Eight Cents a Head: Sweden Fines the Vendor That Leaked 2.2 Million People
On September 22, Sweden’s Authority for Privacy Protection (Integritetsskyddsmyndigheten, or IMY) issued a SEK 1.8 million administrative fine — roughly €160,000, or about $180,000 — against Miljödata, an IT services supplier whose systems were breached in a cyberattack in August 2025. According to IMY, the intrusion exposed the personal data of some 2.2 million people, a substantial slice of Sweden’s roughly 10.5 million residents. Miljödata’s customer base runs deep into the public sector — a majority of Sweden’s municipalities, several regions, and government agencies — which is precisely why a single vendor’s failure rippled across so much of the population. Cybernews reports the stolen data included personal identity numbers, contact details, and sensitive records touching sick leave and rehabilitation, some of which surfaced on the dark web.
IMY grounded the penalty in Article 32.1 of the GDPR — the obligation to implement appropriate technical and organizational security measures. Per the regulator’s own account, Miljödata fell short on several fronts: insufficient security measures for the categories of data it held, inadequate controls when installing new software, and no automated, real-time monitoring capable of catching an intrusion in progress. Director General Eric Leijonram, in IMY’s statement, stressed that the GDPR requires appropriate safeguards and that the authority views the incident seriously, urging organizations to review the security of the data they are responsible for.
The arithmetic problem
Now do the division. SEK 1.8 million spread across 2.2 million affected people works out to roughly SEK 0.82 per victim — about eight U.S. cents. Whatever else it is, a penalty of eight cents a head is not a number that reorders a company’s risk calculus. It is closer to a filing fee than a sanction.

This is the recurring pathology of GDPR enforcement against the mid-market. The headline penalties — the hundreds of millions levied on Big Tech — get the coverage and do the regulatory theater. But the vast connective tissue of the data economy is companies like Miljödata: unglamorous back-office suppliers processing sensitive records for hundreds of public bodies, operating well below the altitude where a fine actually stings. For those firms, the expected cost of a breach — probability of getting caught, times probability of a fine, times a penalty this modest — is comfortably cheaper than the sustained security investment that would prevent it. The math rewards the gamble.
Why it matters
The mismatch is not between the fine and Miljödata; it is between the fine and the harm. The 2.2 million people whose identity numbers and sick-leave records were exfiltrated do not get eight cents. They get the open-ended, years-long exposure to identity fraud and the particular indignity of having medical-adjacent data traded on criminal forums — harm that no SEK 1.8 million payment to the state treasury remediates, because none of it flows to them. GDPR was sold, in part, as a regime that would make the mishandling of personal data economically painful. When the pain nets out to pennies per person, the incentive it was meant to create simply doesn’t fire.
And the law did not force the number this low. A breach of Article 32’s security duty falls under Article 83(4) of the GDPR, which allows fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher. That €10 million floor exists so that small firms can still be fined meaningfully: it means IMY could, in principle, have imposed a penalty roughly sixty times larger, whatever Miljödata’s revenue. Regulators weigh many factors when setting a fine, including a firm’s size and means, its cooperation, and what it did to limit the damage, and IMY was under no obligation to go anywhere near the ceiling. But the gap between what the statute allowed and what the regulator chose is the story. The framework left room for a penalty that reflected 2.2 million victims; the decision priced them at eight cents.
The uncomfortable takeaway is that GDPR’s deterrent depends less on the size of its maximum fines than on regulators’ willingness to use them against the unglamorous vendors that actually hold the data. A penalty a rational supplier could have budgeted for in advance is not a deterrent — and until enforcement weighs the number of people harmed as heavily as the size of the firm that harmed them, “GDPR compliance” for the mid-market will keep being a line item, not a constraint.
Sources
- IMY (Swedish DPA), press release: "Sanktionsavgift mot Miljödata för bristande säkerhet" (Sep 22, 2026)
- Cybernews, "Miljödata data breach exposes 2.2M people, draws GDPR fine"
- Sweden Herald, "Miljödata fined SEK 1.8 million after major data breach, Swedish watchdog says"
- teiss, "Swedish regulator fines IT provider Miljödata over data breach affecting millions"
- GDPR Article 83 — General conditions for imposing administrative fines
Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.
Latest from prompt/power
- Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
Leave a Reply