P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Sweden fined a processor six pence a head for a breach that reached a fifth of the country

IMY fined Miljodata 1,800,000 kronor over a breach covering 2.2 million people, which is about 6.2 pence each. The number that matters is the ceiling it sits under, and it was never four per cent.

By Parminder Kumar Sharma · · 21 min read

Editorial illustration for the briefing: Sweden fined a processor six pence a head for a breach that reached a fifth of the country

Six pence a person

On 22 September 2026 the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten or IMY, fined Miljodata i Karlskrona Aktiebolag 1,800,000 kronor for breaching Article 32.1 of the GDPR. The company had told the regulator that about 2,200,000 people were registered in the affected services and were covered by the incident.

Divide one by the other and you get 0.818 kronor per person.

The European Central Bank reference rates for 23 September 2026 put the euro at 11.2720 kronor and at 0.85950 pounds, which crosses to 13.1146 kronor to the pound. So 0.818 kronor is 6.2 pence. The whole penalty, for a breach that reached roughly a fifth of the Swedish population, comes to about 137,252 pounds.

That number is real, it is arithmetic rather than rhetoric, and it is the reason this decision is worth a UK reader's time. It is also, on its own, close to meaningless.

The interesting fact is what happens when you divide the same fine by the company instead of by the public. Miljodata's turnover for the 2025 financial year was 58,476,045 kronor. The fine is 3.08 per cent of that. It is larger than two per cent of the undertaking's worldwide annual turnover, and IMY says so in the decision. The penalty is not small because the regulator went easy. It is small per head because the company is small and the harm was enormous, and nothing in the GDPR's fining structure connects those two quantities.

What the 2.2 million actually counts

Before the arithmetic can carry any weight, the denominator has to mean something. It is worth being precise, because two different numbers are in public circulation and they count different things.

IMY's decision says the personal data incident covered about 2,200,000 natural persons, and that this figure comes from Miljodata. Read in context, it is the population registered in the affected services and caught by the incident, not a confirmed count of individuals whose records were published.

The Swedish Prosecution Authority closed its criminal investigation into the attack on 14 April 2026 without charging anyone, citing insufficient evidence despite international cooperation. Reporting of that closure put the number of people whose data the attackers obtained at just over 1.5 million.

Use the smaller figure and the fine becomes 1.20 kronor per person, or 9.2 pence. The point survives the choice of denominator, which is the only reason it is safe to lead with it. Whichever count you prefer, the regulatory price of one person's exposure is under a shilling.

The data itself is what makes the comparison bite. Miljodata supplies web based systems for personnel and working environment administration: sickness absence, rehabilitation, occupational injuries and incident reporting. It has over 300 customers across Sweden, a large share of them municipalities, regions and other public bodies. The services held about 20 personal data items per registered person, which across 2.2 million people is on the order of 44 million individual data points.

IMY records that the processing involved special category health data under Article 9: sickness absence records, rehabilitation documentation and medical certificates. It also involved documentation of school incidents, personnel notes, Swedish personal identity numbers, and personal data relating to children. In a limited number of cases it involved protected identities, which the decision notes were not intended to be processed in the services at all.

IMY's language about health data is not hedged. Processing of that kind, the decision says, can amount to a particularly serious interference with the fundamental rights to private life and to the protection of personal data.

The ceiling was never four per cent

The most common way to get this story wrong is to reach for the famous number. The GDPR's headline penalty, up to 4 per cent of global annual turnover or 20 million euro whichever is higher, does not apply here and could never have applied here.

Article 83.5 carries the 4 per cent and 20 million euro maximum, and it covers the basic principles of processing, the lawful bases, Article 9, data subject rights, international transfers and non compliance with a supervisory authority's order. Article 32 is not in that list.

Article 32 sits in Article 83.4, alongside Articles 8, 11, 25 to 39, 42 and 43. That tier is capped at 10 million euro, or 2 per cent of the undertaking's total worldwide annual turnover in the preceding financial year, whichever is higher. IMY sets this out expressly in the decision.

Working the cap through is where the decision becomes genuinely instructive, because IMY does it in the open and the result is counterintuitive.

Miljodata is a wholly owned subsidiary of Persona Grata Informationssystem Aktiebolag. IMY applies the competition law concept of an undertaking, citing recital 150, the Court of Justice in Deutsche Wohnen, and the Akzo presumption that a parent owning 100 per cent of the shares exercises decisive influence. The presumption was not rebutted, so the two companies are treated as a single economic unit.

No consolidated group accounts had been prepared, so IMY added the two companies' turnover for the 2025 financial year: Persona Grata reported 0 kronor, and Miljodata reported 58,476,045 kronor. Two per cent of that combined figure is 1,169,521 kronor.

And that is lower than 10 million euro. So the static limb governs, and IMY states plainly that the highest sanction available in the case was 10 million euro. At the ECB rate for 23 September 2026 that is 112,720,000 kronor, or about 8,595,000 pounds.

Set the issued fine against that ceiling and it is 1.6 per cent of the maximum. Per person, the maximum would have been 51.24 kronor, or about 3.91 pounds. The fine that was issued is about one sixty third of it.

Now set the same fine against the company. At 1,800,000 kronor it is 1.54 times the two per cent turnover limb, and 3.08 per cent of the group's annual revenue. IMY was able to exceed two per cent of turnover precisely because the statute says whichever is higher, and for a company this size the fixed euro figure is far higher. For an undertaking with turnover above 500 million euro the position reverses and the percentage limb takes over.

A horizontal bar chart on a zero baseline in Swedish kronor showing the 1,800,000 kronor sanction as a narrow sliver, two per cent of group turnover at 1,169,521 kronor as a narrower one, the group's 2025 turnover of 58,476,045 kronor at roughly half width, and the 10 million euro statutory maximum of 112,720,000 kronor filling the chart, with a note listing the response costs the decision records but does not quantify.
Drawn from the figures in IMY decision IMY-2025-21177 and the ECB euro reference rates for 23 September 2026.

Why IMY landed where it did, in its own words

Miljodata argued that no penalty was warranted at all, and that if one were, the only effective, proportionate and dissuasive response was a reprimand. IMY rejected that, finding the infringement was not of the minor kind that recital 148 allows to be met with a reprimand.

The decision is unusually explicit about which mitigating arguments it accepted and which it declined, and the pattern is worth studying because it is the pattern the EDPB fining guidelines 04/2022 produce.

IMY assessed the infringement as being of high severity. It cited the scale of processing, the number of data items per person, the health data, the children's data, the identity numbers, the fact that the failing touched the core of Miljodata's own business, and the degree of negligence. It found the company had acted negligently, which is the threshold the Court of Justice requires before a fine may be imposed at all.

On damage, IMY invoked the Court of Justice's position that harm can arise for data subjects from loss of control over their own personal data, even without concrete misuse. That disposed of the company's argument that no data subject or controller had brought a specific claim.

How IMY treated each factor Miljodata advanced, from the decision's section on mitigating and aggravating circumstances

Factor advanced by the companyHow IMY treated it
Encryption of attachments and free text fieldsReduced risk to some degree, but did not go beyond what could be expected. Not mitigating.
Post incident remediation and investmentNot shown to have reduced harm to data subjects enough to count. Not mitigating.
Self reporting the breach within the statutory deadlineExpected conduct. Neither raises nor lowers the fine.
Cooperation with IMY during the investigationExpected conduct. Neither raises nor lowers the fine.
Helping customers file their own breach notificationsNot of a kind to be treated as mitigating.
Information work with several hundred controllers and with SKRAccepted, to some mitigating extent. The only factor that reduced the fine.
No prior GDPR investigationNot identified as a separate mitigating factor in the decision.

The closing sentence of the reasoning is the whole calculation in one line: the amount reflects the high severity of the infringement and the size of the company. Severity pushed it up, size pulled it down, and the footnote points to the passage in the EDPB guidelines explaining how an undertaking's turnover can be used to adjust a figure that starts from the static 10 million euro amount.

It is worth stating clearly what the decision does not contain, because inference is tempting here. There is no discussion of the ransom, of whether one was demanded or paid. There is no finding on Article 33 or Article 34 notification timing. There is no order for individual redress, and no mechanism in the decision by which any of the 2.2 million people receives anything.

One unchecked version number, three undetected days

The mechanism matters because it is mundane, and because the two failings IMY identified are both things a UK organisation can check this week.

About seven days before the incident, Miljodata installed a support component for a firewall solution, bought from what the decision repeatedly calls a well known and reputable supplier. The supplier delivered an out of date version. Nothing on the supplier's website at the point of order, and nothing at the point of download, indicated that it was not the current release. That version carried a known critical vulnerability, and the supplier had published information about that vulnerability on its own site more than a year before the installation.

The component went onto a server exposed to the internet. It was not put through a test environment. Miljodata never explicitly approved the installed version and, in its own account, had no reason to question a costly product from a well known vendor, so the question of checking the version and its known vulnerabilities never arose.

On 20 August 2025 an attacker exploited that vulnerability through an SQL injection, reached the server, escalated privileges and assigned itself the highest rights in the system. It then moved laterally between servers for three days, despite two factor authentication being enabled on internal services and despite separate role based accounts being in place. IMY records that the attacker circumvented virus detection, security monitoring and multi factor authentication.

Miljodata's monitoring was, in IMY's words, primarily oriented towards system performance and availability. The company's EDR solution proved insufficiently resilient. Nothing alerted on the initial intrusion attempts, on the lateral movement, on the encryption, or on the transfer of personal data out.

On the night of 23 August the attacker began encrypting servers and then extracted the information. That afternoon, a technical alarm fired: not a security alert, but a fault alarm in the service. Miljodata isolated every server about an hour later and activated an external incident response team the same evening.

IMY's conclusion on this point is blunt and quantified: the attacker obtained more information than it otherwise would have, because the monitoring did not raise the alarm in time.

A vertical sequence of dated stages: a vendor ships an out of date firewall component carrying a known critical flaw published more than a year earlier; Miljodata installs it on an internet facing server without checking the version; on 20 August 2025 an SQL injection gives the attacker full rights; three days of lateral movement go undetected because monitoring watched performance, not security; and IMY fines 1,800,000 kronor on 22 September 2026.
Built from the narrative and findings in IMY decision IMY-2025-21177.

The two failings IMY actually found are narrower than the incident. It did not hold that Miljodata's security programme was generally inadequate, and the decision acknowledges multi layered protection, access control, logging, monitoring and incident preparedness were in place. What it found was that the company failed to check that the correct version of the component was installed before integrating it, which IMY calls a basic security measure given the nature of the processing, and that it failed to have automatic real time monitoring capable of identifying suspicious activity and intrusion attempts.

IMY notes pointedly that Miljodata demonstrably had the capacity to take the second measure, because it introduced round the clock EDR and SOC monitoring shortly after the incident.

Stated in the decision, and not stated

A regulator's decision is a narrow document. It answers the question the regulator asked and is silent on much that a reader assumes it covers. The silences are where the cost of a breach actually lives.

What IMY decision IMY-2025-21177 puts on the record against what it leaves open

QuestionStated in the decisionNot stated
The amount1,800,000 kronor, and that 10 million euro was the applicable maximumAny sterling or dollar equivalent, and whether the fine has been paid or appealed
The legal basisArticle 32.1, with Articles 58.2 and 83 as the powers, in the Article 83.4 tierAny finding under Article 33 or 34, or any Article 5 or Article 9 finding
The data categoriesIdentity numbers, contact, employment and absence data; health data; school incidents; children; some protected identitiesHow many of the 2.2 million had health data specifically, or how many records were actually published
The root causeA vendor supplied out of date component with a year old known flaw, installed without a version check, exploited by SQL injectionThe vendor's name, the product, and any CVE identifier
The notification timelineIncident 20 August, discovered 23 August, notified to IMY 26 August, published on the darknet 14 September 2025When individual data subjects were told, or whether Article 34 notification was adequate
Individual redressThat loss of control is itself damage, and that no controller or data subject had made a specific claimAny compensation order, any redress route, or any sum reaching any affected person
The cost of the responseAn external IR team, forensics, rebuilt domain controllers, a replaced security stack, new EDR and 24/7 SOC, hundreds of customer meetingsAny figure at all. The company called the cost significant and the decision does not price it

The comforting labels that were all present

This case is an unusually clean demonstration that a control name on an assurance questionnaire is not a control.

Multi factor authentication was enabled. IMY records that two factor authentication was active on internal services in the technical environment before and at the time of the incident, and that the attacker circumvented it. MFA on internal services does not help when the entry point is an unauthenticated injection flaw in an internet facing component and the attacker escalates to system level rights rather than authenticating as anyone.

Role separation was in place. Separate authorisation accounts for different roles existed. The attacker escalated past them.

Encryption was in use. Miljodata encrypted attachments and free text fields. IMY accepted that this reduced risk to some degree, but held that it could not be taken as evidence the data was protected from unauthorised access during the intrusion, and declined to treat it as mitigating.

A reputable vendor supplied the component. This is the label that did the most damage. The company's stated reason for not verifying the version was that the product was expensive and came from a well known supplier. The supplier shipped a release with a publicly documented critical flaw more than a year old.

There was monitoring. There was a great deal of monitoring. It watched whether the service was up, not whether it was being robbed.

The UK reading: the fine is the smallest number in the range

The ICO holds the same architecture of powers. Under section 157 of the Data Protection Act 2018 the standard maximum is 8,700,000 pounds or 2 per cent of total annual worldwide turnover, whichever is higher, and the higher maximum is 17,500,000 pounds or 4 per cent. Article 32 of the UK GDPR attracts the standard maximum, exactly as Article 32 of the EU GDPR attracts the Article 83.4 tier.

The closest British analogue is unusually close. On 26 March 2025 the ICO fined Advanced Computer Software Group Limited 3,076,320 pounds over a ransomware incident in August 2022 that put the personal data of 79,404 people at risk, including details of how to enter the homes of 890 people receiving care at home. Attackers reached systems of Advanced's health and care subsidiary through a customer account without multi factor authentication. It was the first UK GDPR fine issued to a processor.

The ICO had announced a provisional intention to fine 6.09 million pounds in August 2024. After representations, and citing Advanced's proactive engagement with the NCSC, the NCA and the NHS among other mitigating steps, the final penalty was agreed at roughly half, by voluntary settlement and without appeal.

Run the same division. Advanced: 3,076,320 pounds across 79,404 people is 38.74 pounds per person. Miljodata: 6.2 pence per person. The British per head figure is about 620 times the Swedish one.

That gap is not a statement about the relative toughness of two regulators. It is a statement about denominators. Advanced's breach was a hundredth the size by headcount and its fine was over twenty times larger in absolute terms, because Advanced is a far bigger company. Both regulators landed well under their ceilings. The ICO's 3.07 million pounds is no more than about 35 per cent of the applicable standard maximum. IMY's 1.8 million kronor is 1.6 per cent of its applicable maximum. Both are dwarfed by what the incidents actually cost the organisations concerned.

So what are the bigger numbers, and why do none of them appear in a fine?

Incident response and rebuild. The decision itemises this without pricing it: an external incident response team engaged the same evening, forensic investigation, sanitisation of compromised systems, restoration of encrypted servers, affected domain controllers rebuilt from scratch to restore a trusted identity infrastructure, a full sweep to confirm no residual malicious code, security solutions decommissioned and replaced, and EDR and SOC monitoring introduced around the clock. Miljodata told the regulator the incident had caused it significant costs and extensive work. A regulator has no reason to quantify that, so nobody does.

Civil claims under Article 82. This is the one the arithmetic exposes most sharply. IMY expressly relied on Court of Justice authority that loss of control over personal data is itself damage, without concrete misuse. The equivalent right exists under Article 82 of the UK GDPR. The entire Swedish fine is about 137,252 pounds. If 275 people out of 2.2 million recovered 500 pounds each, that alone would exceed the fine. That is 0.012 per cent of the affected population. The calculation is arithmetic, not a forecast of any litigation, but it shows how thin the regulatory number is next to a civil tail.

Customer and contractual consequence. Miljodata held over 300 customers, a large share of them public bodies with procurement obligations. The decision records hundreds of individual customer meetings and a coordinating role with Sweden's municipalities and regions. It does not record a single contractual outcome, because that is not the regulator's business. Processor contracts contain indemnities and termination rights, and those operate whatever the regulator decides.

Operational loss. Every server was isolated about an hour after discovery. For a supplier of personnel administration systems to Swedish municipalities, that is an outage across a large part of the public sector payroll and absence estate. No part of that appears in a fine.

And no redress for anyone. The fine is paid to the state. The criminal investigation into the attackers closed in April 2026 with nobody charged. On the face of the decision, a person whose sickness absence record was published on the darknet has received, by way of outcome from this enforcement, six pence of notional penalty paid to the Swedish exchequer.

What to do about it, in order

Take this with you

The order worth doing it in

  • Take the two findings literally. List every security component installed on an internet facing host in the last 24 months and confirm, from the artefact rather than the order, which version is actually running.
  • Add a version and known vulnerability check to your change process as a gate, applied to security products specifically. Vendor reputation and purchase price are not evidence of currency.
  • Ask whether your monitoring alerts on security events or on service health. Miljodata had monitoring that worked perfectly and told nobody anything, because it was watching the wrong thing.
  • Test the detection you believe you have. The failure here was not the absence of EDR but its insufficient resilience, discovered only after three days of undetected lateral movement.
  • Assume multi factor authentication on internal services will not stop an unauthenticated flaw in an edge component. Map which of your controls sit behind the entry point rather than in front of it.
  • Identify where you are the processor. Article 32 binds processors directly, the ICO has now fined one, and the obligation does not wait for the controller to ask.
  • Recalculate your own exposure using the correct tier. For a security failure it is 8.7 million pounds or 2 per cent, whichever is higher, not 17.5 million or 4 per cent.
  • Then set the regulatory figure aside and cost the response, the civil tail, the contractual consequences and the outage. Present the business case on those numbers, because those are the ones that will actually arrive.
  • If you hold special category data on behalf of public sector employers, write down what your customers would have to do on the day you tell them. Miljodata's coordination work was the single thing that reduced its fine.

The question that exposes the gap

There is a structural point underneath the six pence, and it is not a criticism of IMY, which applied the statute and the EDPB guidelines carefully and transparently.

The GDPR caps a security failure at the higher of 10 million euro and 2 per cent of the offender's turnover. Both limbs are measured against the organisation. Neither is measured against the number of people harmed. A processor with 58 million kronor of revenue can hold the occupational health records of a fifth of a country, and the ceiling on its worst case penalty is set by its revenue, not by that fifth.

That is not an accident of this case. It is how the instrument is built, and it is built the same way in the United Kingdom.

So the question to put to your own board is not whether you could survive a fine. Almost certainly you could, and the fine is the number you can most easily predict.

How many people's records do you hold, and what is the largest penalty your own turnover would permit a regulator to impose if you lost every one of them? Divide the second by the first. If the answer is a number of pence, then the regulator is not the party you are protecting those people from, and your security case has to be made to someone else, on some other number.

Sources

  1. PrimaryThe full 17 page decision IMY-2025-21177 of 22 September 2026, read in full: the 1,800,000 kronor amount, Article 32.1, the turnover and Article 83.4 ceiling reasoning, the two security failings, the attack narrative and the mitigating factorsIntegritetsskyddsmyndigheten (IMY)accessed 2026-09-24
  2. PrimaryIMY press release announcing the sanction, used for the summary of data categories and the affected countIntegritetsskyddsmyndigheten (IMY)accessed 2026-09-24
  3. PrimaryText of GDPR Article 83, used to confirm that Article 32 falls in the paragraph 4 tier of 10 million euro or 2 per cent rather than the paragraph 5 tier of 20 million euro or 4 per centGDPR-infoaccessed 2026-09-24
  4. PrimaryEuro foreign exchange reference rates for 23 September 2026, used for every kronor to sterling and euro to kronor conversion in this pieceEuropean Central Bankaccessed 2026-09-24
  5. PrimarySection 157 of the Data Protection Act 2018, used for the UK standard maximum of 8.7 million pounds or 2 per cent and the higher maximum of 17.5 million pounds or 4 per centThe National Archivesaccessed 2026-09-24
  6. PrimaryICO enforcement record for Advanced Computer Software Group Limited, used for the 3,076,320 pound penalty, the date and the 79,404 affected peopleInformation Commissioner's Officeaccessed 2026-09-24
  7. PrimaryPress release of 14 April 2026 closing the criminal investigation into the Miljodata intrusion and attempted extortion without chargesAklagarmyndigheten (Swedish Prosecution Authority)accessed 2026-09-24
  8. PrimaryPopulation statistics for the first half of 2026, used for the comparison of 2.2 million people against the Swedish populationStatistics Sweden (SCB)accessed 2026-09-24
  9. Reported byFiled annual accounts for Miljodata i Karlskrona AB, used to corroborate the 2025 net turnover figure that IMY states in the decision and to identify the parent companyAllabolagaccessed 2026-09-24
  10. Reported byReport on the closure of the criminal investigation, the source of the figure of just over 1.5 million people whose data the attackers obtainedSVT Nyheteraccessed 2026-09-24

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.