Sweden's IMY fined software vendor Miljödata SEK 1.8m for a breach affecting 2.2 million people. Why the processor was fined, and what the GDPR asks of vendors.
11 min read
On 22 September 2026, Sweden's data protection authority, the IMY, fined the software company Miljödata SEK 1.8 million (about USD 183,000) over the ransomware attack that exposed the personal data of 2.2 million people in August 2025, as BleepingComputer reported the same day (MLex also covered it for subscribers). Miljödata supplies the systems that a majority of Swedish municipalities, several regions, government agencies and a large number of private employers use to manage sick leave, rehabilitation and workplace incidents. In GDPR terms it acted mainly as a processor: it handled the data on behalf of its customers, who are the controllers.
That is what makes the case worth reading closely. Regulators have fined processors before, though far less often than controllers. Here the IMY went straight to the company that ran the systems while opening separate investigations into two municipalities and one region. The IMY's press release and its 17-page decision set out the reasoning. They also answer a question that reaches well beyond Sweden: when a vendor is breached, who answers for what, and how is the fine calculated?
The decision reconstructs the attack from Miljödata's own forensic account, which the IMY saw no reason to doubt:
The records held around twenty data points per person: personal identity numbers, contact details, employment data and absence records. The services also contained health data on sick leave and rehabilitation, staff notes and protected personal data. To a limited extent they also held information about children who worked for a customer or appeared in records of school incidents. Miljödata had encrypted attachments and free-text fields. The IMY accepted that this reduced the risk of harm to some degree, and held that it did not shield the data from the access that took place. In the weeks after the attack the IMY received more than 500 breach notifications from organisations naming Miljödata as their processor, and some seventy complaints from affected people.
Article 32(1) GDPR requires both the controller and the processor to put in place technical and organisational measures that ensure a level of security appropriate to the risk. The IMY first measured the risk: health data, children's data and identity numbers on 2.2 million people, across more than 300 customers. That called for a high level of security. It then identified two failures.
The first was the firewall component. Picture a new lock fitted to the front door. The manufacturer had described the model's flaw on its own website more than a year earlier, and the person who installed it never checked the model number. The supplier had shipped Miljödata an outdated version with a known critical vulnerability. Miljödata told the IMY it had no reason to suspect anything, since the product was expensive and came from a well-known supplier, a point SVT highlighted in its coverage. The IMY's view was that checking you have received the right version is a basic security measure. That holds all the more for new software placed on an internet-facing server with no prior run in a test environment.
The second was detection. Miljödata's monitoring behaved more like a gauge on a boiler than a smoke detector: it reported whether the systems were running and raised the alarm when they stopped. For three days the attacker got past virus detection, security monitoring and multi-factor authentication and moved from server to server. The IMY found the monitoring had been aimed mainly at performance and availability. Given the risk, it held that automated real-time monitoring for suspicious activity was a basic measure, and earlier detection would have limited what the attacker could take. Miljödata introduced round-the-clock EDR and SOC monitoring shortly after the incident, which the IMY read as evidence that the measure had been within reach.
One line in the file deserves attention. Miljödata's own threat analysis had rated the likelihood of a cyber attack as relatively low, partly because of the company's limited public profile. The same analysis rated the consequences for the people in its systems as severe. The IMY's Director-General, Eric Leijonram, said the failure allowed a threat actor to obtain data on a large part of Sweden's population, as reported by Ny Teknik. Miljödata maintains that it did not infringe the GDPR, and the decision can be appealed within three weeks to the Administrative Court in Stockholm.
Yes. A processor is any person or body that processes personal data on behalf of a controller (Article 4(8)). The security duty in Article 32 names both. Article 83(4)(a) sets fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher, for breaches of the obligations of the controller and the processor under Articles 25 to 39.
Think of a municipality's HR files stored in a hired archive. The municipality decides what goes into the boxes, why, for how long and who may open them. The archive company decides how the building is locked and watched. Article 32 speaks to both. The archive answers for its locks. The municipality answers for having chosen that archive and for checking, at intervals, that the locks still work.
The Miljödata decision shows how directly this operates. Miljödata acted mainly as a processor, as a sub-processor where it served customers through other suppliers, and as a controller for a limited set of activities. The IMY declined to assign a role to each activity: since Article 32 binds controllers and processors alike, the answer would not change the infringement.
Processor fines remain the minority, and they are no longer isolated:
Each answers for its own part.
Compensation follows its own logic. Under Article 82(2), a controller is liable for damage caused by processing that infringes the GDPR. A processor is liable only where it breached obligations addressed specifically to processors, or acted outside or against the controller's lawful instructions. The gate is narrow, and Article 32 sits inside it, because the security duty is addressed to processors expressly. Where both are responsible for the same damage, each is liable for all of it towards the person affected (Article 82(4)), and whoever pays can recover the other's share (Article 82(5)).
The Court of Justice has shaped how these claims run. In Natsionalna agentsia za prihodite (C-340/21) it held that:
The IMY relied on the same line of case law to reject Miljödata's argument that nobody had suffered concrete harm: losing control over one's data is already damage.
Choosing a processor is itself an act of the controller, and so is keeping an eye on it. The EDPB's Guidelines 07/2020 on controllers and processors say the controller must assess whether a processor's guarantees are sufficient and be able to prove it did so. They describe that duty as continuing. It does not end when the contract is signed, and the controller should verify the guarantees at appropriate intervals, through audits and inspections where appropriate. The guidelines even use the example of a municipality relying on a standardised cloud service, and conclude that the standard nature of the offer leaves the municipality's obligations intact.
That is the ground the IMY is now examining in two municipalities and one region. One of them is the City of Gothenburg. The IMY's letter to the city states that the authority is reviewing whether the city took appropriate measures under Article 32. The outcomes are pending, and nothing in the Miljödata decision anticipates them. Whether and how far public bodies can be fined at all is for each Member State to settle in its own law (Article 83(7)).
On paper, the controller's duty becomes provable through three things:
Building that map, supplier by supplier, is the core of a GDPR product audit.
The decision is unusually open about the fine. The IMY followed the five-step method in the EDPB's Guidelines 04/2022 on the calculation of administrative fines.
The legal maximum. Miljödata is wholly owned by Persona Grata Informationssystem AB. Under the Akzo presumption from EU competition law, a parent holding 100% of a subsidiary is presumed to exercise decisive influence over it, so the two count as a single undertaking. The parent reported zero turnover for 2025 and Miljödata SEK 58,476,045. Two per cent of that is SEK 1,169,521. Because the GDPR applies whichever cap is higher, the ceiling was €10 million. For a company of this size the percentage cap is a trapdoor that never opens and the fixed figure is the real limit. That is why the fine could reach about 3% of annual turnover.
The seriousness. The IMY rated the infringement high. It cited the scale, the sensitivity of the data, the presence of children and the fact that the failure concerned Miljödata's core business. It also cited a degree of negligence it considered aggravating, because the vulnerability had been public for more than a year.
The adjustments. Self-notification and cooperation with the investigation were treated as neutral, since both are legal duties. In the IMY's view, the encryption of attachments and free-text fields did not go beyond what could be expected. The information effort Miljödata made right after the attack earned some mitigating weight; it included individual meetings with several hundred affected controllers. Miljödata's request for a reprimand in place of a fine was rejected.
The IMY does not publish its arithmetic, and the guidelines do not require it to state the exact starting amount. Applying their brackets as an illustration:
That gives a band of roughly €6,000 to €200,000 before adjustments. SEK 1.8 million sits in its upper part, consistent with a case rated high. Five days before the decision, the EDPB adopted new guidelines on when a fine is the right tool compared with the other corrective powers.
The decision names two measures as basic for processing of this kind, and neither is exotic:
The chain in this case ran from the municipalities to Miljödata, from Miljödata to the firewall supplier, and from the supplier to an outdated build. The IMY placed that last link on Miljödata's side of the ledger: buying from a reputable supplier leaves the duty to check what actually arrived with the buyer.
NIS2 (Directive (EU) 2022/2555) approaches the same problem from the cybersecurity side. Entities within its scope must manage supply chain security, including their relationships with direct suppliers (Article 21(2)(d)). In doing so they must take into account each supplier's vulnerabilities, the quality of its products and its secure development practices (Article 21(3)). Where a data protection authority fines a breach, the NIS2 authority may not fine the same conduct again, though it keeps its other enforcement powers (Article 35(2)). The IMY decision does not examine NIS2, and whether Miljödata or its customers fall within its scope is a question for another file.
Security is one of several obligations EU law now writes into the vendor relationship. The Data Act governs how customers leave a SaaS provider, including one with no establishment in the EU. It also requires connected products placed on the market from 12 September 2026 to give users access to their data by design.
Yes. Article 32 imposes the security obligation on processors directly. Article 83(4)(a) allows fines of up to €10 million or 2% of worldwide turnover, whichever is higher, for breaching it. Miljödata, the ICO's Advanced case and the IMY's Sportadmin case are recent examples.
Both can be, for different failures. The processor answers for its own security and for alerting the controller. The controller answers for choosing and supervising the processor, for its own measures, and for notifying the authority and, where needed, the people affected. Towards those people, anyone responsible for the same damage is liable for all of it.
Security measures appropriate to the risk. They are judged by the state of the art, the cost of implementation, the nature and scale of the processing and the harm a breach could cause. The Article gives encryption, resilience, recovery and regular testing as examples. A breach does not by itself prove the measures were inadequate; the test is whether they matched the risk.
Under the EDPB's five-step method: identify the infringement and its legal maximum, rate its seriousness, adjust for the size of the undertaking, weigh aggravating and mitigating factors, and check that the result is effective, proportionate and dissuasive.
The Miljödata decision draws its line clearly. A processor carries its own security obligation, enforceable with its own fine. The reputation of an upstream supplier does not discharge that obligation when the flaw had been public for a year. The two failures the IMY identified were an unchecked component and monitoring that watched uptime and missed the intruder. Both are ordinary, which is why the decision will be read well beyond Sweden. For the 2.2 million people whose records were exposed, it establishes which failures made that possible and who answered for them. What the municipalities and the region did with their own obligations is the part the IMY has yet to decide.
GDPR tested against your real product, from the first form to the last supplier receiving data.
60 minutes on Google Meet with a qualified lawyer specialising in artificial intelligence, data, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.