Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Privacy

Sweden fines Miljödata over breach of 2.2 million people

IMY fined the HR software supplier SEK 1.8 million after a 2025 attack exposed sick leave, rehabilitation and school incident data.

By · Published · Updated · 4 min read

Sweden fines Miljödata over breach of 2.2 million people

Sweden's privacy regulator IMY has fined HR software supplier Miljödata SEK 1.8 million (about $183,000) over a 2025 cyberattack that exposed data on 2.2 million people, SafeState reports.

What was exposed

Data processed for employers and public bodies, including:

  • National identity numbers
  • Sick leave details
  • Rehabilitation cases
  • Incidents involving school pupils

What IMY found

  • Miljödata did not run adequate checks when installing new software.
  • It had no automated, real-time monitoring to detect intrusions.

IMY ruled this breached Article 32(1) of the GDPR and that the company acted negligently. It is still examining the public bodies that used Miljödata's systems, so more penalties are possible.

Is the fine too small?

As P.K. Sharma points out, it works out at about six pence per person — but measured against Miljödata's 2025 turnover of about SEK 58 million, it is a significant share of revenue.

Why it matters

A single software supplier's weakness exposed data on roughly a fifth of Sweden's population. Organizations are responsible for checking the security of the vendors they hand data to.

Sources

Read next