Data
24/9/26

The Miljödata GDPR fine: when the processor pays for a data breach

Sweden's IMY fined software vendor Miljödata SEK 1.8m for a breach affecting 2.2 million people. Why the processor was fined, and what the GDPR asks of vendors.

Estimated reading time:

11 min read

Guillermo Passas Varo

On 22 September 2026, Sweden's data protection authority, the IMY, fined the software company Miljödata SEK 1.8 million (about USD 183,000) over the ransomware attack that exposed the personal data of 2.2 million people in August 2025, as BleepingComputer reported the same day (MLex also covered it for subscribers). Miljödata supplies the systems that a majority of Swedish municipalities, several regions, government agencies and a large number of private employers use to manage sick leave, rehabilitation and workplace incidents. In GDPR terms it acted mainly as a processor: it handled the data on behalf of its customers, who are the controllers.

That is what makes the case worth reading closely. Regulators have fined processors before, though far less often than controllers. Here the IMY went straight to the company that ran the systems while opening separate investigations into two municipalities and one region. The IMY's press release and its 17-page decision set out the reasoning. They also answer a question that reaches well beyond Sweden: when a vendor is breached, who answers for what, and how is the fine calculated?

What happened at Miljödata

The decision reconstructs the attack from Miljödata's own forensic account, which the IMY saw no reason to doubt:

  • 20 August 2025. The attacker gets in through an SQL injection against a support component of a firewall solution. Miljödata had installed that component on an internet-facing server about a week earlier. The attacker then escalates its privileges and moves laterally between servers.
  • Night leading into 23 August. The attacker starts encrypting several servers and extracts data.
  • Afternoon of 23 August. A technical alarm about faults in the service goes off. Miljödata isolates all servers within roughly an hour and calls in an external incident response team.
  • 26 August. Miljödata notifies the IMY.
  • 2 September. The internal investigation finds signs that data had been exfiltrated.
  • 14 September. The attacker publishes part of the data on the dark web, after demanding a ransom of 1.5 bitcoin, according to BleepingComputer.

The records held around twenty data points per person: personal identity numbers, contact details, employment data and absence records. The services also contained health data on sick leave and rehabilitation, staff notes and protected personal data. To a limited extent they also held information about children who worked for a customer or appeared in records of school incidents. Miljödata had encrypted attachments and free-text fields. The IMY accepted that this reduced the risk of harm to some degree, and held that it did not shield the data from the access that took place. In the weeks after the attack the IMY received more than 500 breach notifications from organisations naming Miljödata as their processor, and some seventy complaints from affected people.

What the IMY found wrong

Article 32(1) GDPR requires both the controller and the processor to put in place technical and organisational measures that ensure a level of security appropriate to the risk. The IMY first measured the risk: health data, children's data and identity numbers on 2.2 million people, across more than 300 customers. That called for a high level of security. It then identified two failures.

The first was the firewall component. Picture a new lock fitted to the front door. The manufacturer had described the model's flaw on its own website more than a year earlier, and the person who installed it never checked the model number. The supplier had shipped Miljödata an outdated version with a known critical vulnerability. Miljödata told the IMY it had no reason to suspect anything, since the product was expensive and came from a well-known supplier, a point SVT highlighted in its coverage. The IMY's view was that checking you have received the right version is a basic security measure. That holds all the more for new software placed on an internet-facing server with no prior run in a test environment.

The second was detection. Miljödata's monitoring behaved more like a gauge on a boiler than a smoke detector: it reported whether the systems were running and raised the alarm when they stopped. For three days the attacker got past virus detection, security monitoring and multi-factor authentication and moved from server to server. The IMY found the monitoring had been aimed mainly at performance and availability. Given the risk, it held that automated real-time monitoring for suspicious activity was a basic measure, and earlier detection would have limited what the attacker could take. Miljödata introduced round-the-clock EDR and SOC monitoring shortly after the incident, which the IMY read as evidence that the measure had been within reach.

One line in the file deserves attention. Miljödata's own threat analysis had rated the likelihood of a cyber attack as relatively low, partly because of the company's limited public profile. The same analysis rated the consequences for the people in its systems as severe. The IMY's Director-General, Eric Leijonram, said the failure allowed a threat actor to obtain data on a large part of Sweden's population, as reported by Ny Teknik. Miljödata maintains that it did not infringe the GDPR, and the decision can be appealed within three weeks to the Administrative Court in Stockholm.

Can a data processor be fined under the GDPR?

Yes. A processor is any person or body that processes personal data on behalf of a controller (Article 4(8)). The security duty in Article 32 names both. Article 83(4)(a) sets fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher, for breaches of the obligations of the controller and the processor under Articles 25 to 39.

Think of a municipality's HR files stored in a hired archive. The municipality decides what goes into the boxes, why, for how long and who may open them. The archive company decides how the building is locked and watched. Article 32 speaks to both. The archive answers for its locks. The municipality answers for having chosen that archive and for checking, at intervals, that the locks still work.

The Miljödata decision shows how directly this operates. Miljödata acted mainly as a processor, as a sub-processor where it served customers through other suppliers, and as a controller for a limited set of activities. The IMY declined to assign a role to each activity: since Article 32 binds controllers and processors alike, the answer would not change the infringement.

Processor fines remain the minority, and they are no longer isolated:

  • In March 2025 the UK's ICO fined Advanced Computer Software Group £3.07 million, its first fine on a processor. The 2022 ransomware attack behind it began through a customer account with no multi-factor authentication.
  • The IMY itself fined Sportadmin, a platform for sports clubs, SEK 6 million in January 2026 on the same Article 32(1) ground.
  • DLA Piper's January 2026 survey recorded several fines imposed directly on processors in 2025. In the same year, breach notifications across Europe rose 22% to an average of 443 a day.

Controller or processor: who is liable for a data breach?

Each answers for its own part.

  • The processor answers for the security of its own systems (Article 32). It must help the controller meet its security and breach obligations (Article 28(3)(f)). It must also alert the controller without undue delay once it becomes aware of a breach (Article 33(2)).
  • The controller answers for choosing a processor that offers sufficient guarantees (Article 28(1)) and for its own security measures. It must notify the supervisory authority within 72 hours (Article 33(1)) and, where the risk is high, the people affected (Article 34). The 500-plus notifications the IMY received are this second layer at work.

Compensation follows its own logic. Under Article 82(2), a controller is liable for damage caused by processing that infringes the GDPR. A processor is liable only where it breached obligations addressed specifically to processors, or acted outside or against the controller's lawful instructions. The gate is narrow, and Article 32 sits inside it, because the security duty is addressed to processors expressly. Where both are responsible for the same damage, each is liable for all of it towards the person affected (Article 82(4)), and whoever pays can recover the other's share (Article 82(5)).

The Court of Justice has shaped how these claims run. In Natsionalna agentsia za prihodite (C-340/21) it held that:

  • a third-party attack does not by itself prove the security measures were inadequate;
  • the controller bears the burden of proving they were appropriate;
  • a hacker's involvement does not by itself exempt the controller from paying;
  • the fear of misuse of one's data can in itself be non-material damage.

The IMY relied on the same line of case law to reject Miljödata's argument that nobody had suffered concrete harm: losing control over one's data is already damage.

Why the investigations into the municipalities matter

Choosing a processor is itself an act of the controller, and so is keeping an eye on it. The EDPB's Guidelines 07/2020 on controllers and processors say the controller must assess whether a processor's guarantees are sufficient and be able to prove it did so. They describe that duty as continuing. It does not end when the contract is signed, and the controller should verify the guarantees at appropriate intervals, through audits and inspections where appropriate. The guidelines even use the example of a municipality relying on a standardised cloud service, and conclude that the standard nature of the offer leaves the municipality's obligations intact.

That is the ground the IMY is now examining in two municipalities and one region. One of them is the City of Gothenburg. The IMY's letter to the city states that the authority is reviewing whether the city took appropriate measures under Article 32. The outcomes are pending, and nothing in the Miljödata decision anticipates them. Whether and how far public bodies can be fined at all is for each Member State to settle in its own law (Article 83(7)).

On paper, the controller's duty becomes provable through three things:

  • a map of which suppliers receive which data;
  • processor agreements that set concrete security requirements (the EDPB warns that they should not merely restate the GDPR);
  • a record of the checks carried out.

Building that map, supplier by supplier, is the core of a GDPR product audit.

How the IMY calculated SEK 1.8 million

The decision is unusually open about the fine. The IMY followed the five-step method in the EDPB's Guidelines 04/2022 on the calculation of administrative fines.

The legal maximum. Miljödata is wholly owned by Persona Grata Informationssystem AB. Under the Akzo presumption from EU competition law, a parent holding 100% of a subsidiary is presumed to exercise decisive influence over it, so the two count as a single undertaking. The parent reported zero turnover for 2025 and Miljödata SEK 58,476,045. Two per cent of that is SEK 1,169,521. Because the GDPR applies whichever cap is higher, the ceiling was €10 million. For a company of this size the percentage cap is a trapdoor that never opens and the fixed figure is the real limit. That is why the fine could reach about 3% of annual turnover.

The seriousness. The IMY rated the infringement high. It cited the scale, the sensitivity of the data, the presence of children and the fact that the failure concerned Miljödata's core business. It also cited a degree of negligence it considered aggravating, because the vulnerability had been public for more than a year.

The adjustments. Self-notification and cooperation with the investigation were treated as neutral, since both are legal duties. In the IMY's view, the encryption of attachments and free-text fields did not go beyond what could be expected. The information effort Miljödata made right after the attack earned some mitigating weight; it included individual meetings with several hundred affected controllers. Miljödata's request for a reprimand in place of a fine was rejected.

The IMY does not publish its arithmetic, and the guidelines do not require it to state the exact starting amount. Applying their brackets as an illustration:

  • a high-seriousness infringement starts between 20% and 100% of the €10 million maximum;
  • for an undertaking with a turnover between €2 million and €10 million, the guidelines suggest working from 0.3% to 2% of that starting amount.

That gives a band of roughly €6,000 to €200,000 before adjustments. SEK 1.8 million sits in its upper part, consistent with a case rated high. Five days before the decision, the EDPB adopted new guidelines on when a fine is the right tool compared with the other corrective powers.

The security bar in the supply chain, and where NIS2 fits

The decision names two measures as basic for processing of this kind, and neither is exotic:

  • verifying the version of a component before it goes into production;
  • automated real-time monitoring for intrusions.

The chain in this case ran from the municipalities to Miljödata, from Miljödata to the firewall supplier, and from the supplier to an outdated build. The IMY placed that last link on Miljödata's side of the ledger: buying from a reputable supplier leaves the duty to check what actually arrived with the buyer.

NIS2 (Directive (EU) 2022/2555) approaches the same problem from the cybersecurity side. Entities within its scope must manage supply chain security, including their relationships with direct suppliers (Article 21(2)(d)). In doing so they must take into account each supplier's vulnerabilities, the quality of its products and its secure development practices (Article 21(3)). Where a data protection authority fines a breach, the NIS2 authority may not fine the same conduct again, though it keeps its other enforcement powers (Article 35(2)). The IMY decision does not examine NIS2, and whether Miljödata or its customers fall within its scope is a question for another file.

Security is one of several obligations EU law now writes into the vendor relationship. The Data Act governs how customers leave a SaaS provider, including one with no establishment in the EU. It also requires connected products placed on the market from 12 September 2026 to give users access to their data by design.

Frequently asked questions

Can a data processor be fined under the GDPR?

Yes. Article 32 imposes the security obligation on processors directly. Article 83(4)(a) allows fines of up to €10 million or 2% of worldwide turnover, whichever is higher, for breaching it. Miljödata, the ICO's Advanced case and the IMY's Sportadmin case are recent examples.

Who is liable for a data breach, the controller or the processor?

Both can be, for different failures. The processor answers for its own security and for alerting the controller. The controller answers for choosing and supervising the processor, for its own measures, and for notifying the authority and, where needed, the people affected. Towards those people, anyone responsible for the same damage is liable for all of it.

What does Article 32 GDPR require?

Security measures appropriate to the risk. They are judged by the state of the art, the cost of implementation, the nature and scale of the processing and the harm a breach could cause. The Article gives encryption, resilience, recovery and regular testing as examples. A breach does not by itself prove the measures were inadequate; the test is whether they matched the risk.

How are GDPR fines calculated?

Under the EDPB's five-step method: identify the infringement and its legal maximum, rate its seriousness, adjust for the size of the undertaking, weigh aggravating and mitigating factors, and check that the result is effective, proportionate and dissuasive.

The Miljödata decision draws its line clearly. A processor carries its own security obligation, enforceable with its own fine. The reputation of an upstream supplier does not discharge that obligation when the flaw had been public for a year. The two failures the IMY identified were an unchecked component and monitoring that watched uptime and missed the intruder. Both are ordinary, which is why the decision will be read well beyond Sweden. For the 2.2 million people whose records were exposed, it establishes which failures made that possible and who answered for them. What the municipalities and the region did with their own obligations is the part the IMY has yet to decide.

did you find this article interesting?

Maybe You Are Interested in Our Tailored Related Services with Open Fees

EU digital companies

GDPR Product Audit

GDPR tested against your real product, from the first form to the last supplier receiving data.

FROM
€3,500 + VAT

Book your Virtual Consultation with a lawyer. Today.

60 minutes on Google Meet with a qualified lawyer specialising in artificial intelligence, data, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.

Choose your lawyer and a time in the calendar. No forms first, no sales calls.