Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security
Sweden's data protection authority fined IT service provider Miljödata i Karlskrona roughly EUR 160,000 after a 2025 cyberattack exposed personal data belonging to 2.2 million individuals, with the stolen data later published on the darknet. The fine was issued under Article 32 of the GDPR for inadequate technical and organisational security measures.
Why this matters: 2.2 million people had their data stolen and dumped publicly, and the company processing it did not have adequate security in place. That is the core problem Article 32 exists to prevent. A EUR 160,000 fine for a breach of that scale is not a large number. It may not change much for the next IT provider cutting corners on security. The people whose data ended up on the darknet do not get a remedy from a fine — they get ongoing exposure.
Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.