems supplier Miljödata SEK 1.8 million over the 2025 intrusion that exposed the personal records of 2.2 million people, ruling that the company’s security was not good enough for the information it held. Integritetsskyddsmyndigheten (IMY) announced the sanction on 22 September, saying Miljödata had acted negligently.
Miljödata i Karlskrona AB supplies HR and work-environment software to much of Sweden’s public sector. In August 2025 a threat actor got into its systems, took a large volume of personal data and published it on the darknet. The company put the number of people affected at 2.2 million.
What IMY found
The regulator’s investigation concluded that Miljödata’s technical and organisational security was not high enough for the categories of data it processed. IMY singled out two failures: the company did not carry out sufficient checks when it installed new software, and it had no automatic, real-time monitoring of its systems that would have caught an intrusion or suspicious activity while it was happening.
The exposed records included personal identity numbers and contact details, alongside sensitive information about sick leave, rehabilitation and incidents involving pupils in schools. Because that material carries a high risk for the people in it, IMY assessed the shortfall as an infringement of Article 32.1 of the GDPR and issued a sanction of SEK 1.8 million.
Who was caught up in it
Miljödata’s customer list is effectively a map of Swedish public services. A majority of the country’s municipalities were affected, along with several regions, state agencies and a large number of private companies. IMY has opened separate investigations into two municipalities and one region in connection with the same incident, and those inquiries are still running.
Eric Leijonram, IMY’s director-general, said the law sets a clear expectation on anyone holding this kind of data. "GDPR requires appropriate security measures for the personal data you handle," he said in the regulator’s announcement. "Miljödata fell short here, and the result is that a threat actor got hold of data on a large part of Sweden’s population. We take what happened seriously, and my hope is that other organisations take the decision on board and review the security of the personal data they are responsible for."
Our opinion
The number that should worry Swedish public services is not the 1.8 million kronor — it is the 2.2 million people, in a country of roughly 10.6 million. A single supplier sitting underneath municipal HR systems turned one compromised network into a national exposure of identity numbers and rehabilitation records, which is exactly the concentration risk that GDPR’s processor rules exist to surface. The specific findings read like a procurement problem as much as a technical one: nobody verified software before it was installed, and nothing was watching the systems in real time. Buying security tooling is the easy half. The harder half is that every municipality and region now has to ask whether it can name the checks it runs on a supplier before signing, and whether that supplier is obliged to prove them afterwards. On this evidence, most of them cannot.