Skip to content
TrustList
News

Swedish regulator fines HR software supplier Miljödata over its 2025 breach

Editorial

By TrustList Editorial

Sweden's data protection authority fined Miljödata SEK 1.8 million for weak security before an attack that exposed data on 2.2 million people, and is now reviewing two municipalities and a region that used it.

About Swedish regulator fines HR software supplier Miljödata over its 2025 breach

Swedish regulator fines HR software supplier Miljödata over its 2025 breach

22 September 2026 — Sweden's data protection authority, IMY, has fined the software company Miljödata SEK 1.8 million for failing to keep personal data secure. The decision was announced on 22 September 2026. It follows a cyber attack in August 2025 that, according to IMY, exposed information about roughly 2.2 million people. IMY has also opened reviews of two municipalities and one region connected with the attack, and those reviews are still open.

What changes

Miljödata supplies HR and work-environment management systems to public bodies and employers in Sweden. The data exposed included personal identity numbers, contact details and sensitive records about sick leave, rehabilitation and incidents in schools.

IMY found that Miljödata broke Article 32(1) of the GDPR, which requires security appropriate to the risk, and named two failings: the company did not carry out adequate checks when installing new software, and it had no automated real-time monitoring to detect intrusions and suspicious activity. Given how sensitive the data was, IMY said, the level of technical and organisational security was not high enough.

The fine is modest by GDPR standards. The more significant point for a buyer is that the regulator is also examining some of the supplier's customers.

Who is affected

The decision was made under EU law, but the same security duty applies in the UK under the UK GDPR. It is relevant to any organisation that keeps employee health, absence or occupational-health data with a software supplier, and to the suppliers that sell such systems. Public bodies, schools and large employers hold this kind of data at scale.

Choosing a supplier does not transfer the responsibility. A buyer can be asked to show how it checked a supplier's security, and what it did when things went wrong.

What to do

  • Check supplier contracts for concrete security commitments: monitoring and intrusion detection, change control over software installed on production systems, and a named breach-notification period.
  • Keep the evidence of your due diligence — the questionnaires, certifications and audit reports you relied on — and review it at renewal.
  • Send the system only the sensitive HR fields it actually needs, and set retention periods so that old absence and health records are deleted.
  • Rehearse a supplier breach: agree in advance who informs staff, who notifies the regulator and how quickly the supplier must hand over logs.

Sources